Files
blue-team-tools/rules/windows/process_creation
yugoslavskiy 4fa928866f oscd task #6 done.
add 25 new rules:

- win_ad_replication_non_machine_account.yml
- win_dpapi_domain_backupkey_extraction.yml
- win_protected_storage_service_access.yml
- win_dpapi_domain_masterkey_backup_attempt.yml
- win_sam_registry_hive_handle_request.yml
- win_sam_registry_hive_dump_via_reg_utility.yml
- win_lsass_access_non_system_account.yml
- win_ad_object_writedac_access.yml
- powershell_alternate_powershell_hosts.yml
- sysmon_remote_powershell_session_network.yml
- win_remote_powershell_session.yml
- win_scm_database_handle_failure.yml
- win_scm_database_privileged_operation.yml
- sysmon_wmi_module_load.yml
- sysmon_remote_powershell_session_process.yml
- sysmon_rdp_registry_modification.yml
- sysmon_powershell_execution_pipe.yml
- sysmon_alternate_powershell_hosts_pipe.yml
- sysmon_powershell_execution_moduleload.yml
- sysmon_createremotethread_loadlibrary.yml
- sysmon_alternate_powershell_hosts_moduleload.yml
- powershell_remote_powershell_session.yml
- win_non_interactive_powershell.yml
- win_syskey_registry_access.yml
- win_wmiprvse_spawning_process.yml

improve 1 rule:

- rules/windows/builtin/win_account_backdoor_dcsync_rights.yml
2019-11-10 18:43:41 +03:00
..
2019-03-06 00:02:37 +01:00
2019-11-08 01:34:30 +03:00
2019-08-23 23:19:39 +02:00
2019-06-13 23:15:38 -05:00
2019-03-06 06:18:38 +01:00
2019-03-06 00:16:40 +01:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 00:16:40 +01:00
2019-06-13 23:15:38 -05:00
2019-03-16 00:37:09 +01:00
2019-06-13 23:15:38 -05:00
2019-11-08 01:34:30 +03:00
2019-03-06 00:16:40 +01:00
2019-06-13 23:15:38 -05:00
2019-11-08 23:56:14 +01:00
2019-11-08 01:34:30 +03:00
2019-06-13 23:15:38 -05:00
2019-11-08 23:56:14 +01:00
2019-03-02 00:14:20 +01:00
2019-11-08 01:34:30 +03:00
2019-03-06 05:57:01 +01:00
2019-11-08 01:34:30 +03:00
2019-03-06 00:16:40 +01:00
2019-06-13 23:15:38 -05:00
2019-03-02 00:14:20 +01:00
2019-11-08 01:34:30 +03:00
2019-11-08 01:34:30 +03:00
2019-11-08 01:34:30 +03:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-11-08 01:34:30 +03:00
2019-11-08 01:34:30 +03:00
2019-11-08 01:34:30 +03:00
2019-03-06 00:16:40 +01:00
2019-10-14 17:26:33 +02:00
2019-09-04 11:31:00 -04:00
2019-03-06 05:25:12 +01:00
2019-06-13 23:15:38 -05:00
2019-05-09 23:09:22 +02:00
2019-06-13 23:15:38 -05:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-06-13 23:15:38 -05:00
2019-04-04 22:32:47 +02:00
2019-11-08 01:34:30 +03:00