Files
blue-team-tools/rules/windows/sysmon
Thomas Patzke 5706361464 Parsing of "near ... within" aggregation operator
* Operator is only parsed. No processing or passing of parsed data to
  backends.
* Changed rule sysmon_mimikatz_inmemory_detection.yml accordingly.
2017-08-03 00:05:48 +02:00
..
2017-04-07 15:42:08 +02:00
2017-05-25 12:06:23 +02:00
2017-04-13 01:08:37 +02:00