Files
sigma-rules/rules/windows
Andrew Pease 7c336a0a91 [New Rule] DefenderControl Activity (#769)
* initial commit

* updated to eql and registry vs. file

* fix updated_date format

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/windows/defense_evasion_defendercontrol_activity.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* changed name and added registry value 3 or 4

* remove duplicate

* fixed date format and lint

* updated indices

* removed fp and updated description

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
2021-02-09 10:12:54 -06:00
..