Jonhnathan
c0f12ddecf
[Rule Tuning] Tighten Up Windows EventLog Indexes, Improve tags ( #4464 )
...
* [Rule Tuning] Tighten Up Windows EventLog Indexes, Improve tags
* Format & order
* Update pyproject.toml
* Update credential_access_cookies_chromium_browsers_debugging.toml
2025-02-19 12:54:31 -03:00
Mika Ayenson
fe8c81d762
[FR] Generate investigation guides ( #4358 )
2025-01-22 11:17:38 -06:00
Jonhnathan
1d9cb6a195
[Rule Tuning] Active Directory Forced Authentication from Linux Host - SMB Named Pipes ( #4117 )
...
* [Rule Tuning] Active Directory Forced Authentication from Linux Host - SMB Named Pipes
* Update rules/cross-platform/credential_access_forced_authentication_pipes.toml
2024-10-11 13:46:57 -03:00
Jonhnathan
fcc8aaaf63
[Rule Tuning] Fix missing Winlogbeat index ( #3976 )
...
* [Rule Tuning] Fix missing Winlogbeat index
* bump
2024-08-09 12:46:33 -03:00
Jonhnathan
f5069763b6
[Rule Tuning] Add System tag to DRs ( #3968 )
...
* [Rule Tuning] Add System tag to DRs
* bump
2024-08-09 11:14:33 -03:00
Jonhnathan
896946ad1b
[New Rule] Active Directory Forced Authentication from Linux Host - SMB Named Pipes ( #3917 )
...
* [New Rule] Active Directory Forced Authentication from Linux Host via SMB Pipes
* Update credential_access_forced_authentication_pipes.toml
* Update rules/cross-platform/credential_access_forced_authentication_pipes.toml
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
2024-07-24 12:01:10 -03:00