Commit Graph

20 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 7d1e149844 Update sysmon_raw_disk_access_using_illegitimate_tools.yml 2022-02-07 20:51:19 +01:00
Florian Roth e69a816f7d fix: extended filters for raw disk access rule 2022-02-07 13:58:16 +01:00
Florian Roth 5c73f913f2 Merge branch 'master' into aurora-false-positive-fixing 2022-02-07 13:17:00 +01:00
Florian Roth b0e73af9ff fix: FPs noticed with Aurora 2022-02-07 13:14:51 +01:00
Florian Roth d083efa095 fix: FPs noticed with Aurora 2022-02-06 23:33:52 +01:00
Florian Roth da444a6395 fix: FPs noticed with Aurora 2022-02-04 09:53:33 +01:00
SimoneCagol 2c964503e9 Update sysmon_raw_disk_access_using_illegitimate_tools.yml 2022-01-14 13:05:45 +01:00
frack113 b5e14ac48f Update rule 2022-01-02 09:50:37 +01:00
Florian Roth de318c122a fix: FPs noticed with Aurora 2021-12-22 13:54:39 +01:00
Florian Roth 4e49c28472 fix: FPs noticed with Aurora 2021-12-18 06:19:35 +01:00
frack113 0dc0fe5903 Fix FP 2021-12-13 20:19:15 +01:00
Florian Roth 89e659355c fix: FPs noticed with Aurora 2021-12-07 15:06:49 +01:00
Florian Roth 6525771916 fix: FPs noticed with Aurora 2021-12-06 16:35:32 +01:00
Florian Roth 9a06cf2da5 fix: FPs noticed with Aurora 2021-12-04 14:28:51 +01:00
Florian Roth f1d2903ec2 fix: FPs with rules 2021-11-20 12:32:15 +01:00
Florian Roth 7d4e3fd2ed fix: more false positive fixes 2021-11-16 23:27:00 +01:00
Florian Roth c61ca81d9c refactor: raw disk access rule FPs 2021-11-09 16:15:31 +01:00
frack113 e45557316e Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
Steven 0c9a82af89 - Remove 'service: sysmon' since defining the categories made the rules generic 2020-10-02 09:37:52 +02:00
Steven 8b74abe0bc - Created new categories for sysmon events
- Replaced the explicit EventIDs with the reference to the category
- Moved the rules to the corresponding directories
2020-09-30 20:44:14 +02:00