mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 22:58:20 +00:00
![]() This signature is relevant for process dumps on Windows that could be extracted by various tools. The unencrypted transmission of the dump of a critical system process (for example, lsass.exe) via network would be detected by this rule. |
||
---|---|---|
.. | ||
__load__.zeek | ||
archive.sig | ||
audio.sig | ||
font.sig | ||
general.sig | ||
image.sig | ||
libmagic.sig | ||
msoffice.sig | ||
video.sig |