Paul Hager
|
0420e9c3bb
|
feat: various new hktl rules
|
2023-04-17 12:08:30 +02:00 |
|
Nasreddine Bencherchali
|
2710bf4710
|
feat: new rules, updates and fp fixes (#4162)
|
2023-04-11 13:04:22 +02:00 |
|
phantinuss
|
85423f784c
|
fix: condition filtering on all filters
|
2023-03-24 10:59:01 +01:00 |
|
phantinuss
|
aa1ab49773
|
fix: FPs found in testing environment
|
2023-03-24 10:41:21 +01:00 |
|
Nasreddine Bencherchali
|
1378cf6d75
|
feat: update cmd based rules
|
2023-03-07 14:13:57 +01:00 |
|
Nasreddine Bencherchali
|
587fbbce58
|
chore: update pipe-notation rules to unsupported
|
2023-02-24 19:54:14 +01:00 |
|
phantinuss
|
ecc41ad20b
|
fix: FP with chocolatey
|
2023-02-21 16:38:05 +01:00 |
|
Wagga
|
273fdb9985
|
fix: typos in multiple rules (#4011)
|
2023-02-06 13:53:23 +01:00 |
|
Florian Roth
|
205f6a4de7
|
fix: FP with Get-ADObject
|
2023-02-06 13:26:37 +01:00 |
|
Nasreddine Bencherchali
|
c68531e688
|
fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2023-02-02 10:52:04 +01:00 |
|
Nasreddine Bencherchali
|
d08acc18ae
|
fix: add missing modified field
|
2023-02-02 00:28:32 +01:00 |
|
Nasreddine Bencherchali
|
5d769b7b19
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2023-02-01 17:10:00 +01:00 |
|
Nasreddine Bencherchali
|
beebafe9ce
|
fix: special case
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
|
2023-02-01 13:22:11 +01:00 |
|
Nasreddine Bencherchali
|
7c38a5c496
|
chore: add nextron authors tag
|
2023-02-01 11:14:59 +01:00 |
|
Nasreddine Bencherchali
|
3e24998fe1
|
feat: add add-appxpackage cmdlet rules
|
2023-01-31 22:11:32 +01:00 |
|
Nasreddine Bencherchali
|
e6c155442f
|
feat: multiple updates and enhancements
|
2023-01-30 20:02:45 +01:00 |
|
frack113
|
5087b95155
|
Merge remote-tracking branch 'upstream/master' into pormotion_status
|
2023-01-27 11:29:27 +01:00 |
|
frack113
|
1033b3f404
|
change status to test
|
2023-01-27 06:48:34 +01:00 |
|
Nasreddine Bencherchali
|
85c5f21818
|
feat: more updates, renames and fixes
|
2023-01-27 00:30:16 +01:00 |
|
Nasreddine Bencherchali
|
58912f5eda
|
Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel
|
2023-01-26 23:01:51 +01:00 |
|
Nasreddine Bencherchali
|
c538550b03
|
feat: updates and fixes
|
2023-01-26 22:42:56 +01:00 |
|
frack113
|
cb67871bd2
|
Revert "Change status of old rules"
|
2023-01-26 19:37:18 +01:00 |
|
frack113
|
5323fd4baa
|
Change status of old rules
|
2023-01-25 18:41:18 +01:00 |
|
frack113
|
f7b159350d
|
Merge pull request #3954 from nasbench/nasbench-rule-devel
feat: updates and enhancements
|
2023-01-25 13:21:44 +01:00 |
|
Nasreddine Bencherchali
|
9a03e4e13d
|
fix: fp found in testing
|
2023-01-24 16:51:37 +01:00 |
|
phantinuss
|
a41a374901
|
fix: FPs found in testing environment
|
2023-01-24 10:30:43 +01:00 |
|
Nasreddine Bencherchali
|
c9b230de6d
|
feat: update pwsh ad module rules
|
2023-01-22 20:07:42 +01:00 |
|
frack113
|
40592f463f
|
Add Microsoft.ActiveDirectory.Management.dll
|
2023-01-22 19:34:09 +01:00 |
|
frack113
|
c7537c5d2a
|
Add import_module dll
|
2023-01-22 17:39:28 +01:00 |
|
frack113
|
75c01db53b
|
Add import_module dll
|
2023-01-22 17:38:59 +01:00 |
|
Nasreddine Bencherchali
|
ecaf89dd91
|
fix: fp with powercat
|
2023-01-21 18:15:37 +01:00 |
|
Nasreddine Bencherchali
|
dfdc232f55
|
fix: optimize "Invoke-Sharp" coverage
|
2023-01-21 12:28:08 +01:00 |
|
Nasreddine Bencherchali
|
ea536c33b3
|
feat: update and merge some pwsh rules
|
2023-01-20 17:07:23 +01:00 |
|
Nasreddine Bencherchali
|
e213252c4c
|
feat: logic update to multiple rules
|
2023-01-19 16:37:10 +01:00 |
|
Nasreddine Bencherchali
|
ff9844b8d7
|
fix: fp and broken field name
|
2023-01-18 10:47:40 +01:00 |
|
Nasreddine Bencherchali
|
f3171177d8
|
fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2023-01-18 10:24:04 +01:00 |
|
Nasreddine Bencherchali
|
459ba25cce
|
Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel
|
2023-01-17 01:01:38 +01:00 |
|
Nasreddine Bencherchali
|
85fb255bc9
|
feat: new rules and updates
|
2023-01-17 01:00:44 +01:00 |
|
Nasreddine Bencherchali
|
3d77511102
|
fix: improve fp description slightly
|
2023-01-16 16:30:08 +01:00 |
|
phantinuss
|
99c5c46397
|
fix: FP found in testing
|
2023-01-16 15:38:52 +01:00 |
|
Tim Shelton
|
09b3e43afc
|
Removing filter specification in condition
|
2023-01-12 16:21:58 +00:00 |
|
redsand (Tim Shelton)
|
3007d98844
|
Merge branch 'SigmaHQ:master' into fp_library_alias_and_use_of_alias
|
2023-01-12 10:19:47 -06:00 |
|
redsand (Tim Shelton)
|
88308b713c
|
Update rules/windows/powershell/powershell_script/posh_ps_tamper_defender.yml
whatever you guys want, im good with. i like @neo23x0 suggestion
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2023-01-12 10:14:14 -06:00 |
|
Nasreddine Bencherchali
|
b6b1eba014
|
fix: fp and add related fields
|
2023-01-11 23:39:15 +01:00 |
|
Nasreddine Bencherchali
|
28a3413aa7
|
feat: updates and enhancements
|
2023-01-11 01:03:52 +01:00 |
|
Nasreddine Bencherchali
|
81f75c1d2e
|
feat: updates and enhancements
|
2023-01-10 00:13:37 +01:00 |
|
Florian Roth
|
bcce3a85aa
|
Merge branch 'master' into rule-devel
|
2023-01-09 09:56:21 +01:00 |
|
Florian Roth
|
0a9be5922c
|
fix: shortened author list to make it fit in VARCHAR(255) DB fields
|
2023-01-09 09:47:26 +01:00 |
|
frack113
|
7f653db16c
|
Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-01-08 14:45:39 +01:00 |
|
frack113
|
2cf8529657
|
Add posh_ps_susp_set_alias
|
2023-01-08 09:55:27 +01:00 |
|