WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts
GNU General Public License v3.0
2.7k stars 242 forks source link

feat(rules): Add rules for AppLocker, Microsoft RDS, PowerShell and RDP sessions #139

Closed catarinadf closed 1 year ago

alexkornitzer commented 1 year ago

LGTM