Files
sigma-rules/rules/windows
Austin Songer 17032194d8 [Rule Tuning] Suspicious WerFault Child Process (#915)
* Update defense_evasion_masquerading_suspicious_werfault_childproc.toml

Added Article "How to Design Abnormal Child Processes Rules without Telemetry"

* bump updated_date

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
2021-02-10 14:17:57 -05:00
..