Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
f5fffd8e92b200b77b1708295d753f2d56c491aa
blue-team-tools/rules/windows
T
History
Tim Shelton f5fffd8e92 FP: filters out erl.exe running handle.exe with elevated privileges
2022-12-28 16:44:25 +00:00
..
builtin
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
create_remote_thread
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
create_stream_hash
Merge pull request #3757 from SigmaHQ/aurora-false-positive-fixing
2022-12-05 18:54:31 +01:00
dns_query
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
driver_load
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
file
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
image_load
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
network_connection
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
pipe_created
refactor: remove unnesessary escape.
2022-12-03 21:56:00 +09:00
powershell
Rules for Issue 575 (#3820)
2022-12-27 15:17:45 +01:00
process_access
feat: filename test enhancements (#3812)
2022-12-23 09:25:16 +01:00
process_creation
FP: filters out erl.exe running handle.exe with elevated privileges
2022-12-28 16:44:25 +00:00
raw_access_thread
feat: enhance duplicate test (#3736)
2022-11-29 13:47:09 +01:00
registry
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
sysmon
Refractor (#3794)
2022-12-18 21:00:14 +01:00
wmi_event
Order yaml field
2022-10-25 12:00:56 +02:00
Powered by Gitea Version: 1.26.1 Page: 935ms Template: 26ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API