1313 detection_rules : ['../rules', '../rules_building_block']
1414 - folder : audit_policies/windows
1515 children :
16- - file : README.md
16+ - file : README.md
17+ - file : audit_policy_change.md
18+ - file : audit_authorization_policy_change.md
19+ - file : audit_detailed_file_share.md
20+ - file : audit_directory_service_access.md
21+ - file : audit_directory_service_changes.md
22+ - file : audit_filtering_platform_connection.md
23+ - file : audit_handle_manipulation.md
24+ - file : audit_logon.md
25+ - file : audit_process_creation_and_command_line.md
26+ - file : audit_security_group_management.md
27+ - file : audit_security_system_extension.md
28+ - file : audit_sensitive_privilege_use.md
29+ - file : audit_special_logon.md
30+ - file : audit_token_right_adjusted_events.md
31+ - file : audit_user_account_management.md
32+ - file : audit_powershell_scriptblock.md
33+ - file : sysmon_eventid1_process_creation.md
34+ - file : sysmon_eventid2_file_creation_time_changed.md
35+ - file : sysmon_eventid3_network_connection.md
36+ - file : sysmon_eventid7_image_loaded.md
37+ - file : sysmon_eventid8_createremotethread.md
38+ - file : sysmon_eventid10_process_access.md
39+ - file : sysmon_eventid11_file_create.md
40+ - file : sysmon_eventid12_13_14_registry_event.md
41+ - file : sysmon_eventid17_18_pipe_event.md
42+ - file : sysmon_eventid19_20_21_wmi_event.md
43+ - file : sysmon_eventid22_dns_query.md
44+ - file : sysmon_eventid23_file_delete.md
0 commit comments