ZS
Zach Stanford
First rule: Wed Jan 16 2019 01:00:00 GMT+0100 (Central European Standard Time)
0rules authored
0sole author
10co-authored
Rule Types
By Severity
critical
0
high
1
medium
8
low
1
informational
0
By Status
stable
0
test
10
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Copy From Or To Admin Share Or Sysvol Folder
Mon Dec 30 2019 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
PowerShell Deleted Mounted Share
Thu Oct 08 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Suspicious Process By Web Server Process
Wed Jan 16 2019 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
New Root Certificate Installed Via Certutil.EXE
Sun Mar 05 2023 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
Arbitrary Command Execution Using WSL
Mon Oct 05 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumThreat Hunt
New Root Certificate Installed Via CertMgr.EXE
Sun Mar 05 2023 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
Browse all 10 rules by Zach Stanford
Filter the full rule library to see only their contributions