TD
The DFIR Report
First rule: Wed Mar 02 2022 01:00:00 GMT+0100 (Central European Standard Time)
0rules authored
2sole author
2co-authored
Rule Types
By Severity
critical
0
high
2
medium
1
low
1
informational
0
By Status
stable
0
test
1
experimental
3
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Potentially Suspicious NTFS Symlink Behavior Modification
Wed Mar 02 2022 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
HackTool - Impacket File Indicators
Mon May 19 2025 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Notepad Password Files Discovery
Fri Feb 21 2025 01:00:00 GMT+0100 (Central European Standard Time)
lowDetection
Suspicious Binaries and Scripts in Public Folder
Thu Jan 23 2025 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Browse all 4 rules by The DFIR Report
Filter the full rule library to see only their contributions