Commit Graph

4228 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 261bb8758a Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-30 11:49:08 +01:00
frack113 aee5ca7afc Fix invalid field cast or name (#3841) 2022-12-30 11:46:21 +01:00
Nasreddine Bencherchali d4b9df608b fix: broken selection 2022-12-30 10:30:15 +01:00
Nasreddine Bencherchali 58f47b9875 fix: add known children appvlp 2022-12-30 10:24:25 +01:00
frack113 995b5918f2 Update rules/windows/process_creation/proc_creation_win_susp_shellexec_rundll_usage.yml 2022-12-30 10:21:54 +01:00
frack113 f083c5f83f Merge branch 'master' into patch-1 2022-12-30 10:12:25 +01:00
frack113 d10ecf5527 Merge pull request #3838 from redsand/fp_sysmon_werfault_child
FP when sysmon crashes and werfault gets launched
2022-12-30 10:08:09 +01:00
zydyka d7bc30587f Update proc_creation_win_sysmon_exploitation.yml 2022-12-30 09:00:57 +05:00
Nasreddine Bencherchali 1e29560591 fix: duplicate title 2022-12-30 01:10:03 +01:00
Nasreddine Bencherchali 2d5231ca2c fix: broken selection 2022-12-30 00:58:17 +01:00
Nasreddine Bencherchali c6fd915619 feat: updates and enhancements 2022-12-30 00:56:40 +01:00
Tim Shelton aeab567fb9 FP when sysmon crashes and werfault gets launched 2022-12-29 21:18:26 +00:00
fukusuket 42ab7c0484 fix regex escape 2022-12-30 00:11:52 +09:00
frack113 197615345b Add missing lolbin OSBinaries (#3835)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-29 14:36:33 +01:00
Nasreddine Bencherchali 19396788db Merge pull request #3831 from redsand/fp_suspicious_process_privilege
FP: filters out erl.exe running handle.exe with elevated privileges
2022-12-28 21:18:54 +01:00
Florian Roth f3abafed94 fix: Windows Defender detection 2022-12-28 20:52:53 +01:00
Nasreddine Bencherchali 77113a7340 fix: author ref 2022-12-28 18:42:47 +01:00
Nasreddine Bencherchali 3677b9f2e6 fix: enhance fp filter 2022-12-28 18:42:12 +01:00
Tim Shelton f5fffd8e92 FP: filters out erl.exe running handle.exe with elevated privileges 2022-12-28 16:44:25 +00:00
frack113 b3ec85b25b Merge pull request #3826 from nasbench/fix-old-sigma-link
fix: rename links from old repo to SigmaHQ
2022-12-28 11:11:04 +01:00
Nasreddine Bencherchali a25027fef8 fix: rename links from old repo to SigmaHQ 2022-12-27 21:05:16 +01:00
frack113 0392f92a0d PowerShell Token Obfuscation (#3825)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-27 20:03:05 +01:00
frack113 e1707c8f50 rewrite issue 1555 (#3818)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-27 19:28:34 +01:00
Florian Roth 3e712480c4 Merge pull request #3824 from SigmaHQ/rule-devel
Htran/NATbypass, Greedy RAR
2022-12-27 16:34:33 +01:00
Nasreddine Bencherchali 88e56229cf fix: indentation and selection names for clarity 2022-12-27 16:26:20 +01:00
Florian Roth 32a17342b4 Update rules/windows/process_creation/proc_creation_win_rar_susp_greedy.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-27 15:46:37 +01:00
frack113 8a6f66b120 Rules for Issue 575 (#3820)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-27 15:17:45 +01:00
Nasreddine Bencherchali 47572e08c8 fix: remove additional space 2022-12-27 14:27:55 +01:00
frack113 7060db3d47 Promotion rules (#3821)
* Promotion rules

* fix missing null

* fix: modified date

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-27 12:29:10 +01:00
sai prashanth pulisetti 8b05818559 Create proc_creation_win_SharpImpersonation_tool.yml (#3823)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-27 12:02:22 +01:00
Florian Roth 0cd5eb375d Merge branch 'master' into rule-devel 2022-12-27 11:58:53 +01:00
Florian Roth 65f92dcd47 rule: HTran / NATBypass usage 2022-12-27 11:58:44 +01:00
frack113 8ea3999754 Merge pull request #3302 from memory-shards/master
Create proc_creation_win_lolbin_agentexecutor.yml
2022-12-24 15:45:35 +01:00
Nasreddine Bencherchali 794d93c298 fix: broken selection 2022-12-24 14:11:32 +01:00
Nasreddine Bencherchali e7d6bf7cab fix: enhance logic of AgentExecutor rules 2022-12-24 14:10:21 +01:00
frack113 271460062e Merge pull request #3815 from nasbench/aadinternals-rules
feat: new aadinternals related rules
2022-12-23 20:20:07 +01:00
frack113 5fdad241ea Update proc_creation_win_lolbin_agentexecutor.yml 2022-12-23 20:11:55 +01:00
Nasreddine Bencherchali 5a8808e0ac fix: wrong category 2022-12-23 19:27:34 +01:00
Nasreddine Bencherchali 1f38e15bb4 fix: fp section 2022-12-23 19:24:08 +01:00
Nasreddine Bencherchali 92e4081de3 fix: duplicate title 2022-12-23 19:20:43 +01:00
Nasreddine Bencherchali 28664d5bb3 feat: new aadinternals related rules 2022-12-23 19:16:17 +01:00
Nasreddine Bencherchali 0aa6f26a6f feat: updates and enhancements 2022-12-23 18:37:59 +01:00
frack113 df015e555c Add more ref 2022-12-23 13:22:50 +01:00
frack113 546e53fb35 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-23 12:34:56 +01:00
frack113 bee5b2f252 Issue 575 page 43 2022-12-23 11:10:17 +01:00
frack113 b200b5dedb Fix title 2022-12-23 10:58:11 +01:00
frack113 9617cdd4ea Issue 575 page 42 2022-12-23 10:50:34 +01:00
Nasreddine Bencherchali 03cc78e916 feat: filename test enhancements (#3812) 2022-12-23 09:25:16 +01:00
frack113 a9a0d6217d Merge pull request #3808 from veramine/patch-11
Remove Logitech auto-updater false positive
2022-12-22 10:37:45 +01:00
Nasreddine Bencherchali 653b498315 fix: update modified field 2022-12-22 10:31:25 +01:00