Files
blue-team-tools/rules
Swachchhanda Shrawan Poudel 4355ece230 Merge PR #5598 from @swachchhanda000 - filter FPs on multiple rules
remove: Active Directory Kerberos DLL Loaded Via Office Application - deprecated as it triggers on normal activity
fix: Scheduled Task Creation Via Schtasks.EXE - add for for msoffice application
fix: Use Short Name Path in Command Line - add filter for dotnet csc.exe
fix: Potential Product Reconnaissance Via Wmic.EXE - add filter for some product related operation through wmic
fix: WMIC Remote Command Execution - fix broken FP filter
fix: Classes Autorun Keys Modification - filter null details
fix: CurrentVersion Autorun Keys Modification - filter null details
fix: Modification of IE Registry Settings - filter null details
fix: Potential Persistence Via Shim Database Modification - filter null details
fix: Scheduled TaskCache Change by Uncommon Program - filter null details
update: Copy From Or To Admin Share Or Sysvol Folder - some logic change

---------

Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2025-11-10 13:52:54 +01:00
..
2023-04-21 15:01:48 +02:00