TL
Tony Lambert)
First rule: Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
0rules authored
0sole author
5co-authored
Top Log Sources
Rule Types
By Severity
critical
0
high
4
medium
1
low
0
informational
0
By Status
stable
0
test
5
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
LSASS Dump Keyword In CommandLine
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Domain Trust Discovery Via Dsquery
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Bypass UAC via WSReset.exe
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Modification of ld.so.preload
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Bypass UAC via Fodhelper.exe
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Browse all 5 rules by Tony Lambert)
Filter the full rule library to see only their contributions