This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
e248012783f396fb202d30baa3e3370c00a82e23
blue-team-tools
/
rules
/
windows
/
sysmon
T
History
Florian Roth
19171f5bed
Merge pull request
#1315
from rtkdmasse/split-up-cmstp-rule
...
Split up cmstp rule into 3 separate rules and remove duplicates
2021-01-09 10:30:33 +01:00
..
sysmon_ads_executable.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_alternate_powershell_hosts_pipe.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_apt_turla_namedpipes.yml
refactor: moved rues from 'apt' folder in respective folders
2020-02-01 17:59:26 +01:00
sysmon_cactustorch.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_cobaltstrike_process_injection.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_createremotethread_loadlibrary.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_cred_dump_tools_named_pipes.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_mal_namedpipes.yml
Add Covenant default named pipe
2019-12-18 15:19:47 +00:00
sysmon_password_dumper_lsass.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_possible_dns_rebinding.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_raw_disk_access_using_illegitimate_tools.yml
Rule fixes
2020-02-20 23:00:16 +01:00
sysmon_susp_powershell_rundll32.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_suspicious_remote_thread.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_wmi_event_subscription.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00
sysmon_wmi_susp_scripting.yml
review windows/sysmon
2020-08-29 02:03:28 +02:00