Files
blue-team-tools/rules/windows/process_creation
yugoslavskiy 701e7f7cc6 oscd task #2 completed
- new rules:

	+ rules/windows/builtin/win_susp_lsass_dump_generic.yml
	+
rules/windows/builtin/win_transferring_files_with_credential_data_via_ne
twork_shares.yml
	+
rules/windows/builtin/win_remote_registry_management_using_reg_utility.y
ml
	+ rules/windows/sysmon/sysmon_unsigned_image_loaded_into_lsass.yml
	+ rules/windows/sysmon/sysmon_lsass_memory_dump_file_creation.yml
	+
rules/windows/sysmon/sysmon_raw_disk_access_using_illegitimate_tools.yml
	+ rules/windows/sysmon/sysmon_cred_dump_tools_dropped_files.yml
	+ rules/windows/sysmon/sysmon_cred_dump_tools_named_pipes.yml
	+
rules/windows/process_creation/process_creation_shadow_copies_creation.y
ml
	+
rules/windows/process_creation/process_creation_shadow_copies_deletion.y
ml
	+
rules/windows/process_creation/process_creation_copying_sensitive_files_
with_credential_data.yml
	+
rules/windows/process_creation/process_creation_shadow_copies_access_sym
link.yml
	+
rules/windows/process_creation/process_creation_grabbing_sensitive_hives
_via_reg.yml
	+
rules/windows/process_creation/process_creation_mimikatz_command_line.ym
l
	+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_dcsync.yml
	+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_netsync.yml
.yml

- updated rules:

	+ rules/windows/builtin/win_susp_raccess_sensitive_fext.yml
	+ rules/windows/builtin/win_mal_creddumper.yml
	+ rules/windows/builtin/win_mal_service_installs.yml
	+ rules/windows/process_creation/win_susp_process_creations.yml
	+ rules/windows/sysmon/sysmon_powershell_exploit_scripts.yml
	+ rules/windows/sysmon/sysmon_mimikatz_detection_lsass.yml

- deprecated rules:

	+ rules/windows/process_creation/win_susp_vssadmin_ntds_activity.yml
2019-11-04 04:26:34 +03:00
..
2019-03-06 00:02:37 +01:00
2019-08-23 23:19:39 +02:00
2019-06-13 23:15:38 -05:00
2019-03-06 06:18:38 +01:00
2019-03-06 00:16:40 +01:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 00:16:40 +01:00
2019-06-13 23:15:38 -05:00
2019-03-16 00:37:09 +01:00
2019-06-13 23:15:38 -05:00
2019-03-06 00:16:40 +01:00
2019-06-13 23:15:38 -05:00
2019-06-13 23:15:38 -05:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:57:01 +01:00
2019-03-06 00:16:40 +01:00
2019-06-13 23:15:38 -05:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 00:16:40 +01:00
2019-10-14 17:26:33 +02:00
2019-03-06 05:25:12 +01:00
2019-06-13 23:15:38 -05:00
2019-05-09 23:09:22 +02:00
2019-06-13 23:15:38 -05:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-06-13 23:15:38 -05:00
2019-04-04 22:32:47 +02:00