This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
4bbe4962b01b5b2bffd02edf3659cd670dc9ddef
blue-team-tools
/
rules
/
windows
/
sysmon
T
History
frack113
d02ee1eddd
Update global ID
2021-09-02 21:16:55 +02:00
..
sysmon_abusing_windows_telemetry_for_persistence.yml
update global id
2021-09-02 21:03:25 +02:00
sysmon_accessing_winapi_in_powershell_credentials_dumping.yml
Merge branch 'master' into falsepositives_NOT_a_list
2021-05-27 10:23:19 +02:00
sysmon_config_modification.yml
Update global ID
2021-09-02 21:16:55 +02:00
sysmon_cve_2021_31979_cve_2021_33771_exploits.yml
Update global ID
2021-09-02 21:16:55 +02:00
sysmon_dcom_iertutil_dll_hijack.yml
Updated rules with modifiers instead of '*' and remove trailing '\\'
2021-06-27 14:51:29 +02:00
sysmon_dns_hybridconnectionmgr_servicebus.yml
Convert eventID 22 to category dns_query
2021-06-10 16:43:33 +02:00
sysmon_pingback_backdoor.yml
update global id
2021-09-02 21:03:25 +02:00
sysmon_wmiprvse_wbemcomn_dll_hijack.yml
Update global ID
2021-09-02 20:07:03 +02:00