Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
737525227ff1d6f13ff4c38af6bc5a41dc274e4a
blue-team-tools/rules/windows
T
History
Nasreddine Bencherchali 737525227f fix: update logsource.json
2023-02-27 13:20:29 +01:00
..
builtin
fix: FP with empty user and ip address
2023-02-23 11:38:47 +01:00
create_remote_thread
fix: resolves #4015
2023-02-07 14:33:56 +01:00
create_stream_hash
fix: change title from domain to wbesites
2023-02-10 10:49:52 +01:00
dns_query
fix: update logsource.json
2023-02-27 13:20:29 +01:00
driver_load
fix: typos in multiple rules (#4011)
2023-02-06 13:53:23 +01:00
file
Update and rename file_event_win_apt_cozy_bear_phishing_campaing_indicators.yml to file_event_win_apt_cozy_bear_phishing_campaign_indicators.yml
2023-02-20 14:10:03 +01:00
image_load
fix: apply suggestions from code review
2023-02-20 12:06:37 +01:00
network_connection
New rules added for LockBit and Reddit used for C2. (#4045)
2023-02-20 12:07:02 +01:00
pipe_created
fix: resolves #4015
2023-02-07 14:33:56 +01:00
powershell
fix: FP with chocolatey
2023-02-21 16:38:05 +01:00
process_access
fix: reduce author set
2023-02-01 14:34:46 +01:00
process_creation
Update proc_creation_win_hktl_jlaive_batch_execution.yml
2023-02-22 17:13:48 +01:00
raw_access_thread
fix: more fp found in testing
2023-01-18 20:16:34 +01:00
registry
Update registry_add_persistence_amsi_providers.yml
2023-02-20 14:11:11 +01:00
sysmon
fix: typos in multiple rules (#4011)
2023-02-06 13:53:23 +01:00
wmi_event
chore: add nextron authors tag
2023-02-01 11:14:59 +01:00
Powered by Gitea Version: 1.26.1 Page: 465ms Template: 17ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API