Files
blue-team-tools/rules/windows
Cyb3rEng 5bbe3dec9b Completed changes to selection1 and selection2
changes were completed to remove ( * ) and stay within rule creation guide:
    - Image|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'

 WMIcommand|contains: 'Win32_Process\:\:Create'
2021-09-08 21:14:58 -06:00
..
2021-08-21 09:58:58 +02:00
2021-07-01 12:18:30 +05:45
2021-08-24 10:27:27 +02:00
2021-08-24 10:27:27 +02:00
2021-09-08 00:19:09 +02:00
2021-09-02 21:16:55 +02:00
2021-09-02 21:03:25 +02:00
2021-09-07 23:38:07 +02:00
2021-09-07 23:38:07 +02:00
2021-09-08 20:38:07 -06:00