Files
sigma-rules/rules/windows
Samirbous 58174015bd [New Rule] Privilege Escalation via Windir Environment Variable (#638)
* [New Rule] Privilege Escalation via Windir Environment Variable

* added equiv envar

* eql syntax

* Update rules/windows/privilege_escalation_rogue_windir_environment_var.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* ecs_version

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
2020-12-08 16:21:42 +01:00
..