Files
blue-team-tools/rules/windows
Nasreddine Bencherchali 67d1036566 Merge pull request #4390 from @nasbench - CVE-2023-36874
new: Potential CVE-2023-36874 Exploitation - Uncommon Report.Wer Location
new: Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation
new: Potential CVE-2023-36874 Exploitation - Fake Wermgr Execution
new: Suspicious Execution Location Of Wermgr.EXE - split from 396f6630-f3ac-44e3-bfc8-1b161bc00c4e
update: Potential Defense Evasion Via Rename Of Highly Relevant Binaries - enhanced child process list
update: Suspicious Child Process Of Wermgr.EXE - update title
fix: SCR File Write Event - update modifier

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-08-24 12:50:57 +02:00
..
2023-07-28 14:32:57 +02:00
2023-08-07 16:09:21 +02:00
2023-08-08 11:06:37 +02:00
2023-07-20 15:47:14 +02:00
2023-02-01 11:14:59 +01:00