EŞ
Ensar Şamil
First rule: Mon Oct 05 2020 02:00:00 GMT+0200 (Central European Summer Time)
0rules authored
0sole author
7co-authored
Rule Types
By Severity
critical
0
high
3
medium
4
low
0
informational
0
By Status
stable
0
test
7
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
COM Object Execution via Xwizard.EXE
Wed Oct 07 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
SyncAppvPublishingServer Execution to Bypass Powershell Restriction
Mon Oct 05 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Time Travel Debugging Utility Usage - Image
Tue Oct 06 2020 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
Mon Oct 05 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Time Travel Debugging Utility Usage
Tue Oct 06 2020 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Malicious PE Execution by Microsoft Visual Studio Debugger
Wed Oct 14 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Browse all 7 rules by Ensar Şamil
Filter the full rule library to see only their contributions