Files
blue-team-tools/rules/windows/builtin
Karneades 68fd20cb66 fix: bound windows event log rules to message field
Fixed rules
- rules/windows/builtin/win_susp_msmpeng_crash.yml
- rules/windows/builtin/win_alert_active_directory_user_control.yml
- rules/windows/builtin/win_av_relevant_match.yml
- rules/windows/builtin/win_mal_creddumper.yml
- rules/windows/builtin/win_susp_sam_dump.yml
- rules/windows/builtin/win_alert_mimikatz_keywords.yml
- rules/windows/builtin/win_alert_enable_weak_encryption.yml
2019-11-02 11:25:29 +01:00
..
2019-03-16 00:37:09 +01:00
2019-06-13 23:15:38 -05:00
2019-03-14 00:44:26 +01:00
2019-06-13 23:15:38 -05:00
2018-09-20 12:44:44 +02:00
2019-06-13 23:15:38 -05:00
2019-06-13 23:15:38 -05:00
2019-06-13 23:15:38 -05:00
2019-06-13 23:15:38 -05:00
2019-06-13 23:15:38 -05:00
2019-06-13 23:15:38 -05:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-06-13 23:15:38 -05:00
2019-06-29 15:35:59 +03:00
2019-03-06 00:43:42 +01:00
2019-04-03 21:50:25 +02:00
2018-09-20 12:44:44 +02:00
2019-03-06 00:43:42 +01:00
2019-03-06 05:25:12 +01:00