frack113
|
01dc930c17
|
Change status for old rules
|
2021-11-27 11:33:14 +01:00 |
|
Florian Roth
|
6664d6e522
|
Merge pull request #2329 from SigmaHQ/rule-devel
fix: regex in lolbas rules
|
2021-11-27 11:05:34 +01:00 |
|
Florian Roth
|
5a9f82206f
|
Merge pull request #1045 from vburov/patch-9
Create win_hack_hydra.yml
|
2021-11-27 10:21:56 +01:00 |
|
Florian Roth
|
8e2be01845
|
Merge branch 'master' into rule-devel
|
2021-11-27 10:17:07 +01:00 |
|
Florian Roth
|
0593446f96
|
fix: regex in diantz rule
|
2021-11-27 10:16:27 +01:00 |
|
Florian Roth
|
62cd452c95
|
Merge branch 'master' into rule-devel
|
2021-11-27 10:16:10 +01:00 |
|
Florian Roth
|
0f6c2e007e
|
fix: regex in Extract32 rule
|
2021-11-27 10:15:24 +01:00 |
|
Florian Roth
|
ef13bea075
|
fix: regular expression in "
|
2021-11-27 10:05:51 +01:00 |
|
Florian Roth
|
97207bdf81
|
Merge branch 'master' into aurora-false-positive-fixing
|
2021-11-27 09:22:15 +01:00 |
|
Florian Roth
|
0ad9f9a859
|
fix: FPs noticed with Aurora
|
2021-11-27 09:13:53 +01:00 |
|
Florian Roth
|
a832b8ffb9
|
refactor: changed filter to be more explicit
|
2021-11-27 08:53:05 +01:00 |
|
Florian Roth
|
9d3ba0f432
|
refactor: reduce to medium
since we cannot easily detect a real threat without a filter for every possible updater, we have to reduce level to medium here
|
2021-11-27 08:52:33 +01:00 |
|
frack113
|
138b066283
|
Merge pull request #2326 from austinsonger/win_lolbas_dump64.yml
process_creation_win_lolbas_dump64.yml
|
2021-11-27 07:50:11 +01:00 |
|
frack113
|
ccc5c2220b
|
Merge pull request #2323 from frack113/lolbas
Lolbas rules
|
2021-11-27 07:48:31 +01:00 |
|
frack113
|
010a988fe5
|
Merge pull request #2318 from austinsonger/clearing_windows_console_history.yml
clearing_windows_console_history.yml
|
2021-11-27 07:43:52 +01:00 |
|
Florian Roth
|
46f0e32118
|
Update process_creation_win_lolbas_dump64.yml
|
2021-11-27 01:18:56 +01:00 |
|
Austin Songer
|
248dcbe735
|
Update process_creation_win_lolbas_dump64.yml
|
2021-11-26 14:34:32 -06:00 |
|
Florian Roth
|
1b8a6b901b
|
docs: change title and description
|
2021-11-26 21:24:54 +01:00 |
|
Florian Roth
|
83e4236edf
|
fix: tag, changed rule to avoid FP with VS binary
there is a legitimate binary used in Visual Studio named dump64.exe, we can exclude the original location and only report when we see it in a different location or used with procdump command line flags
https://www.advanceduninstaller.com/Visual-Studio-Professional-2019-dc240beb51a0e41e029278d4ad2a2e87-application.htm
|
2021-11-26 21:23:21 +01:00 |
|
Austin Songer
|
18bab18dd9
|
Update process_creation_win_lolbas_dump64.yml
|
2021-11-26 14:19:10 -06:00 |
|
Austin Songer
|
d485fa9b93
|
Create process_creation_win_lolbas_dump64.yml
|
2021-11-26 14:03:10 -06:00 |
|
Florian Roth
|
11b8ccfe8f
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-11-26 20:47:22 +01:00 |
