Files
blue-team-tools/rules/proxy
Tomasuh b5d5a648b5 proxy_ua_bitsadmin_susp_ip.yml falsepositive fix
Change to endswith instead of startswith to avoid matching subdomains which starts with digits, example: 3.au.download.windowsupdate.com
2022-08-24 08:19:51 +02:00
..
2022-01-19 18:23:30 +01:00
2021-11-27 11:33:14 +01:00
2022-01-19 18:23:30 +01:00
2021-12-01 14:20:05 +01:00
2022-08-18 13:02:11 +02:00