This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
4bb44f02e1dc0734ff11d5c7ec16f99852ef8be3
blue-team-tools
/
rules
/
windows
T
History
Florian Roth
8154ca355a
Merge pull request
#768
from maximelb/master
...
Remove "condition" from global rule in CVE-2020-1048.
2020-05-18 12:52:49 +02:00
..
builtin
remove false positives with cmd as child of services.exe (not specifically related to meterpreter/cobaltstrike)
2020-05-15 04:45:25 -04:00
deprecated
Merge branch 'master' into oscd
2020-02-03 23:13:16 +01:00
malware
Changed level to ciritcal
2020-05-11 10:40:23 +02:00
other
fix: converted CRLF line break to LF
2020-03-25 14:36:34 +01:00
powershell
fix incorrect use of action global
2020-05-06 22:53:02 +02:00
process_creation
standardize rules with Image and CommandLine instead of NewProcessName and ProcessCommandLine
2020-05-15 12:35:32 -04:00
sysmon
Remove "condition" from global rule.
2020-05-17 12:44:57 -07:00