|
Florian Roth
|
eae38d08f0
|
fix: FPs
|
2021-11-26 20:46:52 +01:00 |
|
Florian Roth
|
1702c057c6
|
Merge branch 'master' into rule-devel
|
2021-11-26 20:02:40 +01:00 |
|
Florian Roth
|
ed73510b48
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-11-26 20:00:56 +01:00 |
|
Florian Roth
|
03cddbba29
|
fix: FPs
|
2021-11-26 20:00:55 +01:00 |
|
frack113
|
5e57e476c2
|
fix remote
|
2021-11-26 19:01:45 +01:00 |
|
frack113
|
0f33cbc85b
|
add lolbas rule
|
2021-11-26 18:50:19 +01:00 |
|
Florian Roth
|
9c8a649e6c
|
fix: FP with suspicious svchost.exe rule
|
2021-11-26 17:12:33 +01:00 |
|
Austin Songer
|
48d9aec318
|
Update powershell_clearing_windows_console_history.yml
|
2021-11-26 09:18:37 -06:00 |
|
Florian Roth
|
d91b925873
|
fix: FPs
|
2021-11-26 14:42:21 +01:00 |
|
Austin Songer
|
25df58702a
|
Update powershell_clearing_windows_console_history.yml
|
2021-11-25 19:08:55 -06:00 |
|
Austin Songer
|
a9ab7f4e13
|
Update powershell_clearing_windows_console_history.yml
|
2021-11-25 19:08:27 -06:00 |
|
Austin Songer
|
f8fd44d92a
|
Update powershell_clearing_windows_console_history.yml
|
2021-11-25 19:06:18 -06:00 |
|
Austin Songer
|
c3d5d1c231
|
clearing_windows_console_history.yml
|
2021-11-25 19:04:30 -06:00 |
|
Florian Roth
|
a6c9a8772c
|
Merge branch 'master' into aurora-false-positive-fixing
|
2021-11-26 00:09:09 +01:00 |
|
Florian Roth
|
11fc576103
|
fix: FPs with rules
|
2021-11-25 19:04:27 +01:00 |
|
phantinuss
|
979a00c2f4
|
fix: FPs found with Aurora
|
2021-11-25 15:36:08 +01:00 |
|
phantinuss
|
271e8291a5
|
fix: remove unneeded escape
|
2021-11-25 09:24:04 +01:00 |
|
frack113
|
bdb00f403f
|
fix rule
|
2021-11-24 19:24:16 +01:00 |
|
frack113
|
960a03eaf4
|
add lobas Binary
|
2021-11-24 19:17:00 +01:00 |
|
Florian Roth
|
3e8b43e324
|
Merge pull request #2307 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2021-11-24 17:31:44 +01:00 |
|
Florian Roth
|
b6bfb1074d
|
Merge pull request #2305 from phantinuss/master
rule: rundll calling shell32 with dll in suspicious location + Download via Certreq
|
2021-11-24 17:30:56 +01:00 |
|
Florian Roth
|
ce7d101b86
|
Merge branch 'master' into aurora-false-positive-fixing
|
2021-11-24 16:59:53 +01:00 |
|
Florian Roth
|
f60e8e5d17
|
fix: more false positive filters
|
2021-11-24 16:58:53 +01:00 |
|
phantinuss
|
eb8c9c046b
|
rule: download using certreq
|
2021-11-24 16:39:44 +01:00 |
|
Florian Roth
|
3ace3808a5
|
refactor: Shell File Write to Suspicious Folder rule
|
2021-11-24 15:54:42 +01:00 |
|
Florian Roth
|
fd6e3bb572
|
fix: dbghelp/dbgcore DLL load FP
|
2021-11-24 13:47:30 +01:00 |
|
Florian Roth
|
5e91d30e29
|
Merge pull request #2306 from SigmaHQ/rule-devel
refactor: change rule for CVE-2021-42321 exploitation
|
2021-11-24 13:42:17 +01:00 |
|
Florian Roth
|
88cc418b98
|
Merge branch 'rule-devel' into aurora-false-positive-fixing
|
2021-11-24 13:42:00 +01:00 |
|