Rule Library
Sigma Rules
2 rules found for "Matthew Green"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Potential Defense Evasion Via Binary Rename
Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
WindowsProcess Creation
Matthew Green+4Sat Jun 15windows
Detectionhightest
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
WindowsProcess Creation
Matthew Green+2Sat Jun 15windows