Files
sigma-rules/rules/windows
Samirbous 8e139012f7 [Rule Tuning] Unusual Process Execution Path - Alternate Data Stream (#1014)
* [Rule Tuning] Unusual Process Execution Path - Alternate Data Stream

* Revert "[Rule Tuning] Unusual Process Execution Path - Alternate Data Stream"

This reverts commit 2bf2c33002f08fec1d9cc64da9795bb189625e4d.

* [Rule Tuning] Unusual Process Execution Path - Alternate Data Stream

* Update rules/windows/defense_evasion_unusual_dir_ads.toml

Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>

Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
2021-03-19 09:45:57 +01:00
..