Files
blue-team-tools/rules/windows/sysmon
Cyb3rEng fe9b91c504 Completed changes to selection1
changed to the following to follow rule creation guidelines:
    - Image|endswith: '\wbem\WMIC.exe'
    - ProcessCommandLine|contains: 'wmic '
2021-09-08 21:26:01 -06:00
..
2021-09-02 21:03:25 +02:00