Files
blue-team-tools/deprecated
Swachchhanda Shrawan Poudel 0c2b76e7d9 Merge PR #5622 from @swachchhanda000 - fix duplicate and fps
remove: PowerShell DownloadFile - Deprecated in favour of 3b6ab547-8ec2-4991-b9d2-2b06702a48d7
remove: Whoami Utility Execution - Deprecated in favor of 502b42de-4306-40b4-9596-6f590c81f073
fix: Usage Of Web Request Commands And Cmdlets - ScriptBlock - Commented out Net.webclient
fix: Usage Of Web Request Commands And Cmdlets - Comment out Net.webclient
fix: System Disk And Volume Reconnaissance via Wmic.EXE - update the rule logic to remove potential FPs
update: PowerShell Download Pattern - add powershell_ise
update: Use Short Name Path in Image - change detection logic structure
update: Local Accounts Discovery - add OriginalFileName field

---------
Co-authored-by: nasbench <nasbench@users.noreply.github.com>
2025-10-20 09:08:28 +05:45
..

Deprecated folder

This folder contains all rules that have been marked as deprecated.

It is recommended to avoid using these rules, as they are no longer maintained or supported.

For a summary of the deprecated rules, refer to deprecated.csv or deprecated.json

references

https://github.com/SigmaHQ/sigma-specification/blob/main/specification/sigma-rules-specification.md#status