Commit Graph

3835 Commits

Author SHA1 Message Date
yugoslavskiy 29fe6e46d8 Merge pull request #1211 from zipa-original/win_persistence_telemetry
[OSCD] Added a rule to detect abusing windows telemetry for persistence
2021-01-06 00:20:51 +03:00
yugoslavskiy c71e0ae0ea Merge pull request #1209 from vburov/patch-15
[OSCD] Create win_susp_multiple_files_renamed_or_deleted.yml
2021-01-06 00:19:41 +03:00
yugoslavskiy 38661bbc10 Merge pull request #1208 from NikitaStormwind/RTT(17)
[OSCD] Atomic Red Team: Detected Windows Software Discovery (T1518)
2021-01-06 00:19:20 +03:00
yugoslavskiy 2cf1994763 Merge pull request #1206 from w0rk3r/oscd5
[OSCD] Windows - Suspicious Service DACL Modification
2021-01-06 00:18:53 +03:00
yugoslavskiy aad2838f58 Merge pull request #1198 from tas-kmanager/mt-oscd-sigma547-50-rule2
[OSCD] Always Install Elevated - Slide 50 - Rule 2
2021-01-06 00:18:44 +03:00
yugoslavskiy e0286abb62 Merge pull request #1197 from w0rk3r/oscd_rules_improvement2
[OSCD] Small improvements on others rules
2021-01-06 00:18:36 +03:00
yugoslavskiy 0b7babaa84 Merge pull request #1196 from tas-kmanager/mt-oscd-sigma547-50-rule1
[OSCD] Always Install Elevated - Slide 50 - Rule 1
2021-01-06 00:18:26 +03:00
yugoslavskiy fc1fa23440 Merge pull request #1191 from vburov/patch-14
[OSCD] Create powershell_cmdline_special_characters.yml
2021-01-06 00:18:12 +03:00
yugoslavskiy 8e50eeb4a9 Merge pull request #1187 from nsaddler/lolbas108
[OSCD] LOLBAS Manage-bde.yml
2021-01-06 00:18:02 +03:00
yugoslavskiy cfbd10ab8b Merge pull request #1186 from nsaddler/lolbas107_2
[OSCD] LOLBAS CL_Mutexverifiers - powershell
2021-01-06 00:17:54 +03:00
yugoslavskiy e91d48cc93 Merge pull request #1185 from nsaddler/lolbas107_1
[OSCD] LOLBAS CL_Mutexverifiers - process_creation
2021-01-06 00:17:46 +03:00
yugoslavskiy 9d1c695204 Merge pull request #1184 from nsaddler/lolbas106_1
[OSCD] LOLBAS CL_Invocation - powershell
2021-01-06 00:17:10 +03:00
yugoslavskiy def4a7dbb9 Merge pull request #1183 from nsaddler/lolbas106
[OSCD] LOLBAS CL_Invocation - process_creation
2021-01-06 00:17:01 +03:00
yugoslavskiy 6f2e8c56b2 Merge pull request #1182 from nsaddler/lolbas80
[OSCD] LOLBAS wab.yml
2021-01-06 00:16:53 +03:00
yugoslavskiy e1fd69f548 Merge pull request #1179 from SanWieb/OSCD_regedit_3
[OSCD] regedit.exe LOLbas 72 [3]
2021-01-06 00:16:45 +03:00
yugoslavskiy 8e6b77fc4f Merge pull request #1177 from OpalSec/oscd
[OSCD] Tasks 24, 25 & 26: Detection for Invoke-Obfuscation CLIP+, STDIN+ & VAR+ Launchers
2021-01-06 00:16:34 +03:00
yugoslavskiy 95d8a9daf0 Merge pull request #1174 from uncleAntik/update
[OSCD] LOLBin vsjitdebugger.exe #136
2021-01-06 00:16:20 +03:00
yugoslavskiy 252345ca00 Merge pull request #1173 from uncleAntik/fix
[OSCD] LOLBin te.exe #133
2021-01-06 00:16:12 +03:00
yugoslavskiy aeb448cd4d Merge pull request #1171 from alejandroortuno/network-sniffing
[OSCD] MacOS Network Sniffing
2021-01-06 00:15:52 +03:00
yugoslavskiy ebc6451b86 Merge pull request #1170 from alejandroortuno/startup-items
[OSCD] MacOS Startup Items
2021-01-06 00:15:45 +03:00
yugoslavskiy ad739f7f29 Merge pull request #1169 from remotephone/oscd_t1113
[OSCD] - T1113 - macOS Screencapture via builtin screencapture utility
2021-01-06 00:15:37 +03:00
yugoslavskiy d50c081f3f Merge pull request #1168 from remotephone/oscd_t1056_002
[OSCD] macOS - T1056.002 - GUI Input capture
2021-01-06 00:15:30 +03:00
yugoslavskiy 1fd0afc58e Merge pull request #1167 from tas-kmanager/mt-oscd-sigma547-43
[OSCD] Add Accesschk tool usage rule
2021-01-06 00:14:08 +03:00
yugoslavskiy 5ade9208d5 Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
2021-01-06 00:12:34 +03:00
yugoslavskiy 46eb01f3c5 Merge pull request #1164 from GlebSukhodolskiy/oscd_reg
[OSCD] Modified Rule "Autorun Keys Modification"
2021-01-06 00:11:58 +03:00
