Yugoslavskiy Daniil
1fc202fe5d
fix typos, update tags
2020-09-13 15:46:45 +02:00
Florian Roth
de5444a81e
Merge pull request #989 from oscd-initiative/master
...
[OSCD Initiative][ATT&CK tags update]
2020-09-08 13:27:58 +02:00
Florian Roth
6f96bbbe65
Merge pull request #977 from barvhaim/patch-1
...
Update win_new_service_creation.yml typo
2020-09-07 09:39:28 +02:00
Florian Roth
37751fc3a1
Merge pull request #978 from barvhaim/patch-2
...
Update sysmon_apt_muddywater_dnstunnel.yml typo
2020-09-07 09:39:11 +02:00
e6e6e
98c412044a
att&ck tags review: windows/process_creation part 5
...
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-09-07 02:00:41 +04:00
e6e6e
7ae76b8d99
Revert "att&ck tags review: windows/process_creation part 5"
...
This reverts commit e94c47e74e .
2020-09-07 01:28:08 +04:00
e6e6e
e94c47e74e
att&ck tags review: windows/process_creation part 5
...
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-09-07 01:19:41 +04:00
grikos
961e4eef4c
att&ck tags review: windows/process_creation part 6
2020-09-05 20:35:21 +03:00
Florian Roth
22465037ac
Update win_susp_mpcmdrun_download.yml
2020-09-04 16:50:57 +02:00
Florian Roth
3283e33cbc
Update and rename win_lolbas_mpcmdrun.yml to win_susp_mpcmdrun_download.yml
2020-09-04 16:49:44 +02:00
Matthew Matchen
df532be142
Added ID field using UUID generated value
2020-09-04 16:38:52 +02:00
Matthew Matchen
2c69815b7b
Removed empty ID field
2020-09-04 16:32:41 +02:00
Matthew Matchen
e0baa097a8
Initial creation
2020-09-04 16:00:23 +02:00
Florian Roth
720ac0d998
fix: syntax bug in rule
2020-09-03 09:18:28 +02:00
Florian Roth
198469bed3
Merge branch 'master' into rule-devel
2020-09-02 17:40:12 +02:00
Florian Roth
423f81c912
Update win_mouse_lock.yml
2020-09-02 14:49:37 +02:00
Florian Roth
73bc514f60
fix: 1 of them / one selection
2020-09-02 12:34:35 +02:00
Yugoslavskiy Daniil
11e0f794d9
review windows/process_creation part 4
2020-09-02 02:34:34 +02:00
aw350m3
7c6c5263ab
fix duplication of key modified in win_malware_emotet.yml
2020-09-01 17:09:54 +00:00
aw350m3
8ed3eb1494
att&ck tags review: windows/process_creation part 3
2020-09-01 17:02:59 +00:00
grikos
65d201b1e4
att&ck tags review: windows/process_creation part 7
2020-08-30 19:17:38 +03:00
Yugoslavskiy Daniil
e04b896cbc
fix tags
2020-08-29 21:34:20 +02:00
grikos
a95c4347d9
fixed typo in tag
2020-08-29 20:19:46 +03:00
grikos
6092bfcec1
att&ck tags review: windows/process_creation part 9
2020-08-29 19:22:09 +03:00
aw350m3
ae99a2b207
Removed extra space that broke tests
2020-08-29 04:46:12 +00:00
aw350m3
4ed3db8d23
Merge branch 'master' of github.com:oscd-initiative/sigma
2020-08-29 04:39:45 +00:00
aw350m3
da766a245f
att&ck tags review: windows/process_creation part 2
2020-08-29 04:39:30 +00:00
grikos
293662810e
att&ck tags review: windows/process_creation part 8
2020-08-28 17:14:26 +03:00
Alexey Lednyov
880b10cce1
att&ck tags review: windows/process_creation part 1, network
2020-08-27 20:43:47 +03:00
Florian Roth
7d3a6293f5
rule: Snatch ransomware
2020-08-26 09:42:34 +02:00
Florian Roth
bc74ac1f8a
Update win_susp_rasdial_activity.yml
2020-08-18 14:40:37 +02:00
Florian Roth
da54e89f30
Merge pull request #976 from diskurse/rule-devel
...
Rule devel
2020-08-17 15:02:31 +02:00
Florian Roth
8a02541b0a
style: removed lists where unnecessary
2020-08-17 15:02:16 +02:00
Florian Roth
6dc8dbb6d8
style: removed lists where unnecessary
2020-08-17 15:01:52 +02:00
Bar Haim
bd96b1c5ad
Update win_susp_rasdial_activity.yml
...
`rasdial` is an `exe`, and probably appear as `rasdial.exe`
`LIKE` is more fit in this case
2020-08-16 16:17:49 +03:00
Bar Haim
c7dc9df87e
Update sysmon_apt_muddywater_dnstunnel.yml
2020-08-16 12:39:04 +03:00
Bar Haim
4168f1e430
Update win_new_service_creation.yml
2020-08-16 11:44:40 +03:00
Cian Heasley
b378b3d62b
win_mouse_lock.yml
...
In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
2020-08-13 12:09:07 +01:00
Cian Heasley
d1e9f01d23
win_dnscat2_powershell_implementation.yml
...
The PowerShell implementation of DNSCat2 calls nslookup to craft queries. Counting nslookup processes spawned by PowerShell will show hundreds or thousands of instances if PS DNSCat2 is active locally.
2020-08-13 12:06:48 +01:00
Thomas Patzke
f827a557f2
Merge pull request #936 from rtkmokuka/typo_wmiprvse_spawning_process
...
Change fitler typo from 'Username' to 'User' for Wmiprvse Spawning Process rule
2020-08-05 23:26:14 +02:00
Florian Roth
4529e4cd52
Merge pull request #966 from Neo23x0/rule-devel
...
rule: TAIDOOR malware load
2020-08-04 14:54:24 +02:00
Florian Roth
052379a512
fix: tightened TAIDOOR rule
2020-08-04 14:37:18 +02:00
Florian Roth
c4953409aa
rule: TAIDOOR malware load
...
https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a
2020-08-04 14:31:29 +02:00
IPv777
a52583dc68
.002 = SMB/Windows Admin Shares
2020-08-03 17:43:14 +02:00
Florian Roth
df3bfb1b37
rule: Winnti Pipemon
2020-07-30 18:55:47 +02:00
Florian Roth
5abf101c0b
Merge pull request #954 from Neo23x0/rule-devel
...
Rule devel
2020-07-28 10:22:52 +02:00
Florian Roth
8970d03f6f
Merge pull request #952 from Neo23x0/devel
...
feat: Detect duplicate rule tags
2020-07-28 10:21:59 +02:00
Florian Roth
80f4b4ec71
fix: rules with duplicate tags
2020-07-27 11:44:47 +02:00
IPv777
77a8ac59ef
remove duplicate
2020-07-24 16:38:08 +02:00
Florian Roth
8a4b53eb3a
fix: rule leads to FPs on systems that don't log the cmdline parameters
2020-07-23 17:04:16 +02:00