Actions: rabbitstack/fibratus
Actions
319 workflow runs
319 workflow runs
Suspicious HTML Application script execution rule
pr
#733:
Pull request #487
synchronize
by
rabbitstack
Suspicious print processor loaded rule
pr
#732:
Pull request #488
opened
by
rabbitstack
Suspicious HTML Application script execution rule
pr
#731:
Pull request #487
synchronize
by
rabbitstack
Suspicious HTML Application script execution rule
pr
#730:
Pull request #487
opened
by
rabbitstack
LSASS process clone creation via reflection rule
pr
#729:
Pull request #486
opened
by
rabbitstack
Suspicious XSL script execution rule
pr
#728:
Pull request #485
opened
by
rabbitstack
Script interpreter host or untrusted process persistence rule
pr
#726:
Pull request #451
synchronize
by
rabbitstack
Script interpreter host or untrusted process persistence rule
pr
#724:
Pull request #451
synchronize
by
rabbitstack
Potential privilege escalation via phantom DLL hijacking rule
pr
#723:
Pull request #447
synchronize
by
rabbitstack
CompatTelRunner.exe as an exclusion in Unusual process modified registry run key rule
pr
#722:
Pull request #449
synchronize
by
rabbitstack
CompatTelRunner.exe as an exclusion in Unusual process modified registry run key rule
pr
#721:
Pull request #449
synchronize
by
rabbitstack
Potential process creation via shellcode rule
pr
#720:
Pull request #483
opened
by
rabbitstack
Potential shellcode execution via ETW logger thread rule
pr
#718:
Pull request #481
synchronize
by
rabbitstack
Potential shellcode execution via ETW logger thread rule
pr
#717:
Pull request #481
opened
by
rabbitstack
Suspicious Netsh Helper DLL execution rule
pr
#715:
Pull request #479
opened
by
rabbitstack
LSASS access from unsigned executable rule
pr
#711:
Pull request #476
opened
by
rabbitstack
LSASS handle leak via Seclogon rule
pr
#710:
Pull request #475
opened
by
rabbitstack