Nasreddine Bencherchali
|
1a9efa1002
|
feat: wmiprvse rule updates and merger
|
2023-01-19 23:10:06 +01:00 |
|
Nasreddine Bencherchali
|
0909b65bff
|
feat: update sharing websites
|
2023-01-19 22:07:31 +01:00 |
|
Nasreddine Bencherchali
|
a7c7816b96
|
fix: driverquery condition and selection
|
2023-01-19 21:52:37 +01:00 |
|
Nasreddine Bencherchali
|
fa1ede8c68
|
feat: new rules for driverquery
|
2023-01-19 21:50:10 +01:00 |
|
Nasreddine Bencherchali
|
7538086e58
|
fix: broken condition
|
2023-01-19 21:49:55 +01:00 |
|
Nasreddine Bencherchali
|
1e57208fa2
|
fix: update broken selection
|
2023-01-19 21:33:29 +01:00 |
|
Nasreddine Bencherchali
|
d9f37de1cf
|
fix: fp found in testing
|
2023-01-19 18:47:11 +01:00 |
|
Nasreddine Bencherchali
|
e213252c4c
|
feat: logic update to multiple rules
|
2023-01-19 16:37:10 +01:00 |
|
Nasreddine Bencherchali
|
fe7d543314
|
fix: rename rules to show importance
|
2023-01-19 13:39:13 +01:00 |
|
Nasreddine Bencherchali
|
3a473b8313
|
fix: small metadata fixes
|
2023-01-18 23:30:40 +01:00 |
|
Nasreddine Bencherchali
|
143a413f4f
|
fix: merge overlapping detections
|
2023-01-18 20:18:36 +01:00 |
|
Nasreddine Bencherchali
|
0cb78e498a
|
fix: more fp found in testing
|
2023-01-18 20:16:34 +01:00 |
|
Nasreddine Bencherchali
|
02e4a5112d
|
fix: fp found in testing
|
2023-01-18 18:41:07 +01:00 |
|
Nasreddine Bencherchali
|
ff9844b8d7
|
fix: fp and broken field name
|
2023-01-18 10:47:40 +01:00 |
|
Nasreddine Bencherchali
|
f3171177d8
|
fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2023-01-18 10:24:04 +01:00 |
|
Nasreddine Bencherchali
|
459ba25cce
|
Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel
|
2023-01-17 01:01:38 +01:00 |
|
Nasreddine Bencherchali
|
b6e4c45ef0
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2023-01-17 01:01:23 +01:00 |
|
Nasreddine Bencherchali
|
85fb255bc9
|
feat: new rules and updates
|
2023-01-17 01:00:44 +01:00 |
|
Nasreddine Bencherchali
|
09731e8547
|
fix: update modified date
|
2023-01-16 10:50:23 +01:00 |
|
jkb
|
391173c153
|
Correcting filepath parameter
According to Microsoft documentation, the parameter is -Filepath not -File-path. See: https://learn.microsoft.com/en-us/powershell/module/pki/import-certificate?view=windowsserver2022-ps
|
2023-01-16 10:46:02 +01:00 |
|
Nasreddine Bencherchali
|
fd823045a9
|
fix: fp in msiexec rule
|
2023-01-16 10:28:15 +01:00 |
|
Nasreddine Bencherchali
|
9783297262
|
Merge pull request #3922 from frack113/redcannary_20230113
New rules based on Redcannary AtomicRedTeam 2023-01-13
|
2023-01-13 18:18:32 +01:00 |
|
Nasreddine Bencherchali
|
8707345be7
|
fix: add related metadata
|
2023-01-13 17:21:21 +01:00 |
|
frack113
|
23620bc8aa
|
Update proc_creation_win_lsa_disablerestrictedadmin.yml
|
2023-01-13 12:31:28 +01:00 |
|
frack113
|
1b11e29fef
|
Move rules
|
2023-01-13 12:15:08 +01:00 |
|
Florian Roth
|
29a61b8c70
|
Merge branch 'master' into rule-devel
|
2023-01-12 23:57:41 +01:00 |
|
Florian Roth
|
df1870df1e
|
add IOC for LocalPotato
|
2023-01-12 23:57:33 +01:00 |
|
Nasreddine Bencherchali
|
90c1e45d83
|
feat: add new reg variant of dev mode
|
2023-01-12 15:05:53 +01:00 |
|
Nasreddine Bencherchali
|
67ea98a6db
|
feat: more updates and fixes
|
2023-01-12 01:05:48 +01:00 |
|
Nasreddine Bencherchali
|
b6b1eba014
|
fix: fp and add related fields
|
2023-01-11 23:39:15 +01:00 |
|
Nasreddine Bencherchali
|
debd658aac
|
feat: new rules related to appx packages
|
2023-01-11 23:04:37 +01:00 |
|
Nasreddine Bencherchali
|
f4d4526d0f
|
fix: fp found in testing
|
2023-01-11 20:05:55 +01:00 |
|
Nasreddine Bencherchali
|
8dc2418ea9
|
fix: some issues
|
2023-01-11 11:18:54 +01:00 |
|
Nasreddine Bencherchali
|
28a3413aa7
|
feat: updates and enhancements
|
2023-01-11 01:03:52 +01:00 |
|
Nasreddine Bencherchali
|
5bd38f8ff0
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2023-01-11 01:03:08 +01:00 |
|
frack113
|
49d7eb244f
|
Remove mitre url
|
2023-01-10 18:24:22 +01:00 |
|
frack113
|
4023bf2c83
|
Remove mitre url
|
2023-01-10 18:09:04 +01:00 |
|
Nasreddine Bencherchali
|
9d6a41edc6
|
fix: fp found in testing
|
2023-01-10 15:11:40 +01:00 |
|
Nasreddine Bencherchali
|
b80b358427
|
fix: fp with defender
|
2023-01-10 00:44:52 +01:00 |
|
Nasreddine Bencherchali
|
81f75c1d2e
|
feat: updates and enhancements
|
2023-01-10 00:13:37 +01:00 |
|
Nasreddine Bencherchali
|
17aaf7fdcd
|
Merge pull request #3888 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
|
2023-01-09 10:39:54 +01:00 |
|
Florian Roth
|
7f45405867
|
fix: FPs noticed with Aurora
|
2023-01-09 09:46:16 +01:00 |
|
frack113
|
f015c940f8
|
Merge pull request #3880 from frack113/from_VT_screen
Add proc_creation_win_double_ext_parent
|
2023-01-06 18:31:47 +01:00 |
|
frack113
|
97ec1c4d54
|
Add related
|
2023-01-06 18:22:36 +01:00 |
|
frack113
|
3346a6d3e4
|
Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-01-06 18:21:06 +01:00 |
|
frack113
|
679d1ee0ed
|
Add more ext
|
2023-01-06 18:17:01 +01:00 |
|
Nasreddine Bencherchali
|
18a77e79e3
|
fix: multiple issues
|
2023-01-06 18:04:04 +01:00 |
|
frack113
|
4adbb3fbd2
|
Add proc_creation_win_double_ext_parent
|
2023-01-06 17:18:50 +01:00 |
|
Nasreddine Bencherchali
|
e56d3763b5
|
fix: unused selection
|
2023-01-06 17:16:20 +01:00 |
|
Nasreddine Bencherchali
|
7e73028c5e
|
feat: updates and enhancements
|
2023-01-06 16:35:34 +01:00 |
|