Gavin Knapp
|
063bb57dfd
|
Update net_connection_win_notion.yaml
Note to self: Leave commits until the morning when working late 🙃🤣.
Removed test user from install path.
|
2023-05-04 07:52:48 +01:00 |
|
Gavin Knapp
|
c11b69b8f5
|
Rename net_connection_win_notion.yml to net_connection_win_notion.yaml
Corrected fileame error
|
2023-05-04 01:50:25 +01:00 |
|
Gavin Knapp
|
401d71d9d3
|
Create net_connection_win_notion.yml
created a rule to detecdt possible C2 coms using Notion SaaS as the C2 endpoint.
|
2023-05-03 23:29:26 +01:00 |
|
phantinuss
|
ba3fbcf334
|
fix: remove erroneous whitespace
|
2023-05-03 15:53:14 +02:00 |
|
Gavin Knapp
|
859d30c50c
|
feat: new rule net_connection_win_google_api_non_browser_access.yml (#4212)
|
2023-05-03 10:32:28 +02:00 |
|
Nasreddine Bencherchali
|
f25a3c530c
|
Merge pull request #4214 from nasbench/coldsteel-rules
feat: add new rules related to coldsteel
|
2023-05-03 10:16:35 +02:00 |
|
kidrek
|
239afc945d
|
fix: update curl rules flags to use regex (#4213)
|
2023-05-03 10:16:01 +02:00 |
|
phantinuss
|
cb399e4944
|
fix: typos/wording
|
2023-05-03 09:01:29 +02:00 |
|
securepeacock
|
65030d99eb
|
chore: move defender rule from internal to public (#4208)
|
2023-05-03 01:33:30 +02:00 |
|
Nasreddine Bencherchali
|
637d610884
|
chore: move rules to new folders (#4205)
|
2023-05-02 23:17:57 +02:00 |
|
Nasreddine Bencherchali
|
5e1cf25642
|
fix: pass tests
|
2023-05-02 22:45:54 +02:00 |
|
Nasreddine Bencherchali
|
b8c587aff3
|
feat: add new rules related to coldsteel
|
2023-05-02 19:02:53 +02:00 |
|
phantinuss
|
03f3f77359
|
Merge pull request #4207 from securepeacock/patch-42
Create net_connection_win_winlogon_net_connections.yml
|
2023-05-02 16:49:19 +02:00 |
|
Fukusuke Takahashi
|
ef95e5278d
|
fix: delete value-modifier in Search-Identifier (#4210)
|
2023-04-30 21:54:24 +02:00 |
|
Nasreddine Bencherchali
|
64648f9e28
|
Update net_connection_win_winlogon_net_connections.yml
|
2023-04-28 16:39:04 +02:00 |
|
Nasreddine Bencherchali
|
5ff0f2a215
|
fix: small updates
|
2023-04-28 16:38:32 +02:00 |
|
securepeacock
|
9ddbb2be8b
|
Update net_connection_win_winlogon_net_connections.yml
|
2023-04-28 10:30:08 -04:00 |
|
securepeacock
|
7355f2a54d
|
Create net_connection_win_winlogon_net_connections.yml
|
2023-04-28 10:06:17 -04:00 |
|
phantinuss
|
6a88ece238
|
fix: adapt level to high
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-04-27 16:59:35 +02:00 |
|
phantinuss
|
941d02dbe5
|
fix: FPs found in production environment
|
2023-04-27 16:40:07 +02:00 |
|
phantinuss
|
cf585abe51
|
feat: new rule for Rubeus in pwsh scriptblock log
|
2023-04-27 16:39:17 +02:00 |
|
phantinuss
|
adb0a1ce1d
|
fix: typo in field
|
2023-04-26 13:22:01 +02:00 |
|
phantinuss
|
648641c381
|
fix: can be end-of-commandline
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-04-25 11:27:21 +02:00 |
|
Nasreddine Bencherchali
|
d024f971de
|
fix: apply suggestions from code review
|
2023-04-25 11:18:59 +02:00 |
|
phantinuss
|
ab6f4848ff
|
fix: FP found in testing environment
|
2023-04-25 11:07:41 +02:00 |
|
phantinuss
