Files
blue-team-tools/rules/windows/sysmon
Sander Wiebing b8ee736f44 Remove AppData folder as suspicious folder
A lot of software is using the AppData folder for startup keys. Some examples:
- Microsoft Teams (\AppData\Local\Microsoft\Teams)
- Resilio (\AppData\Roaming\Resilio Sync\)
- Discord ( (\AppData\Local\Discord\)
- Spotify ( (\AppData\Roaming\Spotify\)

Too many to whitelist them all
2020-05-24 15:16:07 +02:00
..
2020-02-20 23:00:16 +01:00
2019-11-12 23:12:27 +01:00
2020-04-14 13:40:34 +02:00
2020-05-18 10:03:18 -04:00