Tim Burrell (MSTIC)
c24bbdcf81
Sigma queries for
...
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-24 15:31:06 +01:00
..
2019-11-12 23:12:27 +01:00
2019-12-20 14:59:26 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-12-05 09:56:20 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-01-24 15:31:06 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-12-20 15:18:05 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00