Commit Graph

9499 Commits

Author SHA1 Message Date
Gavin Knapp 063bb57dfd Update net_connection_win_notion.yaml
Note to self: Leave commits until the morning when working late 🙃🤣.

Removed test user from install path.
2023-05-04 07:52:48 +01:00
Gavin Knapp c11b69b8f5 Rename net_connection_win_notion.yml to net_connection_win_notion.yaml
Corrected fileame error
2023-05-04 01:50:25 +01:00
Gavin Knapp 401d71d9d3 Create net_connection_win_notion.yml
created a rule to detecdt possible C2 coms using Notion SaaS as the C2 endpoint.
2023-05-03 23:29:26 +01:00
phantinuss ba3fbcf334 fix: remove erroneous whitespace 2023-05-03 15:53:14 +02:00
Gavin Knapp 859d30c50c feat: new rule net_connection_win_google_api_non_browser_access.yml (#4212) 2023-05-03 10:32:28 +02:00
Nasreddine Bencherchali f25a3c530c Merge pull request #4214 from nasbench/coldsteel-rules
feat: add new rules related to coldsteel
2023-05-03 10:16:35 +02:00
kidrek 239afc945d fix: update curl rules flags to use regex (#4213) 2023-05-03 10:16:01 +02:00
phantinuss cb399e4944 fix: typos/wording 2023-05-03 09:01:29 +02:00
securepeacock 65030d99eb chore: move defender rule from internal to public (#4208) 2023-05-03 01:33:30 +02:00
Nasreddine Bencherchali 637d610884 chore: move rules to new folders (#4205) 2023-05-02 23:17:57 +02:00
Nasreddine Bencherchali 5e1cf25642 fix: pass tests 2023-05-02 22:45:54 +02:00
Nasreddine Bencherchali b8c587aff3 feat: add new rules related to coldsteel 2023-05-02 19:02:53 +02:00
phantinuss 03f3f77359 Merge pull request #4207 from securepeacock/patch-42
Create net_connection_win_winlogon_net_connections.yml
2023-05-02 16:49:19 +02:00
Fukusuke Takahashi ef95e5278d fix: delete value-modifier in Search-Identifier (#4210) 2023-04-30 21:54:24 +02:00
Nasreddine Bencherchali 64648f9e28 Update net_connection_win_winlogon_net_connections.yml 2023-04-28 16:39:04 +02:00
Nasreddine Bencherchali 5ff0f2a215 fix: small updates 2023-04-28 16:38:32 +02:00
securepeacock 9ddbb2be8b Update net_connection_win_winlogon_net_connections.yml 2023-04-28 10:30:08 -04:00
securepeacock 7355f2a54d Create net_connection_win_winlogon_net_connections.yml 2023-04-28 10:06:17 -04:00
phantinuss 6a88ece238 fix: adapt level to high
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-04-27 16:59:35 +02:00
phantinuss 941d02dbe5 fix: FPs found in production environment 2023-04-27 16:40:07 +02:00
phantinuss cf585abe51 feat: new rule for Rubeus in pwsh scriptblock log 2023-04-27 16:39:17 +02:00
phantinuss adb0a1ce1d fix: typo in field 2023-04-26 13:22:01 +02:00
phantinuss 648641c381 fix: can be end-of-commandline
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-04-25 11:27:21 +02:00
Nasreddine Bencherchali d024f971de fix: apply suggestions from code review 2023-04-25 11:18:59 +02:00
phantinuss ab6f4848ff fix: FP found in testing environment 2023-04-25 11:07:41 +02:00
phantinuss 1c311b1ba9 fix: commandline match was too unspecific 2023-04-25 11:07:41 +02:00
phantinuss 0e7d782776 Merge pull request #4196 from nasbench/nash-rule-dev
feat: small updates
2023-04-25 09:04:02 +02:00
phantinuss 7188e83ccb Merge pull request #4195 from swachchhanda000/master
Modified rule to detect every possible way of rdrleakdiag execution
2023-04-25 08:48:04 +02:00
Nasreddine Bencherchali 4eb95d28dd feat: small updates 2023-04-24 23:23:38 +02:00
Nasreddine Bencherchali 3170c29e91 fix: merge rules and update detection 2023-04-24 19:24:19 +02:00
BlueTeamOps 1c333860ee feat: new rule Suspicious Network Connection to IP Lookup Service APIs 2023-04-24 17:30:57 +02:00
Swachchhanda Poudel fc8c66b3a4 Added detection to detect every possible way of execution through rdrleakdiag 2023-04-24 21:05:57 +05:45
phantinuss 465ded22a3 Merge pull request #4190 from swachchhanda000/master
Added support when flag is called another way while executing xsl…
2023-04-24 14:05:05 +02:00
phantinuss f26e4c2c62 fix: minor 2023-04-24 09:10:47 +02:00
Nasreddine Bencherchali 1d5bbb76f0 feat: add iwr related rules 2023-04-23 15:42:02 +02:00
Nasreddine Bencherchali 6e515496f7 fix: add modified 2023-04-22 21:25:11 +02:00
0xv1n d80fd4f9b7 typo in wevtutil image name
small typo fix.
2023-04-22 15:19:46 -04:00
swachchhanda 558925f7bc Added support for when flag is called another way while executing xsl file from wmic 2023-04-21 18:47:15 +05:45
Nasreddine Bencherchali 53c69e9cc2 chore: move more rules 2023-04-21 15:01:49 +02:00
Nasreddine Bencherchali b26f9a9793 chore: move more rules 2023-04-21 15:01:48 +02:00
Nasreddine Bencherchali a066ee9a4d chore: move solarwinds rules 2023-04-21 15:00:38 +02:00
Nasreddine Bencherchali 23a9f98eae chore: move more rules 2023-04-21 15:00:36 +02:00
Nasreddine Bencherchali 7d3ef2a1d3 chore: move more rules 2023-04-21 15:00:36 +02:00
Nasreddine Bencherchali b851734126 chore: move 3cx related rules 2023-04-21 15:00:35 +02:00
Nasreddine Bencherchali f42d6dcbed Merge pull request #4187 from nasbench/queuejumper-rules
feat: new rules related to queuejumper
2023-04-21 14:54:12 +02:00
Nasreddine Bencherchali faf78e1301 Merge pull request #4188 from nasbench/fw-rules-eid-updates
feat: update firewall rules event ids
2023-04-21 14:50:48 +02:00
Nasreddine Bencherchali 2d960a079a fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-04-21 14:45:16 +02:00
phantinuss 35b027ee1c Merge pull request #4184 from swachchhanda000/master
Added new rule that identifies the creation of a scheduled job by usi…
2023-04-21 13:31:22 +02:00
phantinuss d82d387071 Merge pull request #4189 from tuanhxh1/tuan.le.ncs
Update Script Block Text When Run Phant0m Script
2023-04-21 11:42:55 +02:00
Nasreddine Bencherchali add0ac0d9f fix: update structure and metadata 2023-04-21 11:38:13 +02:00