Commit Graph

10135 Commits

Author SHA1 Message Date
phantinuss 2cecd0e6ef workflow: rename steps 2022-02-21 11:01:44 +01:00
phantinuss 0c473a3e77 workflow: evaluate findings, exclude known FPs 2022-02-21 11:01:44 +01:00
phantinuss 20761d0332 workflow: link to latest release 2022-02-21 11:01:44 +01:00
phantinuss 48eefe29f7 workflow: verbose remove of deprecated rules 2022-02-21 11:01:43 +01:00
phantinuss 00f1f561dd workflow: fix: missing -l grep flag 2022-02-21 11:01:43 +01:00
phantinuss d3397929b4 workflow: fix: quote command with pipe 2022-02-21 11:01:43 +01:00
phantinuss e6fe8fdedd workflow: execute evtx-sigma-checker 2022-02-21 11:01:43 +01:00
frack113 fa083b5008 Merge pull request #2713 from frack113/tor
Simple TOR rules
2022-02-21 06:27:38 +01:00
frack113 2a0aa9a24b Merge pull request #2711 from frack113/file_rename
add file_rename_win_not_dll_to_dll
2022-02-21 06:27:24 +01:00
frack113 15e659fed8 Rename win_etw_rename_to_dll.yml to file_rename_win_not_dll_to_dll.yml 2022-02-20 18:59:08 +01:00
frack113 4d8cbe89b7 Merge pull request #2714 from frack113/fix_reg_fp
Fix FP binary
2022-02-20 18:00:13 +01:00
frack113 dcf936bb6c Rename win_pc_tor_browser.yml to proc_creation_win_tor_browser.yml 2022-02-20 17:59:53 +01:00
Florian Roth dff806c5bc changed description, fix: onion TLD position of '.' 2022-02-20 12:17:12 +01:00
Florian Roth e7bf14c6dc description and title 2022-02-20 12:14:57 +01:00
Florian Roth 505734730d increased level 2022-02-20 12:14:14 +01:00
Florian Roth d3c0d90ba7 increased level 2022-02-20 12:14:05 +01:00
frack113 470ca979b4 Fix FP binary 2022-02-20 11:31:08 +01:00
frack113 82660bbaf2 Simple TOR rules 2022-02-20 11:26:13 +01:00
frack113 604600ac2f Merge pull request #2709 from frack113/fix_aurora_fp
Fix FP for win_pc_susp_run_folder
2022-02-20 09:05:17 +01:00
frack113 ec7af1fcaa add win_etw_rename_to_dll 2022-02-19 18:30:14 +01:00
frack113 631a300236 Fix some FP 2022-02-19 10:25:26 +01:00
frack113 fde2e7b61e Merge pull request #2706 from phantinuss/master
Fix FPs
2022-02-19 08:09:40 +01:00
phantinuss f2be1ed1b8 fix: FPs 2022-02-18 13:04:25 +01:00
frack113 cabe5c5043 Merge pull request #2703 from frack113/lolbin
add win_pc_lolbin_wlrmdr
2022-02-17 19:26:19 +01:00
Florian Roth e0d8f59f42 Update win_pc_lolbin_wlrmdr.yml 2022-02-17 16:24:52 +01:00
Florian Roth dba4a43ef9 Merge pull request #2702 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-02-17 13:02:07 +01:00
Florian Roth 5deb9af698 Update sysmon_reg_office_security.yml 2022-02-17 08:15:25 +01:00
Florian Roth 283475e064 Merge branch 'master' into aurora-false-positive-fixing 2022-02-17 08:13:38 +01:00
frack113 1a76bb82d6 Merge pull request #2700 from frack113/DOSfuscation
add win_pc_cmd_dosfuscation
2022-02-17 06:32:45 +01:00
frack113 3b02967ffb add win_pc_lolbin_wlrmdr 2022-02-16 19:53:46 +01:00
Florian Roth 50efc894bc add common "set" expressions
add common caret obfuscated "set" expressions often found in Invoke-Obfuscation code
2022-02-16 17:33:33 +01:00
Florian Roth 8850de3a2e exclude values that could be prone to FPs
Sorry, I have to disable some of the values. I guess these values would make the rule trigger many false positives.
2022-02-16 17:31:52 +01:00
Florian Roth eb9e23dc22 Merge pull request #2701 from phantinuss/checkbaseline
Fix FPs (Example Installation 5)
2022-02-16 17:29:04 +01:00
Florian Roth 57271c3c00 fix: bugs in rules 2022-02-16 17:26:57 +01:00
frack113 fb71c1bb67 fix double double quote 2022-02-16 17:19:01 +01:00
Florian Roth 51bbe21c70 fix: more Aurora FP fixes 2022-02-16 17:16:50 +01:00
Florian Roth 2500c16aea fix: FPs noticed with Aurora 2022-02-16 17:00:27 +01:00
phantinuss 9fce5735ad fix: remove unneded escape for " 2022-02-16 16:31:13 +01:00
phantinuss c92b5e8835 fix: known FP 2022-02-16 16:31:13 +01:00
phantinuss 27e4c333d6 fix: filter MS Office 2022-02-16 16:31:13 +01:00
phantinuss ebc27d7c9f fix: exclude cutepdf writer 2022-02-16 16:31:12 +01:00
phantinuss 6816f32c93 fix: remove trailing \ 2022-02-16 16:31:12 +01:00
phantinuss 3207f3ff47 fix: filter known software 2022-02-16 16:31:12 +01:00
phantinuss 5a03d8d5ac fix: filter known software 2022-02-16 16:31:12 +01:00
phantinuss e2f80e5aa8 fix: exclude msiexec from SysWOW64 2022-02-16 16:31:12 +01:00
phantinuss 3e254fe3e4 fix: exclude known office addins 2022-02-16 16:31:12 +01:00
phantinuss cc6613a799 fix: filter MS Office and Dropbox 2022-02-16 16:31:12 +01:00
phantinuss 741640cb10 fix: filter known extensions and toolbar entries 2022-02-16 16:31:12 +01:00
phantinuss ac8cd7516a fix: single list items 2022-02-16 16:31:11 +01:00
phantinuss 7b8ea16ca3 fix: single list item 2022-02-16 16:31:11 +01:00