This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
4a74a56ba37f63e5b407a9ea4abfdc8aea017943
blue-team-tools
/
rules
/
windows
T
History
Thomas Patzke
4a74a56ba3
Merge pull request
#1052
from NikitaStormwind/task
...
[OSCD] Detecting use WinAPI Functions in PowerShell
#69
2020-10-13 00:46:25 +02:00
..
builtin
Update win_net_use_admin_share.yml
2020-10-07 08:23:31 +11:00
deprecated
fix: buggy rule
2020-05-23 18:32:02 +02:00
driver_load
att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other
2020-08-25 01:09:17 +02:00
file_event
Merge pull request
#989
from oscd-initiative/master
2020-09-08 13:27:58 +02:00
image_load
Delete sysmon_tttracer_mod_load.yml
2020-10-06 20:42:32 +03:00
malware
Further subtechnique updates
2020-06-17 11:31:40 -06:00
network_connection
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-08-25 23:51:22 +00:00
other
Merge pull request
#1007
from d4rk-d4nph3/master
2020-09-15 15:45:00 +02:00
powershell
Update powershell_accessing_win_api.yml
2020-10-07 14:47:29 +03:00
process_access
fix typos, update tags
2020-09-13 15:46:45 +02:00
process_creation
Merge pull request
#1051
from esebese/oscd
2020-10-13 00:45:22 +02:00
registry_event
added event type & changed technique
2020-10-02 09:22:14 +05:30
sysmon
Update sysmon_psexec_pipes_artifacts.yml
2020-10-07 14:43:25 +03:00