Actions: rabbitstack/fibratus
Actions
340 workflow runs
340 workflow runs
LSASS access from unsigned executable rule
pr
#711:
Pull request #476
opened
by
rabbitstack
LSASS handle leak via Seclogon rule
pr
#710:
Pull request #475
opened
by
rabbitstack
DLL loaded via LdrpKernel32 overwrite rule
pr
#708:
Pull request #473
opened
by
rabbitstack
Suspicious access to the hosts file rule
pr
#707:
Pull request #472
opened
by
rabbitstack
Potential ClickFix infection chain via Run window rule
pr
#704:
Pull request #470
synchronize
by
rabbitstack
Potential ClickFix infection chain via Run window rule
pr
#703:
Pull request #470
synchronize
by
rabbitstack
Potential ClickFix infection chain via Run window rule
pr
#702:
Pull request #470
synchronize
by
rabbitstack
Potential ClickFix infection chain via Run window rule
pr
#701:
Pull request #470
opened
by
rabbitstack
LSASS memory dump via MiniDumpWriteDump rule
pr
#700:
Pull request #469
synchronize
by
rabbitstack
LSASS memory dump via MiniDumpWriteDump rule
pr
#699:
Pull request #469
opened
by
rabbitstack
Potential process hollowing rule
pr
#698:
Pull request #450
synchronize
by
rabbitstack
Unsigned DLL injection via remote thread rule
pr
#696:
Pull request #466
opened
by
rabbitstack
Potential process injection via tainted memory section rule
pr
#694:
Pull request #460
synchronize
by
rabbitstack
Suspicious object symbolic link creation rule
pr
#693:
Pull request #463
synchronize
by
rabbitstack
Potential process injection via tainted memory section rule
pr
#692:
Pull request #460
synchronize
by
rabbitstack
Suspicious object symbolic link creation rule
pr
#689:
Pull request #463
opened
by
rabbitstack
Potential process injection via tainted memory section rule
pr
#688:
Pull request #460
synchronize
by
rabbitstack