Commit Graph

11006 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 083d30c19d fix: title and add python filter 2023-01-02 15:02:28 +01:00
Nasreddine Bencherchali e23a63a60e fix: typo in field name 2023-01-02 14:52:35 +01:00
Nasreddine Bencherchali 3749416a30 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-02 14:50:27 +01:00
Nasreddine Bencherchali a99b5082e1 feat: updates and enhancements 2023-01-02 14:49:45 +01:00
frack113 b13a74adc9 Update from review 2023-01-02 12:05:54 +01:00
frack113 5e09d46226 Update rules/windows/builtin/dns_server_analytical/win_apt_gallium.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-02 11:56:08 +01:00
frack113 e09850f968 fix field name 2023-01-02 11:06:57 +01:00
frack113 0e8d1f9b0d Check field name 2023-01-02 10:59:51 +01:00
frack113 0aad498425 Last lolbin (#3845)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-31 19:53:44 +01:00
Nasreddine Bencherchali 2240507e77 Merge pull request #3848 from frack113/linux_sysmon
Linux sysmon
2022-12-31 19:41:07 +01:00
Nasreddine Bencherchali f67cd766d0 Merge pull request #3846 from fukusuket/fix-invalid-regex-escape
fix: remove incorrect backslash escape(in `|re` block)
2022-12-31 18:35:36 +01:00
frack113 b6426ab3f9 Fix file name 2022-12-31 18:23:37 +01:00
frack113 c2ce5d01fc Add sysmon linux v1.0.2 2022-12-31 18:08:11 +01:00
frack113 ddb5cd0ead Add sysmon linux v1.0.2 2022-12-31 18:04:21 +01:00
fukusuket 04ecbbded9 fix: typo modified 2022-12-31 21:57:05 +09:00
fukusuket 9298295c15 fix: remove invalid backslash escape 2022-12-31 21:35:07 +09:00
Fukusuke Takahashi 1ab7324ca0 fix: remove unneeded double backslash escape (#3844) 2022-12-31 08:32:46 +01:00
signalblur 73f56c2f0e Hidden Linux Binary Execution (#3108)
Co-authored-by: Florian Roth <venom14@gmail.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-31 08:27:32 +01:00
Nasreddine Bencherchali 7dab38b19f fix: add missing modified date 2022-12-30 20:56:21 +01:00
fukusuket bd6243be7d fix: remove unneeded backslash escape in character class. 2022-12-31 00:33:00 +09:00
Nasreddine Bencherchali 261bb8758a Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-30 11:49:08 +01:00
frack113 aee5ca7afc Fix invalid field cast or name (#3841) 2022-12-30 11:46:21 +01:00
Nasreddine Bencherchali d4b9df608b fix: broken selection 2022-12-30 10:30:15 +01:00
Nasreddine Bencherchali 58f47b9875 fix: add known children appvlp 2022-12-30 10:24:25 +01:00
frack113 995b5918f2 Update rules/windows/process_creation/proc_creation_win_susp_shellexec_rundll_usage.yml 2022-12-30 10:21:54 +01:00
frack113 f083c5f83f Merge branch 'master' into patch-1 2022-12-30 10:12:25 +01:00
frack113 d10ecf5527 Merge pull request #3838 from redsand/fp_sysmon_werfault_child
FP when sysmon crashes and werfault gets launched
2022-12-30 10:08:09 +01:00
zydyka d7bc30587f Update proc_creation_win_sysmon_exploitation.yml 2022-12-30 09:00:57 +05:00
Nasreddine Bencherchali 1e29560591 fix: duplicate title 2022-12-30 01:10:03 +01:00
Nasreddine Bencherchali 2d5231ca2c fix: broken selection 2022-12-30 00:58:17 +01:00
Nasreddine Bencherchali c6fd915619 feat: updates and enhancements 2022-12-30 00:56:40 +01:00
Tim Shelton aeab567fb9 FP when sysmon crashes and werfault gets launched 2022-12-29 21:18:26 +00:00
frack113 b97a7e0b0f Merge pull request #3837 from fukusuket/fix-powershell-token-obfuscation-regex
refactor: regex escapes in `|re` block(`{`, `}`, `"`, `backquote`)
2022-12-29 19:37:26 +01:00
Nasreddine Bencherchali 61901a97c7 Merge pull request #3832 from SigmaHQ/aurora-false-positive-fixing
fix: Discord FP
2022-12-29 17:25:27 +01:00
Nasreddine Bencherchali 07cc91719c fix: enhance selection 2022-12-29 17:14:21 +01:00
fukusuket 42ab7c0484 fix regex escape 2022-12-30 00:11:52 +09:00
frack113 197615345b Add missing lolbin OSBinaries (#3835)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-29 14:36:33 +01:00
Nasreddine Bencherchali c2ad03cfa2 Merge pull request #3834 from nasbench/nasbench-rule-devel
feat: updates and new rules
2022-12-29 13:25:52 +01:00
Nasreddine Bencherchali d38195ea31 fix: remove folder start 2022-12-29 11:32:37 +01:00
Nasreddine Bencherchali 425c29cf1c feat: add new linux rules 2022-12-29 11:17:42 +01:00
Nasreddine Bencherchali 19396788db Merge pull request #3831 from redsand/fp_suspicious_process_privilege
FP: filters out erl.exe running handle.exe with elevated privileges
2022-12-28 21:18:54 +01:00
Florian Roth f3abafed94 fix: Windows Defender detection 2022-12-28 20:52:53 +01:00
Florian Roth bc5ed3e453 fix: Discord FP 2022-12-28 20:39:26 +01:00
BlueTeamOps 05135ec828 Further improved several AWS rules (#3827)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-28 19:46:36 +01:00
Nasreddine Bencherchali 77113a7340 fix: author ref 2022-12-28 18:42:47 +01:00
Nasreddine Bencherchali 3677b9f2e6 fix: enhance fp filter 2022-12-28 18:42:12 +01:00
Nasreddine Bencherchali 7baadc4d3f Merge pull request #3830 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-12-28 18:35:58 +01:00
Tim Shelton f5fffd8e92 FP: filters out erl.exe running handle.exe with elevated privileges 2022-12-28 16:44:25 +00:00
Nasreddine Bencherchali a1038670aa feat: add new reference 2022-12-28 16:17:46 +01:00
Korving-F bf79fa78bc Updates modified timestamp 2022-12-28 14:52:27 +02:00