|
1c311b1ba9
|
fix: commandline match was too unspecific
|
2023-04-25 11:07:41 +02:00 |
|
phantinuss
|
0e7d782776
|
Merge pull request #4196 from nasbench/nash-rule-dev
feat: small updates
|
2023-04-25 09:04:02 +02:00 |
|
phantinuss
|
7188e83ccb
|
Merge pull request #4195 from swachchhanda000/master
Modified rule to detect every possible way of rdrleakdiag execution
|
2023-04-25 08:48:04 +02:00 |
|
Nasreddine Bencherchali
|
4eb95d28dd
|
feat: small updates
|
2023-04-24 23:23:38 +02:00 |
|
Nasreddine Bencherchali
|
3170c29e91
|
fix: merge rules and update detection
|
2023-04-24 19:24:19 +02:00 |
|
BlueTeamOps
|
1c333860ee
|
feat: new rule Suspicious Network Connection to IP Lookup Service APIs
|
2023-04-24 17:30:57 +02:00 |
|
Swachchhanda Poudel
|
fc8c66b3a4
|
Added detection to detect every possible way of execution through rdrleakdiag
|
2023-04-24 21:05:57 +05:45 |
|
phantinuss
|
465ded22a3
|
Merge pull request #4190 from swachchhanda000/master
Added support when flag is called another way while executing xsl…
|
2023-04-24 14:05:05 +02:00 |
|
phantinuss
|
f26e4c2c62
|
fix: minor
|
2023-04-24 09:10:47 +02:00 |
|
Nasreddine Bencherchali
|
1d5bbb76f0
|
feat: add iwr related rules
|
2023-04-23 15:42:02 +02:00 |
|
Nasreddine Bencherchali
|
6e515496f7
|
fix: add modified
|
2023-04-22 21:25:11 +02:00 |
|
0xv1n
|
d80fd4f9b7
|
typo in wevtutil image name
small typo fix.
|
2023-04-22 15:19:46 -04:00 |
|
swachchhanda
|
558925f7bc
|
Added support for when flag is called another way while executing xsl file from wmic
|
2023-04-21 18:47:15 +05:45 |
|
Nasreddine Bencherchali
|
53c69e9cc2
|
chore: move more rules
|
2023-04-21 15:01:49 +02:00 |
|
Nasreddine Bencherchali
|
b26f9a9793
|
chore: move more rules
|
2023-04-21 15:01:48 +02:00 |
|
Nasreddine Bencherchali
|
a066ee9a4d
|
chore: move solarwinds rules
|
2023-04-21 15:00:38 +02:00 |
|
Nasreddine Bencherchali
|
23a9f98eae
|
chore: move more rules
|
2023-04-21 15:00:36 +02:00 |
|
Nasreddine Bencherchali
|
7d3ef2a1d3
|
chore: move more rules
|
2023-04-21 15:00:36 +02:00 |
|
Nasreddine Bencherchali
|
b851734126
|
chore: move 3cx related rules
|
2023-04-21 15:00:35 +02:00 |
|
Nasreddine Bencherchali
|
f42d6dcbed
|
Merge pull request #4187 from nasbench/queuejumper-rules
feat: new rules related to queuejumper
|
2023-04-21 14:54:12 +02:00 |
|
Nasreddine Bencherchali
|
faf78e1301
|
Merge pull request #4188 from nasbench/fw-rules-eid-updates
feat: update firewall rules event ids
|
2023-04-21 14:50:48 +02:00 |
|
Nasreddine Bencherchali
|
2d960a079a
|
fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
|
2023-04-21 14:45:16 +02:00 |
|
phantinuss
|
35b027ee1c
|
Merge pull request #4184 from swachchhanda000/master
Added new rule that identifies the creation of a scheduled job by usi…
|
2023-04-21 13:31:22 +02:00 |
|
phantinuss
|
d82d387071
|
Merge pull request #4189 from tuanhxh1/tuan.le.ncs
Update Script Block Text When Run Phant0m Script
|
2023-04-21 11:42:55 +02:00 |
|
Nasreddine Bencherchali
|
add0ac0d9f
|
fix: update structure and metadata
|
2023-04-21 11:38:13 +02:00 |
|