Files
blue-team-tools/rules/windows/process_creation
jkb f316469cd7 Fixing selection_user to match NT AUTHORITY\SYSTEM
This should be 'SYSTEM' not ' SYSTEM ' - these leading/trailing spaces are making this detection invalid since the /RU parameter value will be "NT AUTHORITY\SYSTEM".
2022-08-26 00:25:04 +02:00
..
2022-03-07 17:11:00 +01:00
2022-03-17 16:48:41 +01:00
2022-08-22 14:52:41 +01:00
2022-08-13 12:11:32 +02:00
2022-08-22 14:52:41 +01:00
2022-08-20 00:49:39 +02:00
2022-08-22 17:43:49 +02:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-06-21 11:47:18 +01:00