Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
d5146fe0d4f90d91df91b25ca75580bb43ef46f6
blue-team-tools/rules/windows
T
History
Nasreddine Bencherchali d5146fe0d4 Update file_event_win_winword_cve_2021_40444.yml
2022-06-17 11:53:17 +01:00
..
builtin
fix: FPs with BITS rule
2022-06-12 17:30:17 +02:00
create_remote_thread
Add "\" to "Image|endswith" modifier
2022-06-02 13:39:07 +01:00
create_stream_hash
…
dns_query
refactor condition
2022-06-03 15:35:24 +02:00
driver_load
refactor condition
2022-06-03 15:35:24 +02:00
file_access
…
file_delete
Add "\" to "Image|endswith" modifier
2022-06-02 13:39:07 +01:00
file_event
Update file_event_win_winword_cve_2021_40444.yml
2022-06-17 11:53:17 +01:00
file_rename
fix: casing of OriginalFileName
2022-06-08 17:14:49 +02:00
image_load
Add "\" to "Image|endswith" modifier
2022-06-02 13:39:07 +01:00
network_connection
Add "\" to "Image|endswith" modifier
2022-06-02 13:39:07 +01:00
pipe_created
refactor condition
2022-06-03 15:35:24 +02:00
powershell
False positive - another amazon module filter
2022-06-08 19:00:12 +00:00
process_access
fix: FP and typo
2022-06-03 15:20:07 +02:00
process_creation
Update proc_creation_win_lolbin_openconsole.yml
2022-06-16 23:41:57 +01:00
raw_access_thread
…
registry
Update registry_set_enabling_turnoffcheck.yml
2022-06-15 11:49:38 -04:00
sysmon
…
wmi_event
refactor condition
2022-06-03 15:35:24 +02:00
Powered by Gitea Version: 1.26.1 Page: 1218ms Template: 83ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API