Files
blue-team-tools/rules
Cyb3rEng 5bbe3dec9b Completed changes to selection1 and selection2
changes were completed to remove ( * ) and stay within rule creation guide:
    - Image|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'

 WMIcommand|contains: 'Win32_Process\:\:Create'
2021-09-08 21:14:58 -06:00
..
2020-09-13 22:03:04 -06:00
2020-09-15 15:45:33 -06:00
2021-09-07 16:36:59 +01:00
2021-09-02 20:07:03 +02:00
2020-09-13 22:03:04 -06:00
2021-09-07 18:16:46 +02:00
2021-09-07 23:38:07 +02:00