Wietze
|
ebbf08ec4d
|
Adding tags (closes #9, #318) (#362)
* Adding various tags as a first iteration
* Adding quotes
* Adding 'Custom Format' properly
* Updating to key:value pairs
* Update template
|
2024-04-03 11:53:36 -04:00 |
|
frack113
|
4f83231697
|
Update old sigma link (#303)
* Update SigmaHQ ref
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
* Update SigmaHQ ref
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
* Update SigmaHq ref
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
* Update SigmaHq ref
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
---------
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2023-10-18 11:30:34 -04:00 |
|
bohops
|
cd16f0aff3
|
Add vsls-agent lolbin and committing a few other changes (#263)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2023-02-25 18:47:44 +00:00 |
|
frack113
|
1072d3dc34
|
Add sigma ref Detection (#272)
* Add sigma ref
* Add missing sigma ref
* Fix sigma link
* Remove by Defender
* Remove by Defender
|
2022-12-29 09:51:15 -05:00 |
|
Michał Kucharski
|
8452c1ca96
|
Update eventvwr.yml with Execute part (#252)
* Update eventvwr.yml with Execute part
All things added based on https://twitter.com/orange_8361/status/1518970259868626944 and my re-tests.
* Update Eventvwr.yml
As asked by @bohops
* Update Eventvwr.yml
|
2022-11-13 14:56:32 -05:00 |
|
xenoscr
|
dd58662ee9
|
Correcting 'UAC bypass' to 'UAC Bypass'
|
2022-09-10 22:58:06 -04:00 |
|
xenoscr
|
ce36f924fc
|
Removing extra --- from each yaml file
|
2022-09-10 22:16:47 -04:00 |
|
bohops
|
23dd0236ae
|
Detection Resources and Other Updates (#179)
* Add detection links for scripts
* Add detection links for OtherMSBins. Fixed and updated as needed.
* Add detection links for MSBins. Fixed and updated as needed.
* Add detection links for oslibraries
* Updating template for Detections
* Removing empty Detection:Sigma entries
* Remove redundant blank line
* Replacing commit URL with file URL
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2021-11-15 08:19:03 -05:00 |
|
Wietze
|
4f7ec8d2af
|
MITRE ATT&CK realignment sprint
|
2021-11-05 18:58:26 +00:00 |
|
Wietze
|
5012f95152
|
Fix Code_Sample field
|
2021-01-10 15:49:30 +00:00 |
|
Wietze
|
14dca38278
|
Standardise date formats (see https://yaml.org/type/timestamp.html)
|
2021-01-10 15:04:52 +00:00 |
|
Oddvar Moe
|
aba9538581
|
minor changes to Eventvwr
|
2018-12-12 12:50:27 +01:00 |
|
Oddvar Moe
|
7addc14d7f
|
Update Eventvwr.yml
Category change
|
2018-12-12 12:45:05 +01:00 |
|
Jacob Gajek
|
fd44373927
|
Eventvwr.exe UAC bypass
|
2018-11-01 15:20:09 -04:00 |
|