Files
blue-team-tools/rules
Brad Kish 7e06fd80fd Proposed fix for sysmon_uac_bypass_eventvwr
Issue: https://github.com/Neo23x0/sigma/issues/888

The rules were not merged correctly with the transition to sysmon categories.

Split the rule into separate documents: one for the registry_event and one for
the process_creation
2020-07-06 09:20:34 -04:00
..
2020-05-14 15:53:09 +02:00
2019-11-12 23:12:27 +01:00
2020-02-02 12:41:12 +01:00
2020-06-24 17:04:04 +02:00
2020-05-26 13:18:50 +02:00