Files
blue-team-tools/rules/windows
4A616D6573 a7a753862c Update win_susp_net_execution.yml
Added:

1. Additional tags for techniques as defined by Atomic Blue.
2. Detection for OriginalFileName as net.exe can easily be renamed.

Part of oscd.community effort.
2019-10-25 12:06:32 +11:00
..
2019-10-11 18:50:33 +02:00
2019-09-06 03:54:19 -04:00