Files
blue-team-tools/rules/windows
Tim Burrell (MSTIC) c24bbdcf81 Sigma queries for
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-24 15:31:06 +01:00
..
2019-11-14 22:26:22 +01:00
2019-11-12 23:12:27 +01:00
2020-01-24 15:31:06 +01:00