Files
blue-team-tools/rules/windows/process_creation
Furkan ÇALIŞKAN edb5b7718e Deleted a part of an already-defined rule
Lolbin rule for explorer.exe proxy execution;

Test scenario;

cd c:\windows\system32
explorer.exe calc.exe
(pops calc.exe) as in https://twitter.com/bohops/status/986984122563391488/photo/1
2020-10-11 21:08:17 +03:00
..
2020-02-07 15:47:27 +01:00
2020-02-02 12:41:12 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-09-03 09:18:28 +02:00
2019-11-12 23:12:27 +01:00
2020-01-11 00:11:27 +01:00
2020-02-20 23:00:16 +01:00
2020-02-02 12:41:12 +01:00
2020-09-26 17:03:29 +02:00
2019-11-12 23:12:27 +01:00
2020-09-13 15:46:45 +02:00
2020-10-09 09:26:01 +03:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-10-09 11:59:08 +03:00
2019-11-12 23:12:27 +01:00
2020-02-20 23:00:16 +01:00
2020-02-02 12:41:12 +01:00