Files
blue-team-tools/rules
Nasreddine Bencherchali 70f3f4fa88 Create win_susp_psloglist.yml
- The flags can be used with both "-" and "/" characters.
- This rule aims to detect any usage of psloglist, no matter if the binary is with the original name or not. This is achieved by looking for both the image name and the specific command line arguments
2021-12-18 21:52:05 +01:00
..
2021-11-27 11:33:14 +01:00
2021-11-27 11:33:14 +01:00
2021-11-23 18:47:42 +01:00
2021-11-27 11:33:14 +01:00
2021-12-10 16:45:42 +01:00
2021-12-01 14:20:05 +01:00
2021-12-16 12:12:37 -05:00
2021-12-18 21:52:05 +01:00