This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
65eb06e231bd428bccedf5ee097e2cb68bc42bf3
blue-team-tools
/
rules
/
windows
T
History
frack113
65eb06e231
Merge pull request
#3876
from frack113/fix_fp_gfx
...
Update proc_creation_win_susp_file_download_via_gfxdownloadwrapper.yml
2023-01-06 13:48:31 +01:00
..
builtin
update logsource
2023-01-04 18:52:24 +01:00
create_remote_thread
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
create_stream_hash
Fix invalid field cast or name (
#3841
)
2022-12-30 11:46:21 +01:00
dns_query
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
driver_load
Fix invalid field cast or name (
#3841
)
2022-12-30 11:46:21 +01:00
file
feat: updates and enhancements
2023-01-04 17:49:32 +01:00
image_load
Last lolbin (
#3845
)
2022-12-31 19:53:44 +01:00
network_connection
Fix invalid field cast or name (
#3841
)
2022-12-30 11:46:21 +01:00
pipe_created
fix: remove unneeded double backslash escape (
#3844
)
2022-12-31 08:32:46 +01:00
powershell
fix: other typos
2023-01-04 17:53:24 +01:00
process_access
fix: remove unneeded double backslash escape (
#3844
)
2022-12-31 08:32:46 +01:00
process_creation
Merge pull request
#3876
from frack113/fix_fp_gfx
2023-01-06 13:48:31 +01:00
raw_access_thread
feat: enhance duplicate test (
#3736
)
2022-11-29 13:47:09 +01:00
registry
feat: updates and enhancements
2023-01-04 17:49:32 +01:00
sysmon
fix: update modified date
2023-01-03 10:37:09 +01:00
wmi_event
Order yaml field
2022-10-25 12:00:56 +02:00