Files
sigma-rules/rules/macos
Samirbous 326bebdebe [New Rule] Execution via Electron Child Process Node.js Module (#817)
* [New Rule] Execution via Electron ChildProc Node.js Module

* relinted

* fixed TID and adjusted KQL for perf

* fixed kql

* Update rules/macos/execution_defense_evasion_electron_app_childproc_node_js.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/execution_defense_evasion_electron_app_childproc_node_js.toml

Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
2021-01-29 19:06:49 +01:00
..