Files
blue-team-tools/rules/windows/process_creation
EzLucky ff558d8561 Merge PR #5663 from @EzLucky - improve coverage of werfaultsecure in EDR process freeze rule
update: Suspicious Process Suspension via WERFaultSecure through EDR-Freeze - refine image path logic and include OriginalFileName for improved rule accuracy

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-10-17 07:23:23 +05:45
..