Azure-Sentinel/Hunting Queries/Syslog
gitj121 eae3c184f0 Adding with changes 2022-03-31 16:38:02 -07:00
..
Apache_log4j_Vulnerability.yaml Adding with changes 2022-03-31 16:38:02 -07:00
Base64_Download_Activity.yaml updating or adding version 2021-12-14 20:16:31 -08:00
Container_Miner_Activity.yaml Revert "Revert "Merge branch 'master' of https://github.com/Azure/Azure-Sentinel"" 2022-01-03 16:21:46 +02:00
CryptoCurrencyMiners.yaml Updating the name from “Azure Sentinel” to “Microsoft Sentinel” for Detection and Hunting Queries. 2021-11-09 18:41:23 -08:00
Firewall_Disable_Activity.yaml updating or adding version 2021-12-14 20:16:31 -08:00
Linux_Toolkit_Detected.yaml Adding with slight change in description 2021-12-15 17:41:05 -08:00
Process_Termination_Activity.yaml updating or adding version 2021-12-14 20:16:31 -08:00
RareProcess_ForLxHost.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
SCXExecuteRunAsProviders.yml updating or adding version 2021-12-14 20:16:31 -08:00
SchedTaskAggregation.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
SchedTaskEditViaCrontab.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
Suspicious_ShellScript_Activity.yaml updating or adding version 2021-12-14 20:16:31 -08:00
disabled_account_squid_usage.yaml fixes 2021-08-06 14:18:45 -07:00
squid_abused_tlds.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
squid_malformed_requests.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
squid_volume_anomalies.yaml Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00