This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
e9af2fb119363efcd23435f8eebc059c3052d570
blue-team-tools
/
rules
/
windows
T
History
Thomas Patzke
d73447c111
Merge pull request
#939
from ktecv2000/master
...
add wmi persistence script event consumer false positive
2020-08-05 23:28:26 +02:00
..
builtin
Merge pull request
#952
from Neo23x0/devel
2020-07-28 10:21:59 +02:00
deprecated
fix: buggy rule
2020-05-23 18:32:02 +02:00
driver_load
fix: bugfix and cosmetics
2020-06-24 18:10:58 +02:00
file_event
add wmi persistence script event consumer false positive
2020-07-20 12:27:16 +08:00
image_load
Updated tags to include sub-techniques
2020-07-18 02:50:57 +01:00
malware
Further subtechnique updates
2020-06-17 11:31:40 -06:00
network_connection
Updated tags to include sub-techniques
2020-07-18 02:50:57 +01:00
other
Updated to include extra registry key
2020-07-18 02:37:11 +01:00
powershell
Merge branch 'master' of github.com:Neo23x0/sigma
2020-07-15 10:27:33 -04:00
process_access
Updated invoke_phantom with sub-technique mapping
2020-07-18 02:32:42 +01:00
process_creation
Merge pull request
#936
from rtkmokuka/typo_wmiprvse_spawning_process
2020-08-05 23:26:14 +02:00
registry_event
Updated suspicious service with sub-techniques
2020-07-18 02:40:22 +01:00
sysmon
Update sysmon_password_dumper_lsass.yml
2020-07-23 14:31:21 +02:00