Files
blue-team-tools/rules
webboy2015 87df79302d Update win_lolbas_execution_of_nltest.exe
Changed condition as follows:
   detection:
       selection:
          EventID: 4689
          ProcessName|endswith: nltest.exe
          Status: "0x0"
     condition: selection

Included  field - SubjectDomainName
2021-10-01 12:55:37 -07:00
..
2021-09-21 20:16:26 +02:00
2021-09-25 11:37:39 +02:00