Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
b2e9b47e9105aa43aeafcfa1cf4121ba76a46adb
blue-team-tools/rules/windows
T
History
Arnim Rupp b2e9b47e91 feat: add new domain to rules related to 3CX compromise (#4154)
2023-03-30 13:18:11 +02:00
..
builtin
fix: FP found in testing
2023-03-23 10:52:08 +01:00
create_remote_thread
feat: update and fixes
2023-03-09 22:10:42 +01:00
create_stream_hash
fix: change title from domain to wbesites
2023-02-10 10:49:52 +01:00
dns_query
feat: add new domain to rules related to 3CX compromise (#4154)
2023-03-30 13:18:11 +02:00
driver_load
fix: typos in multiple rules (#4011)
2023-02-06 13:53:23 +01:00
file
Add office filter
2023-03-29 06:42:21 +02:00
image_load
Fix FP
2023-03-28 14:55:57 +02:00
network_connection
feat: add new domain to rules related to 3CX compromise (#4154)
2023-03-30 13:18:11 +02:00
pipe_created
fix: resolves #4015
2023-02-07 14:33:56 +01:00
powershell
fix: condition filtering on all filters
2023-03-24 10:59:01 +01:00
process_access
fix: remove version number
2023-03-23 12:11:29 +01:00
process_creation
feat: new rule related to susp child process of 3CXDesktopApp (#4153)
2023-03-30 00:36:02 +02:00
raw_access_thread
fix: more fp found in testing
2023-01-18 20:16:34 +01:00
registry
feat: new rules related to ZScaler blog - OneNote: A Growing Threat for Malware Distribution (#4111)
2023-03-17 13:00:57 +01:00
sysmon
fix: typos in multiple rules (#4011)
2023-02-06 13:53:23 +01:00
wmi_event
chore: add nextron authors tag
2023-02-01 11:14:59 +01:00
Powered by Gitea Version: 1.26.1 Page: 539ms Template: 10ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API