mirror of
https://github.com/SigmaHQ/sigma
synced 2026-06-08 12:34:14 +00:00
dcf236fede
- Added "Invoke-EventViewer.ps1" script to the rule "file_event_win_powershell_exploit_scripts" - Added "OriginalFileName" to "proc_creation_win_susp_taskkill" - Created rule for "winword" being used as a LOLBIN to download and load arbitrary DLLs