Nasreddine Bencherchali
|
67ea98a6db
|
feat: more updates and fixes
|
2023-01-12 01:05:48 +01:00 |
|
Nasreddine Bencherchali
|
b6b1eba014
|
fix: fp and add related fields
|
2023-01-11 23:39:15 +01:00 |
|
Nasreddine Bencherchali
|
debd658aac
|
feat: new rules related to appx packages
|
2023-01-11 23:04:37 +01:00 |
|
Nasreddine Bencherchali
|
f4d4526d0f
|
fix: fp found in testing
|
2023-01-11 20:05:55 +01:00 |
|
Nasreddine Bencherchali
|
8dc2418ea9
|
fix: some issues
|
2023-01-11 11:18:54 +01:00 |
|
Nasreddine Bencherchali
|
28a3413aa7
|
feat: updates and enhancements
|
2023-01-11 01:03:52 +01:00 |
|
Nasreddine Bencherchali
|
5bd38f8ff0
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2023-01-11 01:03:08 +01:00 |
|
frack113
|
49d7eb244f
|
Remove mitre url
|
2023-01-10 18:24:22 +01:00 |
|
frack113
|
4023bf2c83
|
Remove mitre url
|
2023-01-10 18:09:04 +01:00 |
|
Nasreddine Bencherchali
|
9d6a41edc6
|
fix: fp found in testing
|
2023-01-10 15:11:40 +01:00 |
|
Nasreddine Bencherchali
|
b80b358427
|
fix: fp with defender
|
2023-01-10 00:44:52 +01:00 |
|
Nasreddine Bencherchali
|
81f75c1d2e
|
feat: updates and enhancements
|
2023-01-10 00:13:37 +01:00 |
|
Nasreddine Bencherchali
|
17aaf7fdcd
|
Merge pull request #3888 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
|
2023-01-09 10:39:54 +01:00 |
|
Florian Roth
|
7f45405867
|
fix: FPs noticed with Aurora
|
2023-01-09 09:46:16 +01:00 |
|
frack113
|
f015c940f8
|
Merge pull request #3880 from frack113/from_VT_screen
Add proc_creation_win_double_ext_parent
|
2023-01-06 18:31:47 +01:00 |
|
frack113
|
97ec1c4d54
|
Add related
|
2023-01-06 18:22:36 +01:00 |
|
frack113
|
3346a6d3e4
|
Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-01-06 18:21:06 +01:00 |
|
frack113
|
679d1ee0ed
|
Add more ext
|
2023-01-06 18:17:01 +01:00 |
|
Nasreddine Bencherchali
|
18a77e79e3
|
fix: multiple issues
|
2023-01-06 18:04:04 +01:00 |
|
frack113
|
4adbb3fbd2
|
Add proc_creation_win_double_ext_parent
|
2023-01-06 17:18:50 +01:00 |
|
Nasreddine Bencherchali
|
e56d3763b5
|
fix: unused selection
|
2023-01-06 17:16:20 +01:00 |
|
Nasreddine Bencherchali
|
7e73028c5e
|
feat: updates and enhancements
|
2023-01-06 16:35:34 +01:00 |
|
frack113
|
65eb06e231
|
Merge pull request #3876 from frack113/fix_fp_gfx
Update proc_creation_win_susp_file_download_via_gfxdownloadwrapper.yml
|
2023-01-06 13:48:31 +01:00 |
|
frack113
|
31530e50b7
|
Update FP
|
2023-01-06 13:28:57 +01:00 |
|
Nasreddine Bencherchali
|
fb1f72a634
|
fix: add missing modified field
|
2023-01-05 23:08:36 +01:00 |
|
Veramine
|
325d532239
|
Update proc_creation_win_susp_3proxy_usage.yml
Fix condition
|
2023-01-05 13:30:45 -08:00 |
|
Nasreddine Bencherchali
|
be4d99d6dd
|
Merge pull request #3868 from nasbench/nasbench-rule-devel
feat: updates and enhancements
|
2023-01-04 19:29:12 +01:00 |
|
Nasreddine Bencherchali
|
679f3d015b
|
fix: remove unnecessary space
|
2023-01-04 19:11:33 +01:00 |
|
Nasreddine Bencherchali
|
46f01f2f88
|
fix: typo in unknown
|
2023-01-04 18:46:34 +01:00 |
|
Tim Shelton
|
903ebb1176
|
FP: tenable nessus client calls cmd during scanning.
|
2023-01-04 17:42:16 +00:00 |
|
Nasreddine Bencherchali
|
219b24be0b
|
fix: broken selection
|
2023-01-04 18:04:14 +01:00 |
|
Nasreddine Bencherchali
|
711ba956e3
|
feat: updates and enhancements
|
2023-01-04 17:49:32 +01:00 |
|
Nasreddine Bencherchali
|
0fe4f16dfb
|
fix: update filter based on ##3865 and #3866
|
2023-01-04 10:28:50 +01:00 |
|
Nasreddine Bencherchali
|
a737737d92
|
fix: enhance filter
|
2023-01-04 00:46:54 +01:00 |
|
Tim Shelton
|
0c520dc930
|
FP: manage engine admanager postgres calling archive.bat
|
2023-01-03 22:04:52 +00:00 |
|
Nasreddine Bencherchali
|
343e3f0934
|
Merge pull request #3859 from D3F7A5105/master
Change Evtx Location Used Wevtutil
|
2023-01-03 13:23:57 +01:00 |
|
Vadim
|
eabad66768
|
Delete proc_creation_win_change_evtx_location.yml
|
2023-01-03 15:15:52 +03:00 |
|
Vadim
|
4329b9ad49
|
Update proc_creation_win_susp_eventlog_clear.yml
|
2023-01-03 15:11:33 +03:00 |
|
Vadim
|
5dc77bad7a
|
Update rule for detects change location evtx
|
2023-01-03 15:10:54 +03:00 |
|
Vadim
|
052cd2e967
|
Update proc_creation_win_change_evtx_location.yml
|
2023-01-03 12:11:13 +03:00 |
|
Vadim
|
2075962596
|
Update proc_creation_win_change_evtx_location.yml
|
2023-01-03 11:54:30 +03:00 |
|
vadim
|
e620fcbc0b
|
Detects change location evtx used wecutil
|
2023-01-03 11:36:54 +03:00 |
|
Florian Roth
|
2b04ae2e35
|
Merge branch 'master' into aurora-false-positive-fixing
|
2023-01-03 00:17:11 +01:00 |
|
Florian Roth
|
fefaa57d3c
|
fix: FPs noticed in CI testing
|
2023-01-03 00:16:32 +01:00 |
|
Nasreddine Bencherchali
|
579b450d17
|
fix: add missing date
|
2023-01-02 15:26:41 +01:00 |
|
Nasreddine Bencherchali
|
083d30c19d
|
fix: title and add python filter
|
2023-01-02 15:02:28 +01:00 |
|
Nasreddine Bencherchali
|
e23a63a60e
|
fix: typo in field name
|
2023-01-02 14:52:35 +01:00 |
|
Nasreddine Bencherchali
|
3749416a30
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2023-01-02 14:50:27 +01:00 |
|
Nasreddine Bencherchali
|
a99b5082e1
|
feat: updates and enhancements
|
2023-01-02 14:49:45 +01:00 |
|
frack113
|
0aad498425
|
Last lolbin (#3845)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-31 19:53:44 +01:00 |
|