Commit Graph

8702 Commits

Author SHA1 Message Date
Florian Roth 0cd5eb375d Merge branch 'master' into rule-devel 2022-12-27 11:58:53 +01:00
Florian Roth 65f92dcd47 rule: HTran / NATBypass usage 2022-12-27 11:58:44 +01:00
frack113 8ea3999754 Merge pull request #3302 from memory-shards/master
Create proc_creation_win_lolbin_agentexecutor.yml
2022-12-24 15:45:35 +01:00
Nasreddine Bencherchali 794d93c298 fix: broken selection 2022-12-24 14:11:32 +01:00
Nasreddine Bencherchali e7d6bf7cab fix: enhance logic of AgentExecutor rules 2022-12-24 14:10:21 +01:00
Nasreddine Bencherchali e6baac1bf2 fix: exclude teamviewer fp & reduce severity 2022-12-23 20:50:38 +01:00
Nasreddine Bencherchali 21f5bf8536 feat: new rules related to rat software based on #2841 2022-12-23 20:42:51 +01:00
frack113 271460062e Merge pull request #3815 from nasbench/aadinternals-rules
feat: new aadinternals related rules
2022-12-23 20:20:07 +01:00
frack113 5fdad241ea Update proc_creation_win_lolbin_agentexecutor.yml 2022-12-23 20:11:55 +01:00
Nasreddine Bencherchali b19abdaeda fix: date position 2022-12-23 20:02:54 +01:00
Nasreddine Bencherchali 5a8808e0ac fix: wrong category 2022-12-23 19:27:34 +01:00
Nasreddine Bencherchali 1f38e15bb4 fix: fp section 2022-12-23 19:24:08 +01:00
Nasreddine Bencherchali 92e4081de3 fix: duplicate title 2022-12-23 19:20:43 +01:00
Nasreddine Bencherchali 28664d5bb3 feat: new aadinternals related rules 2022-12-23 19:16:17 +01:00
Nasreddine Bencherchali 0aa6f26a6f feat: updates and enhancements 2022-12-23 18:37:59 +01:00
frack113 df015e555c Add more ref 2022-12-23 13:22:50 +01:00
frack113 546e53fb35 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-23 12:34:56 +01:00
frack113 bee5b2f252 Issue 575 page 43 2022-12-23 11:10:17 +01:00
frack113 b200b5dedb Fix title 2022-12-23 10:58:11 +01:00
frack113 9617cdd4ea Issue 575 page 42 2022-12-23 10:50:34 +01:00
Nasreddine Bencherchali 03cc78e916 feat: filename test enhancements (#3812) 2022-12-23 09:25:16 +01:00
Nasreddine Bencherchali 3fc4390767 Merge pull request #3809 from qasimqlf/patch-18
fix: updated targetUserName and ipAddress
2022-12-22 15:16:52 +01:00
Florian Roth 9aa823fe3b Merge pull request #3810 from nasbench/nasbench-rule-devel
feat: rule dev and updates
2022-12-22 15:04:08 +01:00
Nasreddine Bencherchali e61795a1ea feat: proxynotshell owa variant rules 2022-12-22 12:10:29 +01:00
frack113 a9a0d6217d Merge pull request #3808 from veramine/patch-11
Remove Logitech auto-updater false positive
2022-12-22 10:37:45 +01:00
Nasreddine Bencherchali 653b498315 fix: update modified field 2022-12-22 10:31:25 +01:00
Qasim Qlf 29377ddfff fix: updated targetUserName and ipAddress 2022-12-22 14:16:25 +05:00
Veramine 5bdf52beae Remove Logitech auto-updater false positive 2022-12-21 23:49:14 -08:00
Veramine 3bb741af66 Remove Windows 10 volume control false positive
https://superuser.com/questions/1175267/what-is-this-rundll32-instance-running
2022-12-21 23:41:39 -08:00
sai prashanth pulisetti 3b6100ccd9 Create Possible Manipulation Of Tokens on a Windows computers remotely Detected via impersonate (#3803)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-21 13:27:22 +01:00
Florian Roth f9d1eb1f2d Update proc_creation_win_renamed_office_processes.yml 2022-12-21 09:18:06 +01:00
Florian Roth 9372987801 fix: missing upper tick
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 08:57:37 +01:00
Florian Roth 7e7cbe41c3 docs: change modified date 2022-12-21 08:57:05 +01:00
Nasreddine Bencherchali 4b6f5f143d feat: add more suspicious cases
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-12-21 00:18:44 +01:00
Nasreddine Bencherchali 7c46e4c3c0 fix: fix #2479 2022-12-21 00:11:04 +01:00
Florian Roth 2580b84de3 fix: typo 2022-12-21 00:07:51 +01:00
Nasreddine Bencherchali beccf416da feat: add two new rules 2022-12-20 23:44:44 +01:00
Nasreddine Bencherchali 6679347fe3 fix: rename files to follow convention 2022-12-20 22:25:49 +01:00
Nasreddine Bencherchali 68f1ce8b9e Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-20 22:24:56 +01:00
Nasreddine Bencherchali 7679d05706 fix: fp found in testing exchange server 2022-12-20 13:23:32 +01:00
Nasreddine Bencherchali 3f48eb4963 fix: selection name and add old path 2022-12-20 10:42:21 +01:00
Nasreddine Bencherchali de5345cfd2 fix: add permalink instead of master 2022-12-20 10:25:52 +01:00
Nasreddine Bencherchali 22761ec2c3 fix: add missing id 2022-12-20 10:25:03 +01:00
MetaOSINT ba52dc2aa8 T1539 Steal Web Session Cookie rules
Update existing rule and add one new rule related to Steal Web Session Cookie technique (T1539)
2022-12-19 23:20:13 -05:00
Nasreddine Bencherchali 05bdb9af74 fix: rename files to fit logic 2022-12-19 19:28:23 +01:00
Nasreddine Bencherchali ff94bfee2b fix: update description to fit logic 2022-12-19 19:23:11 +01:00
Nasreddine Bencherchali 9c308642c7 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-19 19:21:55 +01:00
Nasreddine Bencherchali c374413664 fix: change to permalink 2022-12-19 18:15:57 +01:00
Nasreddine Bencherchali 060174e2dd fix: small fixes
- Added modified date
- Updated DLL sideload version
2022-12-19 18:14:01 +01:00
pbssubhash 8a9f1ee273 Update file_event_win_wermgr_local_privilege_escalation.yml 2022-12-19 22:39:05 +05:30