Files
blue-team-tools/rules/windows/process_creation
gs3cl 92b72ffdc1 Update win_nltest_query.yml
modification based on new reports

1.https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11) 
-> for (selection_recon1 and seletion_recon2")
2.https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters -> nltest example
3.MITRE reference just for reference to MITRE to gain more insights
4.https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/ 
-> new Report about Trickbot with reference and usage of "nltest" therefore I included the option in this rule
2021-08-18 20:45:18 +00:00
..
2021-08-07 15:54:43 +02:00
2021-08-06 18:45:38 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-02-07 15:47:27 +01:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-12-08 10:15:30 +01:00
2021-07-07 09:05:00 +02:00
2021-07-01 12:18:30 +05:45
2021-07-31 10:18:21 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-01-11 00:11:27 +01:00
2021-08-16 15:50:14 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-08-12 13:27:51 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-27 10:34:46 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-02-20 23:00:16 +01:00
2021-07-09 16:41:03 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45