Commit Graph

4312 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 1a9efa1002 feat: wmiprvse rule updates and merger 2023-01-19 23:10:06 +01:00
Nasreddine Bencherchali 0909b65bff feat: update sharing websites 2023-01-19 22:07:31 +01:00
Nasreddine Bencherchali a7c7816b96 fix: driverquery condition and selection 2023-01-19 21:52:37 +01:00
Nasreddine Bencherchali fa1ede8c68 feat: new rules for driverquery 2023-01-19 21:50:10 +01:00
Nasreddine Bencherchali 7538086e58 fix: broken condition 2023-01-19 21:49:55 +01:00
Nasreddine Bencherchali 1e57208fa2 fix: update broken selection 2023-01-19 21:33:29 +01:00
Nasreddine Bencherchali d9f37de1cf fix: fp found in testing 2023-01-19 18:47:11 +01:00
Nasreddine Bencherchali e213252c4c feat: logic update to multiple rules 2023-01-19 16:37:10 +01:00
Nasreddine Bencherchali fe7d543314 fix: rename rules to show importance 2023-01-19 13:39:13 +01:00
Nasreddine Bencherchali 3a473b8313 fix: small metadata fixes 2023-01-18 23:30:40 +01:00
Nasreddine Bencherchali 143a413f4f fix: merge overlapping detections 2023-01-18 20:18:36 +01:00
Nasreddine Bencherchali 0cb78e498a fix: more fp found in testing 2023-01-18 20:16:34 +01:00
Nasreddine Bencherchali 02e4a5112d fix: fp found in testing 2023-01-18 18:41:07 +01:00
Nasreddine Bencherchali ff9844b8d7 fix: fp and broken field name 2023-01-18 10:47:40 +01:00
Nasreddine Bencherchali f3171177d8 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-18 10:24:04 +01:00
Nasreddine Bencherchali 459ba25cce Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel 2023-01-17 01:01:38 +01:00
Nasreddine Bencherchali b6e4c45ef0 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-17 01:01:23 +01:00
Nasreddine Bencherchali 85fb255bc9 feat: new rules and updates 2023-01-17 01:00:44 +01:00
Nasreddine Bencherchali 09731e8547 fix: update modified date 2023-01-16 10:50:23 +01:00
jkb 391173c153 Correcting filepath parameter
According to Microsoft documentation, the parameter is -Filepath not -File-path. See: https://learn.microsoft.com/en-us/powershell/module/pki/import-certificate?view=windowsserver2022-ps
2023-01-16 10:46:02 +01:00
Nasreddine Bencherchali fd823045a9 fix: fp in msiexec rule 2023-01-16 10:28:15 +01:00
Nasreddine Bencherchali 9783297262 Merge pull request #3922 from frack113/redcannary_20230113
New rules based on Redcannary AtomicRedTeam 2023-01-13
2023-01-13 18:18:32 +01:00
Nasreddine Bencherchali 8707345be7 fix: add related metadata 2023-01-13 17:21:21 +01:00
frack113 23620bc8aa Update proc_creation_win_lsa_disablerestrictedadmin.yml 2023-01-13 12:31:28 +01:00
frack113 1b11e29fef Move rules 2023-01-13 12:15:08 +01:00
Florian Roth 29a61b8c70 Merge branch 'master' into rule-devel 2023-01-12 23:57:41 +01:00
Florian Roth df1870df1e add IOC for LocalPotato 2023-01-12 23:57:33 +01:00
Nasreddine Bencherchali 90c1e45d83 feat: add new reg variant of dev mode 2023-01-12 15:05:53 +01:00
Nasreddine Bencherchali 67ea98a6db feat: more updates and fixes 2023-01-12 01:05:48 +01:00
Nasreddine Bencherchali b6b1eba014 fix: fp and add related fields 2023-01-11 23:39:15 +01:00
Nasreddine Bencherchali debd658aac feat: new rules related to appx packages 2023-01-11 23:04:37 +01:00
Nasreddine Bencherchali f4d4526d0f fix: fp found in testing 2023-01-11 20:05:55 +01:00
Nasreddine Bencherchali 8dc2418ea9 fix: some issues 2023-01-11 11:18:54 +01:00
Nasreddine Bencherchali 28a3413aa7 feat: updates and enhancements 2023-01-11 01:03:52 +01:00
Nasreddine Bencherchali 5bd38f8ff0 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-11 01:03:08 +01:00
frack113 49d7eb244f Remove mitre url 2023-01-10 18:24:22 +01:00
frack113 4023bf2c83 Remove mitre url 2023-01-10 18:09:04 +01:00
Nasreddine Bencherchali 9d6a41edc6 fix: fp found in testing 2023-01-10 15:11:40 +01:00
Nasreddine Bencherchali b80b358427 fix: fp with defender 2023-01-10 00:44:52 +01:00
Nasreddine Bencherchali 81f75c1d2e feat: updates and enhancements 2023-01-10 00:13:37 +01:00
Nasreddine Bencherchali 17aaf7fdcd Merge pull request #3888 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
2023-01-09 10:39:54 +01:00
Florian Roth 7f45405867 fix: FPs noticed with Aurora 2023-01-09 09:46:16 +01:00
frack113 f015c940f8 Merge pull request #3880 from frack113/from_VT_screen
Add proc_creation_win_double_ext_parent
2023-01-06 18:31:47 +01:00
frack113 97ec1c4d54 Add related 2023-01-06 18:22:36 +01:00
frack113 3346a6d3e4 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-06 18:21:06 +01:00
frack113 679d1ee0ed Add more ext 2023-01-06 18:17:01 +01:00
Nasreddine Bencherchali 18a77e79e3 fix: multiple issues 2023-01-06 18:04:04 +01:00
frack113 4adbb3fbd2 Add proc_creation_win_double_ext_parent 2023-01-06 17:18:50 +01:00
Nasreddine Bencherchali e56d3763b5 fix: unused selection 2023-01-06 17:16:20 +01:00
Nasreddine Bencherchali 7e73028c5e feat: updates and enhancements 2023-01-06 16:35:34 +01:00