Files
blue-team-tools/rules
4A616D6573 a7a753862c Update win_susp_net_execution.yml
Added:

1. Additional tags for techniques as defined by Atomic Blue.
2. Detection for OriginalFileName as net.exe can easily be renamed.

Part of oscd.community effort.
2019-10-25 12:06:32 +11:00
..
2019-10-07 22:14:44 +02:00
2019-08-05 19:51:22 +02:00
2019-06-08 22:40:28 -04:00
2019-10-25 12:06:32 +11:00