Commit Graph

6731 Commits

Author SHA1 Message Date
frack113 01dc930c17 Change status for old rules 2021-11-27 11:33:14 +01:00
Florian Roth 6664d6e522 Merge pull request #2329 from SigmaHQ/rule-devel
fix: regex in lolbas rules
2021-11-27 11:05:34 +01:00
Florian Roth 5a9f82206f Merge pull request #1045 from vburov/patch-9
Create win_hack_hydra.yml
2021-11-27 10:21:56 +01:00
Florian Roth 8e2be01845 Merge branch 'master' into rule-devel 2021-11-27 10:17:07 +01:00
Florian Roth 0593446f96 fix: regex in diantz rule 2021-11-27 10:16:27 +01:00
Florian Roth 62cd452c95 Merge branch 'master' into rule-devel 2021-11-27 10:16:10 +01:00
Florian Roth 0f6c2e007e fix: regex in Extract32 rule 2021-11-27 10:15:24 +01:00
Florian Roth ef13bea075 fix: regular expression in " 2021-11-27 10:05:51 +01:00
Florian Roth 97207bdf81 Merge branch 'master' into aurora-false-positive-fixing 2021-11-27 09:22:15 +01:00
Florian Roth 0ad9f9a859 fix: FPs noticed with Aurora 2021-11-27 09:13:53 +01:00
Florian Roth a832b8ffb9 refactor: changed filter to be more explicit 2021-11-27 08:53:05 +01:00
Florian Roth 9d3ba0f432 refactor: reduce to medium
since we cannot easily detect a real threat without a filter for every possible updater, we have to reduce level to medium here
2021-11-27 08:52:33 +01:00
frack113 138b066283 Merge pull request #2326 from austinsonger/win_lolbas_dump64.yml
process_creation_win_lolbas_dump64.yml
2021-11-27 07:50:11 +01:00
frack113 ccc5c2220b Merge pull request #2323 from frack113/lolbas
Lolbas rules
2021-11-27 07:48:31 +01:00
frack113 efa099aec7 Merge pull request #2321 from austinsonger/Azure-Subscription-Permission-Elevation
Azure subscription permission elevation
2021-11-27 07:47:54 +01:00
frack113 7a5bf359a1 Merge pull request #2320 from austinsonger/azure_unusual_authentication_interruption.yml
azure_unusual_authentication_interruption.yml
2021-11-27 07:47:40 +01:00
frack113 5922483f2e Merge pull request #2322 from austinsonger/admission_controllers
Updated Descriptions and Tags
2021-11-27 07:44:48 +01:00
frack113 010a988fe5 Merge pull request #2318 from austinsonger/clearing_windows_console_history.yml
clearing_windows_console_history.yml
2021-11-27 07:43:52 +01:00
Florian Roth 46f0e32118 Update process_creation_win_lolbas_dump64.yml 2021-11-27 01:18:56 +01:00
Austin Songer 248dcbe735 Update process_creation_win_lolbas_dump64.yml 2021-11-26 14:34:32 -06:00
Florian Roth 1b8a6b901b docs: change title and description 2021-11-26 21:24:54 +01:00
Florian Roth 83e4236edf fix: tag, changed rule to avoid FP with VS binary
there is a legitimate binary used in Visual Studio named dump64.exe, we can exclude the original location and only report when we see it in a different location or used with procdump command line flags
https://www.advanceduninstaller.com/Visual-Studio-Professional-2019-dc240beb51a0e41e029278d4ad2a2e87-application.htm
2021-11-26 21:23:21 +01:00
Austin Songer 18bab18dd9 Update process_creation_win_lolbas_dump64.yml 2021-11-26 14:19:10 -06:00
Austin Songer d485fa9b93 Create process_creation_win_lolbas_dump64.yml 2021-11-26 14:03:10 -06:00
Florian Roth 11b8ccfe8f Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-11-26 20:47:22 +01:00
Florian Roth eae38d08f0 fix: FPs 2021-11-26 20:46:52 +01:00
Austin Songer 98084e857c Update azure_subscription_permissions_elevation_via_auditlogs.yml 2021-11-26 13:42:48 -06:00
Austin Songer 7e0634e43c Update azure_subscription_permissions_elevation_via_activitylogs.yml 2021-11-26 13:42:39 -06:00
Florian Roth 1702c057c6 Merge branch 'master' into rule-devel 2021-11-26 20:02:40 +01:00
Florian Roth ed73510b48 Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-11-26 20:00:56 +01:00
Florian Roth 03cddbba29 fix: FPs 2021-11-26 20:00:55 +01:00
Austin Songer 92f3705bd9 Update and rename activitylogs_azure_subscription_permissions_elevation.yml to azure_subscription_permissions_elevation_via_activitylogs.yml 2021-11-26 12:08:43 -06:00
Austin Songer 5508462029 Rename auditlogs_azure_subscription_permissions_elevation.yml to azure_subscription_permissions_elevation_via_auditlogs.yml 2021-11-26 12:08:13 -06:00
Austin Songer 8e78578892 Update activitylogs_azure_subscription_permissions_elevation.yml 2021-11-26 12:07:21 -06:00
Austin Songer 05c6e3dd12 Update azure_unusual_authentication_interruption.yml 2021-11-26 12:05:36 -06:00
frack113 5e57e476c2 fix remote 2021-11-26 19:01:45 +01:00
frack113 0f33cbc85b add lolbas rule 2021-11-26 18:50:19 +01:00
Austin Songer cd5edd4b65 Merge branch 'SigmaHQ:master' into admission_controllers 2021-11-26 11:44:37 -06:00
Austin Songer d78bbb9333 Update activitylogs_azure_subscription_permissions_elevation.yml 2021-11-26 11:42:32 -06:00
Austin Songer 0a18b42445 Update azure_unusual_authentication_interruption.yml 2021-11-26 11:41:33 -06:00
Florian Roth 91f0e03481 Merge pull request #2319 from SigmaHQ/aurora-false-positive-fixing
fix: FP with suspicious svchost.exe rule
2021-11-26 18:40:05 +01:00
Austin Songer 5e42b73a92 activitylogs_azure_subscription_permissions_elevation.yml 2021-11-26 11:33:37 -06:00
Austin Songer 26ae440bd0 auditlogs_azure_subscription_permissions_elevation.yml 2021-11-26 11:32:57 -06:00
Austin Songer b260f25cc0 Create azure_unusual_authentication_interruption.yml 2021-11-26 11:07:53 -06:00
Austin Songer 2f42753b6c Update gcp_kubernetes_admission_controller.yml 2021-11-26 10:35:04 -06:00
Austin Songer d6f1edf5ab Update azure_kubernetes_admission_controller.yml 2021-11-26 10:34:50 -06:00
Austin Songer caf14e3fa0 Update azure_kubernetes_admission_controller.yml 2021-11-26 10:32:23 -06:00
Austin Songer 2c271f5be8 Update gcp_kubernetes_admission_controller.yml 2021-11-26 10:32:11 -06:00
Austin Songer 64179e3512 Update azure_kubernetes_admission_controller.yml 2021-11-26 10:31:36 -06:00
Austin Songer 60743f75da Update gcp_kubernetes_admission_controller.yml 2021-11-26 10:31:33 -06:00