• vulnerability_applocker_ruleset_enforcement_mode

    • Under Review on
    • 0 Comments
    well its a vulnerability need to get descriptions of each of these vulnerabilities into the documentation. SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string...
  • windows_services_md5

    • Under Review on
    • 0 Comments
    windows_services_md5 SCHEMA description string Plugin description text display_name string Service Display name name string Name of the registry value entry path string Full path to the value sha1 string...
  • windows_event_user_account_deleted

    • Under Review on
    • 0 Comments
    windows_event_user_account_deleted SCHEMA description string Plugin description text eventid int The Windows event ID privilege_list string The list of user privileges which were used during the operation provider_name...
  • vulnerability_app_disabled_exception_chain_validation

    • Under Review on
    • 0 Comments
    Detect disabled exception chain validation. https://www.windowsworkstation.com/win2012/disable-sehop/ SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string ...
  • vulnerability_srp_default_level

    • Under Review on
    • 0 Comments
    vulnerability_srp_default_level SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long time of the most recent registry...
  • vulnerability_uac_disabled

    • Under Review on
    • 0 Comments
    vulnerability_uac_disabled SCHEMA data string Data content of registry value key string Name of the key mtime long time of the most recent registry write name string Name of the registry value entry path...
  • threat_stickykeys_registry_backdoor

    • Under Review on
    • 0 Comments
    Windows sticky keys have been changed SCHEMA data string Data content of registry value key string Name of the key mtime long time of the most recent registry write name string Name of the registry value entry...
  • running_processes_osx_events

    • Under Review on
    • 0 Comments
    Mac os running process info SCHEMA cmdline string Process command line egid long Effective group ID at process start euid long Effective user ID at process start gid long Group ID (unsigned) of the user running...
  • windows_services_md5

    • Under Review on
    • 0 Comments
    windows_services_md5 SCHEMA description string Plugin description text display_name string Service Display name name string Name of the registry value entry path string Full path to the value sha1 string...
  • windows_event_replay_attack

    • Under Review on
    • 0 Comments
    windows_event_replay_attack SCHEMA authentication_package string The name of the authentication package which was used for the logon description string Plugin description text eventid int The Windows event ID logon_process...