This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
7f66081288135746fcd63f5f12f9beff3bedf2aa
blue-team-tools
/
rules
/
windows
/
process_access
T
History
frack113
b267504708
Merge pull request
#2179
from frack113/fix_sysmon_in_memory_assembly_execution
...
Fix sysmon in memory assembly execution
2021-10-23 10:11:08 +02:00
..
sysmon_cmstp_execution_by_access.yml
…
sysmon_cobaltstrike_bof_injection_pattern.yml
…
sysmon_cred_dump_lsass_access.yml
…
sysmon_direct_syscall_ntopenprocess.yml
…
sysmon_in_memory_assembly_execution.yml
…
sysmon_invoke_phantom.yml
…
sysmon_lazagne_cred_dump_lsass_access.yml
…
sysmon_littlecorporal_generated_maldoc.yml
…
sysmon_load_undocumented_autoelevated_com_interface.yml
…
sysmon_lsass_dump_comsvcs_dll.yml
…
sysmon_lsass_memdump.yml
…
sysmon_malware_verclsid_shellcode.yml
…
sysmon_mimikatz_trough_winrm.yml
…
sysmon_pypykatz_cred_dump_lsass_access.yml
…
sysmon_svchost_cred_dump.yml
…
sysmon_uac_bypass_wow64_logger.yml
…
win_susp_shell_spawn_from_winrm.yml
…