-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Pull requests: SwiftOnSecurity/sysmon-config
Pull requests list
Add pwsh.exe to list of suspicious Windows tools
#176
opened Jan 28, 2023 by
miscalibrated
Loading...
Add some "TargetFilename" in "SYSMON EVENT ID 15" section
#164
opened Feb 21, 2022 by
matcha-shake
Loading...
Update the Antivirus Tampering configuration, using general condition
#160
opened Oct 18, 2021 by
hieuttmmo
Loading...
Registry key to detect definitions of Windows Defender Exclusions
#155
opened Jul 12, 2021 by
phantinuss
Loading...
Update NetworkConnect rule to fix Metasploit default port
#143
opened Mar 6, 2021 by
brokenvhs
Loading...
Added detection for CVE-2017-0199 and CVE-2017-8759.
#118
opened May 21, 2020 by
d4rk-d4nph3
Loading...
ProTip!
Add no:assignee to see everything that’s not assigned.