yugoslavskiy 4c8e0b201d Merge pull request #1162 from uncleAntik/131
[OSCD] LOLBin sqltoolsps.exe #131
2021-01-06 00:11:33 +03:00
yugoslavskiy b56a7181ce Merge pull request #1157 from invrep-de/oscd
[OSCD] Bad Opsec Powershell Artifacts
2021-01-06 00:11:24 +03:00
yugoslavskiy 319ebd158c Merge pull request #1155 from sn0w0tter/oscd2
[OSCD] LOLBAS atbroker suspicious creation of ATs
2021-01-06 00:11:13 +03:00
yugoslavskiy d2087c276c Merge pull request #1151 from zinint/1009-27-2
[OSCD] Detects Obfuscated Powershell via VAR++ Launcher #27 (Services)
2021-01-06 00:10:55 +03:00
yugoslavskiy 1f0d081c01 Merge pull request #1144 from NikitaStormwind/regular28(3)
[OSCD] Detects Obfuscated Powershell via Stdin in Scripts #28 (Services)
2021-01-05 23:23:00 +03:00
yugoslavskiy 1cfc0d17ef Merge pull request #1141 from omkar72/oscd-6
[OSCD] suspicious clr logs creation
2021-01-05 23:22:36 +03:00
yugoslavskiy 82e5d031b0 Merge pull request #1139 from omkar72/oscd-4
[OSCD] script applications loading .net dll
2021-01-05 23:17:25 +03:00
yugoslavskiy 635ac44949 Merge pull request #1132 from remotephone/oscd_t1070_002
[OSCD] Adding t1070_002 - Clear mac system logs
2021-01-05 23:16:57 +03:00
yugoslavskiy 793d271d37 Merge pull request #1131 from oscd-initiative/oscd_sigma_art_macos_task_63
[OSCD] macOS hidden user creation
2021-01-05 23:16:36 +03:00
yugoslavskiy a82c559816 Merge pull request #1130 from vburov/patch-13
[OSCD] Create powershell_cmdline_specific_encoded_methods.yml
2021-01-05 23:16:24 +03:00
yugoslavskiy dd7a95ac74 Merge pull request #1081 from cy1337/patch-1
[OSCD] Added nltest LOLBIN
2021-01-05 23:16:14 +03:00
yugoslavskiy a4101a6808 Merge pull request #1128 from alejandroortuno/local-group
[OSCD] Local System Groups Discovery
2021-01-05 23:14:47 +03:00
yugoslavskiy db66f8365e Merge pull request #1127 from alejandroortuno/account-creation
[OSCD]  MacOS local account creation
2021-01-05 23:14:28 +03:00
yugoslavskiy f2c6011c6b Merge pull request #1126 from skirankumar/master
[OSCD]Sysmon_silenttrinity_stager_msbuild_activity.yml
2021-01-05 23:14:20 +03:00
yugoslavskiy 1c1c38e091 Merge pull request #1119 from uncleAntik/oscd
[OSCD] sqlps.exe LOLbin
2021-01-05 23:14:02 +03:00
yugoslavskiy 07ac09f9aa Merge pull request #1114 from NikitaStormwind/regular29(3)
[OSCD] Detects Obfuscated Powershell via use Clip.exe in Scripts #29 (Services)
2021-01-05 23:13:48 +03:00
yugoslavskiy 220a4873c7 Merge pull request #1109 from NikitaStormwind/regular31(3)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (Services)
2021-01-05 23:13:38 +03:00
yugoslavskiy 9803dc8baa Merge pull request #1108 from NikitaStormwind/regular30(3)
[OSCD] Detects Obfuscated Powershell via use Rundll32 in Scripts #30 (Services)
2021-01-05 23:13:27 +03:00
yugoslavskiy 39991a8ab6 Merge pull request #1106 from stvetro/2020
[OSCD] Suspicious ftp.exe usage (LOLBin)
2021-01-05 23:13:03 +03:00
yugoslavskiy 804db42b7a Merge pull request #1105 from Vasilisa-L/OSCD_rasautou
[OSCD] Rasautou.exe LOLbin
2021-01-05 23:12:48 +03:00
yugoslavskiy 794cd7aaeb Merge pull request #1104 from Vasilisa-L/OSCD_rpcping
[OSCD] rpcping lolbin
2021-01-05 23:12:35 +03:00
yugoslavskiy 05b03afddb Merge pull request #1103 from concorde18/oscd_win_susp_diskshadow
[OSCD] win_susp_diskshadow
2021-01-05 23:10:55 +03:00
yugoslavskiy d48bac226f Merge pull request #1099 from NikitaStormwind/regular31(2)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (process_creation)
2021-01-05 23:10:46 +03:00
yugoslavskiy 32aea9ad2b Merge pull request #1098 from NikitaStormwind/regular31
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (4104, 4103)
2021-01-05 23:10:28 +03:00
yugoslavskiy ae3c0d0801 Merge pull request #1095 from esebese/task136
[OSCD]win_pe_exec_vsjitdebugger.yml added
2021-01-05 23:10:18 +03:00