0xrawsec / whids

Open Source EDR for Windows
https://rawsec.lu
GNU Affero General Public License v3.0
1.14k stars 138 forks source link

Build canary rules for Microsoft-Windows-Kernel-File logs #94

Closed qjerome closed 2 years ago