Files
blue-team-tools/rules/windows/process_creation
Ali Alwashali bb97300f1f Merge PR #4532 from @alwashali - Update EventLog Query Related Rules
new: EventLog Query Requests By Builtin Utilities
update: Potentially Suspicious EventLog Recon Activity Using Log Query Utilities - Enhanced logic from simply covering wevtutil to covering other tools and conditions.

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-11-20 12:47:01 +01:00
..