Files
blue-team-tools/rules
Cyb3rEng fe9b91c504 Completed changes to selection1
changed to the following to follow rule creation guidelines:
    - Image|endswith: '\wbem\WMIC.exe'
    - ProcessCommandLine|contains: 'wmic '
2021-09-08 21:26:01 -06:00
..
2020-09-13 22:03:04 -06:00
2020-09-15 15:45:33 -06:00
2021-09-07 16:36:59 +01:00
2021-09-02 20:07:03 +02:00
2020-09-13 22:03:04 -06:00
2021-09-07 18:16:46 +02:00
2021-09-07 23:38:07 +02:00
2021-09-08 21:26:01 -06:00