Files
sigma-rules/rules/windows
Samirbous 8126bde72c [Rule Tuning] Suspicious Process Creation CallTrace (#2207)
Excluding some FPs by process.parent.executable and process.parent.args.

(cherry picked from commit 04dcf09c03)
2022-08-01 17:01:08 +00:00
..