Files
sigma-rules/rules/macos
Samirbous 18a4e468ce [New Rule] Attempt to Unload Elastic Endpoint Security Kernel Extension (#807)
* [New Rule] Attempt to Unload Elastic Endpoint Security Kernel Extension

* Update rules/macos/defense_evasion_unload_endpointsecurity_kext.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/defense_evasion_unload_endpointsecurity_kext.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/defense_evasion_unload_endpointsecurity_kext.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* added subtechnique

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
2021-02-08 22:22:16 +01:00
..