This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
3
Packages
Projects
Releases
Wiki
Activity
Files
749a7b4df558a84778db0d0f2a4fbc276f452c2f
blue-team-tools
/
rules
/
windows
/
process_access
T
History
Nasreddine Bencherchali
238e0ecd7d
Update Ref+Selection
2022-07-11 14:11:53 +01:00
..
proc_access_win_cmstp_execution_by_access.yml
…
proc_access_win_cobaltstrike_bof_injection_pattern.yml
…
proc_access_win_cred_dump_lsass_access.yml
…
proc_access_win_direct_syscall_ntopenprocess.yml
…
proc_access_win_handlekatz_lsass_access.yml
…
proc_access_win_in_memory_assembly_execution.yml
…
proc_access_win_invoke_phantom.yml
…
proc_access_win_lazagne_cred_dump_lsass_access.yml
…
proc_access_win_littlecorporal_generated_maldoc.yml
…
proc_access_win_load_undocumented_autoelevated_com_interface.yml
…
proc_access_win_lsass_dump_comsvcs_dll.yml
…
proc_access_win_lsass_memdump_evasion.yml
Update Ref+Selection
2022-07-11 14:11:53 +01:00
proc_access_win_lsass_memdump_indicators.yml
Update Ref+Selection
2022-07-11 14:11:53 +01:00
proc_access_win_lsass_memdump.yml
Update Ref+Selection
2022-07-11 14:11:53 +01:00
proc_access_win_lsass_werfault.yml
…
proc_access_win_malware_verclsid_shellcode.yml
…
proc_access_win_mimikatz_trough_winrm.yml
…
proc_access_win_pypykatz_cred_dump_lsass_access.yml
…
proc_access_win_rare_proc_access_lsass.yml
Merge branch 'master' into aurora-false-positive-fixing
2022-07-07 18:21:16 +02:00
proc_access_win_susp_proc_access_lsass_susp_source.yml
Update Ref+Selection
2022-07-11 14:11:53 +01:00
proc_access_win_susp_proc_access_lsass.yml
Update Ref+Selection
2022-07-11 14:11:53 +01:00
proc_access_win_svchost_cred_dump.yml
…
proc_access_win_uac_bypass_wow64_logger.yml
…
process_access_win_shellcode_inject_msf_empire.yml
…
process_access_win_susp_seclogon.yml
…