Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
fdbdca003b9db506e20d926c26bf07f68a55639c
blue-team-tools/rules/windows
T
History
4A616D6573 fdbdca003b Create win_powershell_web_request.yml
Broader rule for detecting web requests via various methods using Windows PowerShell, slightly crosses over the below rules but caters for different methods:

https://github.com/Neo23x0/sigma/blob/99b15edf8add183543ca5738ec93f87416c34bd9/rules/windows/process_creation/win_powershell_download.yml
https://github.com/Neo23x0/sigma/blob/0fa914139ca85966b49f0a8eda40a3f26608e86b/rules/windows/powershell/powershell_suspicious_download.yml
2019-10-24 11:57:37 +11:00
..
builtin
rule: mimikatz use extended
2019-10-11 18:50:33 +02:00
malware
rules: AV rules updated to reflect 1.7.2 auf AV cheat sheet
2019-10-04 16:17:34 +02:00
other
Converted to use the new process_creation data source
2019-03-09 20:57:59 +03:00
powershell
Create win_powershell_web_request.yml
2019-10-24 11:57:37 +11:00
process_creation
rule: another reference link for 'execution by ordinal'
2019-10-22 15:18:19 +02:00
sysmon
fix: relevant fields in lsass dll load rule
2019-10-16 19:09:20 +02:00
Powered by Gitea Version: 1.26.1 Page: 64ms Template: 4ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API