Files
blue-team-tools/rules/windows
Cyb3rEng fe9b91c504 Completed changes to selection1
changed to the following to follow rule creation guidelines:
    - Image|endswith: '\wbem\WMIC.exe'
    - ProcessCommandLine|contains: 'wmic '
2021-09-08 21:26:01 -06:00
..
2021-08-21 09:58:58 +02:00
2021-07-01 12:18:30 +05:45
2021-08-24 10:27:27 +02:00
2021-08-24 10:27:27 +02:00
2021-09-08 00:19:09 +02:00
2021-09-02 21:16:55 +02:00
2021-09-02 21:03:25 +02:00
2021-09-07 23:38:07 +02:00
2021-09-07 23:38:07 +02:00
2021-09-08 21:22:26 -06:00
2021-09-08 21:26:01 -06:00