Files
blue-team-tools/rules/windows/process_creation
Swachchhanda Shrawan Poudel d27d120401
Create Release / Create Release (push) Has been cancelled
Merge PR #5183 from @swachchhanda000 - add rules for malware abusing grimresource and RTLO techniques
new: MMC Loading Script Engines DLLs
new: Potentially Suspicious Child Processes Spawned by ConHost
new: Scheduled Task Creation Masquerading as System Processes
new: Schtasks Curl Download and Powershell Execution Combination
new: MMC Executing Files with Reversed Extensions Using RTLO Abuse
update: Potential Defense Evasion Via Right-to-Left Override - add `[U+202E]`
update: Potential File Extension Spoofing Using Right-to-Left Override - add `[U+202E]` and more extensions

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-10-01 14:16:23 +02:00
..