frack113
|
a305a0be45
|
Merge pull request #2983 from d4rk-d4nph3/master
Added rule for Nimbuspwn exploitation
|
2022-05-05 20:41:30 +02:00 |
|
Bhabesh
|
a70e96355c
|
Beautify the rule
|
2022-05-05 23:48:41 +05:45 |
|
Bhabesh
|
7f2ad6df89
|
Fix for error
|
2022-05-05 11:24:20 +05:45 |
|
Bhabesh
|
46827e2655
|
Added rule for Nimbuspwn exploitation
|
2022-05-04 20:30:40 +05:45 |
|
zakibro
|
0bb96b323d
|
Update lnx_crontab_file_modification.yml
|
2022-04-19 19:47:12 +02:00 |
|
zakibro
|
4212e24424
|
Update lnx_crontab_file_modification.yml
fixing title
|
2022-04-16 17:44:43 +02:00 |
|
Pawel Mazur
|
c1db0b4fed
|
Adding Linxu crontab rule
|
2022-04-16 17:36:11 +02:00 |
|
Florian Roth
|
3114433944
|
fix: product unix > linux
|
2022-03-24 11:40:51 +01:00 |
|
Florian Roth
|
fb7d0b5469
|
refactor: move macos rules to separate dir
|
2022-03-24 09:17:05 +01:00 |
|
phantinuss
|
043747822f
|
fix: more falsepositives harmonization
|
2022-03-16 14:57:06 +01:00 |
|
phantinuss
|
6ae28b7a1c
|
fix: legitimate --> Legitimate
|
2022-03-16 14:35:19 +01:00 |
|
phantinuss
|
8d3f8acb60
|
fix: none --> Unknown
|
2022-03-16 14:19:21 +01:00 |
|
phantinuss
|
b23eee6ebf
|
fix: unknown --> Unknown
|
2022-03-16 13:43:54 +01:00 |
|
Florian Roth
|
9beafefe52
|
rules: suspicious linux patterns
|
2022-03-14 12:01:52 +01:00 |
|
frack113
|
7fb8272f94
|
Name Normalization
Name Normalization
|
2022-02-27 10:58:14 +01:00 |
|
frack113
|
ec7319be21
|
Name Normalization
Name Normalization
|
2022-02-27 07:39:46 +01:00 |
|
Florian Roth
|
86892c8f89
|
Merge pull request #2726 from rafaelszt/master
Adds root folder monitoring for bash configs
|
2022-02-22 17:33:21 +01:00 |
|
Rafael Teixeira
|
09aa506059
|
Updated modified date
|
2022-02-22 12:48:41 -03:00 |
|
frack113
|
8bb3379b68
|
Normalization of rule names
|
2022-02-22 11:16:31 +01:00 |
|
Rafael Teixeira
|
6ff13ddf68
|
Added root user files
|
2022-02-21 10:15:48 -03:00 |
|
Andreas Hunkeler
|
c8fa678a9b
|
rule: add tag execution to new bpftrace rule
|
2022-02-11 14:14:22 +01:00 |
|
Andreas Hunkeler
|
66b9d35ee9
|
rule: add new bpftrace unsafe option rule
|
2022-02-11 12:08:53 +01:00 |
|
frack113
|
ff9ecf395f
|
Fix detection
|
2022-02-06 19:16:27 +01:00 |
|
zakibro
|
d5257f9a05
|
Update lnx_auditd_systemd_service_creation.yml
fixing logic
|
2022-02-04 12:15:36 +01:00 |
|
Pawel Mazur
|
fede3b1183
|
Auditd rule - Systemd Service Creation
|
2022-02-03 20:31:07 +01:00 |
|
frack113
|
c3c13d6089
|
add lnx_pwnkit_local_privilege_escalation
|
2022-01-29 10:07:54 +01:00 |
|
zakibro
|
c1c5ed0db7
|
Update lnx_auditd_cve_2021_4034.yml
|
2022-01-27 12:55:22 +01:00 |
|
zakibro
|
bd9b5172cd
|
Update lnx_auditd_cve_2021_4034.yml
|
2022-01-27 12:44:53 +01:00 |
|
Pawel Mazur
|
c924977576
|
Adding auditd rule for CVE-2021-4034
|
2022-01-27 12:36:19 +01:00 |
|
Pawel Mazur
|
bbdfb79bc0
|
Adding new linux auditd rule - Disable Dystem Firewall
|
2022-01-22 15:12:24 +01:00 |
|
frack113
|
dfc477888b
|
Merge pull request #2583 from BlackB0lt/patch-22
Create lnx_doas_conf_creation.yml
|
2022-01-21 18:44:08 +01:00 |
|
Florian Roth
|
885f70b0f3
|
Update lnx_doas_execution.yml
|
2022-01-20 13:08:39 +01:00 |
|
Florian Roth
|
375acb8ba4
|
Update lnx_doas_conf_creation.yml
|
2022-01-20 13:07:53 +01:00 |
|
Sittikorn S
|
f21d10b69f
|
Update lnx_doas_conf_creation.yml
|
2022-01-20 11:00:18 +07:00 |
|
Sittikorn S
|
f195160baa
|
Update lnx_doas_execution.yml
|
2022-01-20 10:58:47 +07:00 |
|
Sittikorn S
|
8b94046efa
|
Update lnx_doas_execution.yml
|
2022-01-20 10:11:24 +07:00 |
|
Sittikorn S
|
41065bcc91
|
Update lnx_doas_conf_creation.yml
|
2022-01-20 10:11:14 +07:00 |
|
Sittikorn S
|
bb574151ba
|
Create lnx_doas_conf_creation.yml
|
2022-01-20 09:50:41 +07:00 |
|
Sittikorn S
|
4f56e0d92e
|
Update lnx_doas_execution.yml
|
2022-01-20 09:48:24 +07:00 |
|
Sittikorn S
|
eb4731b370
|
Create lnx_doas_execution.yml
|
2022-01-20 09:46:17 +07:00 |
|
frack113
|
4631d0c482
|
remove invalid tag
|
2022-01-19 18:23:30 +01:00 |
|
frack113
|
f7e670d55e
|
Simple Quote
|
2022-01-11 13:40:53 +01:00 |
|
Florian Roth
|
e055ec1d52
|
refactor: change all " of them" expressions
|
2022-01-11 10:59:57 +01:00 |
|
frack113
|
9092958019
|
fix quote
|
2022-01-10 22:25:47 +01:00 |
|
frack113
|
a885d95aa3
|
Update pattern
|
2021-12-10 16:45:42 +01:00 |
|
frack113
|
b56630ced1
|
Add lnx_susp_dev_tcp
|
2021-12-10 13:39:06 +01:00 |
|
phantinuss
|
07a0a37273
|
feat: discourage the usage of 'all of them' and migrate existing rules to use the preferred method 'all of selection*'
|
2021-12-02 14:47:39 +01:00 |
|
Pawel Mazur
|
6e43a294a2
|
Linux Auditd - Discovery of Capabilities files
|
2021-11-28 16:48:37 +01:00 |
|
frack113
|
01dc930c17
|
Change status for old rules
|
2021-11-27 11:33:14 +01:00 |
|
Florian Roth
|
4a69c71b2f
|
Update lnx_shell_clear_cmd_history.yml
|
2021-11-24 09:31:12 +01:00 |
|