Files
blue-team-tools/rules/windows
Nasreddine Bencherchali 40ccd91a94 Update proc_creation_win_msdt_diagcab.yml
In my testing i found that ".diagcab" extension is not required. You can use .txt with the /cab flag and it'll spawn an msdt process.

Also I added the "-" (dash) version of the flag
2022-06-21 11:45:53 +01:00
..
2022-06-03 15:35:24 +02:00
2022-06-03 15:35:24 +02:00
2022-06-21 11:43:18 +01:00
2022-03-15 18:05:42 +01:00