Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
691dca6fd2cac002bec9f158bb3ecf4c679a76fa
blue-team-tools/rules
T
History
frack113 691dca6fd2 Merge PR #4808 from @frack113 - FP Bad practice GPO
fix: Windows Binaries Write Suspicious Extensions - Add new filter for when "bat" or "powershell" scripts are written via GPO to run at startup.

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2024-04-15 13:43:35 +02:00
..
application
Merge PR #4694 from @LAripping - Add native Kubernetes detections
2024-03-26 18:26:46 +01:00
category
Merge PR #4533 from @nasbench - Promote experimental rules
2023-11-02 10:48:45 +01:00
cloud
Merge PR #4791 from @nasbench - Promote older rules status from experimental to test
2024-04-01 15:14:10 +02:00
compliance
Merge PR #4681 from @nasbench - Add Missing Ref & Tags
2024-01-29 13:37:20 +01:00
linux
Merge PR #4791 from @nasbench - Promote older rules status from experimental to test
2024-04-01 15:14:10 +02:00
macos
Merge PR #4759 from @joshnck - Add new rules covering incoming TeamViewer connection activity
2024-03-15 21:41:29 +01:00
network
Merge PR #4765 from @frack113 - Update additional rules to use the cidr modifier
2024-03-13 14:51:21 +01:00
web
Merge PR #4815 from - Add new malware user-Agent
2024-04-15 10:26:56 +02:00
windows
Merge PR #4808 from @frack113 - FP Bad practice GPO
2024-04-15 13:43:35 +02:00
README.md
chore: move more rules
2023-04-21 15:01:48 +02:00

README.md

TBD

Reference in New Issue View Git Blame Copy Permalink
Powered by Gitea Version: 1.26.1 Page: 1333ms Template: 13ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API