This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
4e16bbafa81e3261d16759f51e632e8ad12c741f
blue-team-tools
/
rules
/
windows
T
History
Florian Roth
17470d1545
Rule: extended parent list for legitimate svchost starts
...
https://twitter.com/Sam0x90/status/1117768799816753153
2019-04-15 14:54:35 +02:00
..
builtin
Update win_lm_namedpipe.yml
2019-04-04 18:22:50 +02:00
malware
Update win_mal_ursnif.yml
2019-04-14 11:51:13 -05:00
other
Converted to use the new process_creation data source
2019-03-09 20:57:59 +03:00
powershell
Added missing tags and some minor improvements
2019-03-05 23:25:49 +01:00
process_creation
Rule: extended parent list for legitimate svchost starts
2019-04-15 14:54:35 +02:00
sysmon
Rule: added date to Tom's WMI rule
2019-04-15 09:06:53 +02:00