Files
blue-team-tools/rules/windows/process_creation
Swachchhanda Shrawan Poudel 7509f6ab6b
Create Release / Create Release (push) Has been cancelled
Merge PR #4698 from @swachchhanda000 - Added rules that detect possible activities associated with services and modules enumeration
new: Interesting Service Enumeration Via Sc.EXE
new: Loaded Module Enumeration Via Tasklist.EXE
fix: SC.EXE Query Execution - Add keybase filter 

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2024-02-12 14:45:36 +01:00
..