Commit Graph

3569 Commits

Author SHA1 Message Date
Gott 2a6c27b7b5 Create proc_creation_win_deviceenroller_evasion.yml 2022-08-29 11:35:54 -04:00
Wagga 7c6bf47757 Update proc_creation_win_susp_rundll32_user32_dll.yml 2022-08-29 07:59:45 +02:00
Wagga 39edfddce4 Update proc_creation_win_lolbin_diantz_ads.yml 2022-08-29 07:58:05 +02:00
Wagga 9d3d718c27 Update proc_creation_win_icacls_deny.yml 2022-08-29 07:57:34 +02:00
Wagga d5724fb583 Update proc_creation_win_susp_advancedrun.yml 2022-08-29 07:56:59 +02:00
Wagga 11e24a6e66 Update proc_creation_win_susp_advancedrun_priv_user.yml 2022-08-29 07:56:27 +02:00
Wagga cffc6fa947 Update proc_creation_win_susp_nmap.yml 2022-08-29 07:55:38 +02:00
Wagga 5515dc7397 Update proc_creation_win_fsutil_drive_enumeration.yml 2022-08-29 07:54:56 +02:00
Wagga da82c739c5 Update proc_creation_win_attrib_system_susp_paths.yml 2022-08-29 07:54:18 +02:00
Wagga c0b3cd847f Update proc_creation_win_lolbin_cl_mutexverifiers.yml 2022-08-29 07:53:15 +02:00
Wagga 37230eabee Update proc_creation_win_lolbin_cl_loadassembly.yml 2022-08-29 07:52:56 +02:00
Wagga 762ac06eea Update proc_creation_win_lolbin_wlrmdr.yml 2022-08-29 07:52:12 +02:00
Wagga b0af5fbc8f Update proc_creation_win_lolbin_squirrel.yml 2022-08-29 07:50:55 +02:00
Wagga 3f3705164f Update proc_creation_win_net_user_add_never_expire.yml 2022-08-29 07:47:56 +02:00
Wagga 1a26c174f2 Update proc_creation_win_inline_base64_mz_header.yml 2022-08-29 07:47:27 +02:00
Wagga c820429bdb Update proc_creation_win_windows_terminal_susp_children.yml 2022-08-29 07:46:30 +02:00
Wagga 8594d926b1 Update proc_creation_win_set_policies_to_unsecure_level.yml 2022-08-29 07:43:52 +02:00
Wagga d8852f6fa6 Update proc_creation_win_dll_sideload_vmware_xfer.yml 2022-08-29 07:27:21 +02:00
Wagga f5a0c0e012 Update proc_creation_win_lolbin_winword.yml 2022-08-29 07:26:44 +02:00
Wagga c8a5414412 Update proc_creation_win_dll_sideload_defender.yml 2022-08-29 07:26:03 +02:00
Florian Roth 00305d6727 Merge pull request #3438 from frack113/redcannary_20220828
Redcannary 20220828
2022-08-28 19:53:08 +02:00
Florian Roth ff88a7e177 fix: FP with VSCode extensions 2022-08-28 19:33:49 +02:00
Florian Roth bd03d86695 Update proc_creation_win_nimgrab.yml 2022-08-28 11:40:05 +02:00
frack113 b9a2c720a8 Redcannary 20220828 2022-08-28 11:16:24 +02:00
Florian Roth 46d917f2ca Merge pull request #3435 from nasbench/nasbench-rule-devel
Rule Dev (New + Update)
2022-08-27 08:56:23 +02:00
Florian Roth 33cd3e9fd9 Merge branch 'master' into rule-devel 2022-08-26 22:49:54 +02:00
Florian Roth bc46de2685 Delete proc_creation_win_sliver_default_shell_command.yml 2022-08-26 20:52:05 +02:00
Florian Roth dcec3280fc merge: Nasreddine's Sliver rules 2022-08-26 20:51:39 +02:00
Nasreddine Bencherchali 40ce21f3e8 Update proc_creation_win_schtasks_system.yml 2022-08-26 19:03:50 +01:00
Nasreddine Bencherchali fcd9236bae Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel 2022-08-26 19:02:04 +01:00
frack113 bdbce73c9d Merge pull request #3434 from nasbench/revert-3433-patch-1
Revert "Fixing selection_user to match NT AUTHORITY\SYSTEM"
2022-08-26 19:56:59 +02:00
Florian Roth 3c363f6bf4 refactor: sliver service rule, fix: FP 2022-08-26 18:09:11 +02:00
Florian Roth 3424c191fc revert: deleted rule 2022-08-26 18:04:02 +02:00
Florian Roth bee8468f6c rule: sysaidserver child 2022-08-26 18:03:14 +02:00
Florian Roth 0dddfab086 rule: MuddyWater rules 2022-08-26 17:49:58 +02:00
Florian Roth c374703ff5 rules: more sliver rules 2022-08-26 17:48:02 +02:00
phantinuss e80116e704 fix: FPs found in testing environment 2022-08-26 17:29:49 +02:00
Nasreddine Bencherchali 11a322f4f0 New + Update 2022-08-26 15:38:43 +01:00
Nasreddine Bencherchali 060fbcda31 Revert "Fixing selection_user to match NT AUTHORITY\SYSTEM" 2022-08-26 11:25:41 +01:00
jkb f316469cd7 Fixing selection_user to match NT AUTHORITY\SYSTEM
This should be 'SYSTEM' not ' SYSTEM ' - these leading/trailing spaces are making this detection invalid since the /RU parameter value will be "NT AUTHORITY\SYSTEM".
2022-08-26 00:25:04 +02:00
Florian Roth a40cce9a63 rule: Sliver implant shell activity pattern 2022-08-25 17:50:47 +02:00
Florian Roth c5e183cf2e Merge pull request #3432 from SigmaHQ/rule-devel
Create Stream Hash Rules
2022-08-25 14:17:50 +02:00
frack113 f324148291 Merge pull request #3424 from nasbench/nasbench-rule-devel
Rule Dev - Update + New Rules
2022-08-24 19:59:08 +02:00
Nasreddine Bencherchali 728a7ccb66 Fix after review 2022-08-24 18:35:23 +01:00
Florian Roth 6a81603d28 Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2022-08-24 16:51:27 +02:00
Florian Roth 4baa18bd33 refactor: added transfer.sh domain 2022-08-24 16:51:26 +02:00
Nasreddine Bencherchali afff53b812 Add '/k' option to CMD rules 2022-08-24 12:48:23 +01:00
Nasreddine Bencherchali f9c39c3c1e Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel 2022-08-24 01:06:02 +01:00
Nasreddine Bencherchali 88295a305c Rule Dev 2022-08-24 01:05:40 +01:00
Florian Roth cdf5b371f1 refactor: extending the rule with /k param 2022-08-23 20:44:11 +02:00