Commit Graph

7428 Commits

Author SHA1 Message Date
Austin Songer 1fa32fcd1a Update 2021-08-23 22:02:47 +00:00
Austin Songer 4ab9519546 Update 2021-08-23 18:59:07 +00:00
Austin Songer 8e4b8f45dd Update 2021-08-23 18:57:17 +00:00
Austin Songer a5c551ad61 Merge branch '365' of https://github.com/austinsonger/sigma into 365 2021-08-23 18:55:40 +00:00
Austin Songer 41786a1b63 In-Progress 2021-08-23 18:55:29 +00:00
Austin Songer 3d151ef9f1 Update microsoft365_logon_from_risky_ip_address.yml 2021-08-23 12:59:53 -05:00
Austin Songer 23e96712f8 Update microsoft365_data_exfiltration_to_unsanctioned_app.yml 2021-08-23 12:59:44 -05:00
Austin Songer 1834324a16 Update 2021-08-23 17:33:57 +00:00
Austin Songer 7d211f2487 Data exfiltration to unsanctioned apps 2021-08-23 17:33:00 +00:00
Austin Songer f5286905ff Merge branch 'SigmaHQ:master' into microsoft365 2021-08-23 12:22:58 -05:00
Austin Songer ae84559488 M365 - Risky IP Addresses 2021-08-23 17:18:16 +00:00
frack113 be316db84d Merge pull request #1899 from secDre4mer/master
feat: Add rule for malicious CSR export on Exchange
2021-08-23 17:26:16 +02:00
frack113 cac40065b0 Merge pull request #1900 from ZikyHD/add_fields
Add fields to event log cleared
2021-08-23 17:15:32 +02:00
SomeOne 037f33b5e2 Replace by default windows fieldnames 2021-08-23 15:24:48 +02:00
SomeOne 45f30cb2b4 Add fields to event log cleared 2021-08-23 15:00:07 +02:00
Max Altgelt 82dde594d1 feat: Add rule for malicious CSR export on Exchange 2021-08-23 11:20:30 +02:00
frack113 52595de85e Merge pull request #1889 from rachelrice/update_aws_rules
Update AWS CloudTrail rules
2021-08-23 11:14:31 +02:00
frack113 8f29075129 Merge pull request #1897 from yugoslavskiy/master
add ATC to the "Projects or Products that use Sigma" section
2021-08-23 06:30:16 +02:00
Yugoslavskiy Daniil 9b30b487c3 add ATC to the Projects or Products that use Sigma section 2021-08-23 04:25:29 +02:00
frack113 fc9666fb4e Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
2021-08-22 18:56:08 +02:00
frack113 0a410010a2 Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
2021-08-22 18:50:58 +02:00
SomeOne 295054dcbe Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
Thomas Patzke 3396d72d81 Merge pull request #1887 from frack113/fix_NodeSubexpression_len
fix sigmac error "has no len()"
2021-08-22 12:11:16 +02:00
Thomas Patzke cbf1fd213b Merge pull request #1856 from theoguidoux/sql-sqlite-fields-selection
[Ready] SQL & SQLite rule fields selection
2021-08-22 12:09:07 +02:00
Thomas Patzke b97a47c32a Merge pull request #1895 from frack113/fix_sigma2attack.py
sigma2attack.py fix yaml error
2021-08-22 12:05:54 +02:00
Thomas Patzke ac8cf2b2c7 Merge pull request #1783 from iChenLei/update-ci-badge
chore: update sigma ci badge
2021-08-22 12:05:23 +02:00
frack113 7cd71b2240 fix yaml error 2021-08-22 08:57:07 +02:00
frack113 b84b301add Merge pull request #1894 from austinsonger/master
Update m365.yml
2021-08-22 07:52:58 +02:00
Austin Songer 579a80411d Update m365.yml 2021-08-21 15:03:31 -05:00
Austin Songer 645492cef5 Update m365.yml
just working on expanding this.
2021-08-21 14:57:38 -05:00
frack113 064c65cb1f Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
2021-08-21 18:04:52 +02:00
frack113 07a87aa7f8 Merge pull request #1858 from frack113/fix_pr718
Replace pr718
2021-08-21 18:02:30 +02:00
frack113 16347e77e4 Merge pull request #1893 from pbssubhash/master
Adding a rule to detect WriteHijack DLL exploitation by PowerUp
2021-08-21 18:00:40 +02:00
frack113 a44206bfa0 Some cleanup 2021-08-21 17:33:39 +02:00
pbssubhash 7bcb6494b7 Merge branch 'master' of https://github.com/pbssubhash/sigma 2021-08-21 20:04:15 +05:30
pbssubhash eee497f656 Title modification 2021-08-21 20:04:03 +05:30
frack113 73c953d633 Fix title 2021-08-21 16:18:16 +02:00
pbssubhash a415463f5b Modified rule 2021-08-21 19:37:28 +05:30
pbssubhash fba54b8d69 First Rule commit 2021-08-21 17:47:56 +05:30
frack113 42c90b9d20 fix powershell_psattack error 2021-08-21 10:05:47 +02:00
frack113 2f683b9ab7 fix powershell_clear_powershell_history error 2021-08-21 10:00:48 +02:00
frack113 0fb6c35b1f Cleanup PS rules 2021-08-21 09:58:58 +02:00
frack113 da839775fe Update PS rules 2021-08-21 09:50:59 +02:00
frack113 6c529f7ab2 Update PS rules 2021-08-21 09:33:52 +02:00
frack113 cb95582077 Update PowerShell rule 2021-08-21 09:08:38 +02:00
frack113 dbbb422a42 Merge pull request #1885 from austinsonger/microsoft365_unusual_volume_of_file_deletion.yml
microsoft365_unusual_volume_of_file_deletion.yml
2021-08-20 17:20:43 +02:00
frack113 34ac3587e9 Merge pull request #1884 from austinsonger/microsoft365_potential_ransomware_activity.yml
microsoft365_potential_ransomware_activity.yml
2021-08-20 17:20:34 +02:00
frack113 73fee68d4b Merge pull request #1883 from austinsonger/microsoft365_user_restricted_from_sending_email.yml
microsoft365_user_restricted_from_sending_email.yml
2021-08-20 17:20:22 +02:00
frack113 b9a355e3f4 cleanup falsepositives 2021-08-20 17:18:32 +02:00
Florian Roth b92346ba5f Merge pull request #1882 from austinsonger/win_susp_bitstransfer.yml
win_susp_bitstransfer.yml
2021-08-20 16:53:52 +02:00