• vulnerability_outlook_flags

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    vulnerability_outlook_flags SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long time of the most recent registry write...
    • 14 Oct 2020 7:04 PM
  • windows_event_user_account_changed

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    windows_event_user_account_changed SCHEMA account_expires string The date when the account expires allowed_to_delegate_to string The list of SPNs to which this account can present delegated credentials. description string...
    • 14 Oct 2020 8:14 PM
  • ioc_windows_registry_malware_sdbot

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 13 Oct 2020
    • 0 Comments
    ioc_windows_registry_malware_sdbot this is a scheduled query to detect sdbot malware. https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/W32~Sdbot-MA/detailed-analysis.aspx Sophos protection capabilities should be protecting...
    • 13 Oct 2020 9:48 PM
  • vulnerability_fontblocking

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    vulnerability_fontblocking Schema analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long time of the most recent registry write...
    • 14 Oct 2020 6:58 PM
  • vulnerability_safer_flags_missing

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    vulnerability_safer_flags_missing SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long time of the most recent registry...
    • 14 Oct 2020 7:05 PM
  • windows_event_audit_log_cleared

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    windows_event_audit_log_cleared SCHEMA description string Plugin description text eventid int The Windows event ID provider_name string The Windows event provider source string The Windows event source ...
    • 14 Oct 2020 7:30 PM
  • vulnerability_srp_transparent

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    vulnerability_srp_transparent SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long time of the most recent registry write...
    • 14 Oct 2020 7:21 PM
  • windows_wsl_installed

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    windows_wsl_installed SCHEMA atime long Last access time ctime long Time of the change event filename string Name of the file that has changed mtime long time of the most recent registry write path string...
    • 14 Oct 2020 8:38 PM
  • vulnerability_disallowed_paths

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    Detect disallowed paths, need to get a definition of such from MRT SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long...
    • 14 Oct 2020 1:53 PM
  • vulnerability_opentype_font

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    vulnerability_opentype_font SCHEMA data string Data content of registry value key string Name of the key mtime long time of the most recent registry write name string Name of the registry value entry path...
    • 14 Oct 2020 7:02 PM
<>