frack113
|
dcf936bb6c
|
Rename win_pc_tor_browser.yml to proc_creation_win_tor_browser.yml
|
2022-02-20 17:59:53 +01:00 |
|
Florian Roth
|
e7bf14c6dc
|
description and title
|
2022-02-20 12:14:57 +01:00 |
|
Florian Roth
|
505734730d
|
increased level
|
2022-02-20 12:14:14 +01:00 |
|
frack113
|
82660bbaf2
|
Simple TOR rules
|
2022-02-20 11:26:13 +01:00 |
|
frack113
|
604600ac2f
|
Merge pull request #2709 from frack113/fix_aurora_fp
Fix FP for win_pc_susp_run_folder
|
2022-02-20 09:05:17 +01:00 |
|
frack113
|
631a300236
|
Fix some FP
|
2022-02-19 10:25:26 +01:00 |
|
frack113
|
cabe5c5043
|
Merge pull request #2703 from frack113/lolbin
add win_pc_lolbin_wlrmdr
|
2022-02-17 19:26:19 +01:00 |
|
Florian Roth
|
e0d8f59f42
|
Update win_pc_lolbin_wlrmdr.yml
|
2022-02-17 16:24:52 +01:00 |
|
frack113
|
1a76bb82d6
|
Merge pull request #2700 from frack113/DOSfuscation
add win_pc_cmd_dosfuscation
|
2022-02-17 06:32:45 +01:00 |
|
frack113
|
3b02967ffb
|
add win_pc_lolbin_wlrmdr
|
2022-02-16 19:53:46 +01:00 |
|
Florian Roth
|
50efc894bc
|
add common "set" expressions
add common caret obfuscated "set" expressions often found in Invoke-Obfuscation code
|
2022-02-16 17:33:33 +01:00 |
|
Florian Roth
|
8850de3a2e
|
exclude values that could be prone to FPs
Sorry, I have to disable some of the values. I guess these values would make the rule trigger many false positives.
|
2022-02-16 17:31:52 +01:00 |
|
frack113
|
fb71c1bb67
|
fix double double quote
|
2022-02-16 17:19:01 +01:00 |
|
phantinuss
|
7b8ea16ca3
|
fix: single list item
|
2022-02-16 16:31:11 +01:00 |
|
phantinuss
|
96bf7421fc
|
fix: reworked rule and added more FP filters
|
2022-02-16 16:31:11 +01:00 |
|
Florian Roth
|
93be74b2fb
|
Merge pull request #2699 from phantinuss/checkbaseline
Fix FPs (Example Installation 4)
|
2022-02-15 20:07:49 +01:00 |
|
frack113
|
ac136f3e17
|
Merge pull request #2676 from redsand/fp_allow_dynatrace_behavior
Filtering fp of dynatrace behavior
|
2022-02-15 19:41:48 +01:00 |
|
frack113
|
98975ef50e
|
add win_pc_cmd_dosfuscation
|
2022-02-15 17:58:39 +01:00 |
|
phantinuss
|
c7d270956c
|
fix: several FPs against a fresh installed Windows with example applications and basic user interaction 4
|
2022-02-15 16:40:04 +01:00 |
|
frack113
|
ce8cdf24ec
|
Aurora FP
|
2022-02-14 18:08:51 +01:00 |
|
frack113
|
b632b6bda0
|
Fix invalid logsource
|
2022-02-14 06:48:22 +01:00 |
|
frack113
|
171edbd1bc
|
Merge pull request #2694 from frack113/Red_20220213
Windows Redcannary
|
2022-02-14 06:34:20 +01:00 |
|
frack113
|
277d14f4ee
|
Merge pull request #2696 from frack113/thedfirreport_qbot
Missing Qbot rules
|
2022-02-14 06:34:09 +01:00 |
|
frack113
|
7f15b7a802
|
Missing Qbot rules
|
2022-02-13 16:07:28 +01:00 |
|
Florian Roth
|
1b7cc9b35a
|
Merge pull request #2691 from frack113/red_20220212
Windows Redcannary
|
2022-02-13 11:23:20 +01:00 |
|
frack113
|
f288134b41
|
Windows Redcannary
|
2022-02-13 11:04:00 +01:00 |
|
frack113
|
e61c9e4b2e
|
Merge pull request #2690 from frack113/susp_temp_exe
add win_pc_susp_run_folder
|
2022-02-13 09:04:16 +01:00 |
|
frack113
|
7e3c088165
|
Windows Redcannary
|
2022-02-12 15:53:13 +01:00 |
|
Florian Roth
|
0feefdc751
|
Update win_pc_susp_run_folder.yml
|
2022-02-12 10:17:27 +01:00 |
|
Florian Roth
|
626b5a0488
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-02-12 00:36:33 +01:00 |
|
frack113
|
4e0b3d719a
|
add win_pc_susp_run_folder
|
2022-02-11 21:37:11 +01:00 |
|
Florian Roth
|
85b25bf17e
|
fix: FP noticed with Aurora
VSCode installer uses .tmp extension
|
2022-02-11 20:21:35 +01:00 |
|
Florian Roth
|
891475dccb
|
Merge pull request #2684 from SigmaHQ/rule-devel
rules: SAM dump, suspicious program names, iso/img mount
|
2022-02-11 18:06:20 +01:00 |
|
Tim Shelton
|
6d27058ce0
|
updating, with suggestions
|
2022-02-11 16:12:43 +00:00 |
|
Florian Roth
|
635a5c7d41
|
fix: wrong condition
|
2022-02-11 12:47:34 +01:00 |
|
Florian Roth
|
1bf00333f7
|
fix: exclude empty OriginalName fields
|
2022-02-11 12:01:02 +01:00 |
|
Florian Roth
|
e6989f9efb
|
rules: samdumps, suspicious program names
|
2022-02-11 11:58:02 +01:00 |
|
frack113
|
6a69a06ea9
|
Merge pull request #2681 from johnpaulglab/patch-1
Update win_pc_msiexec_install_quiet.yml
|
2022-02-11 06:35:18 +01:00 |
|
johnpaulglab
|
a8f8f88c34
|
Update win_pc_msiexec_execute_dll.yml
Spelling error
|
2022-02-10 14:41:22 -06:00 |
|
johnpaulglab
|
89e98db927
|
Update win_pc_msiexec_install_quiet.yml
Spelling error
|
2022-02-10 14:38:51 -06:00 |
|
phantinuss
|
6ad44598ee
|
fix: several FPs against a fresh installed Windows with example applications and basic user interaction 2
|
2022-02-10 16:12:17 +01:00 |
|
Florian Roth
|
47d9595123
|
Merge pull request #2677 from SigmaHQ/rule-devel
refactor and new: lsass process dumping rules
|
2022-02-10 15:51:19 +01:00 |
|
Tobias Michalski
|
6af5d4b6f5
|
fix: False Positive fix
Empty field CurrentDirectory should be "or"-ed
|
2022-02-10 12:15:18 +01:00 |
|
Florian Roth
|
a05b3e50e5
|
refactor and new: lsass process dumping rules
|
2022-02-10 09:17:25 +01:00 |
|
Tim Shelton
|
330450cae6
|
fixing error
|
2022-02-10 00:01:55 +00:00 |
|
Tim Shelton
|
bc40160444
|
fixing more yaml lint complaints
|
2022-02-10 00:00:03 +00:00 |
|
Tim Shelton
|
a72f843081
|
i think the yaml is angry
|
2022-02-09 23:50:07 +00:00 |
|
Tim Shelton
|
2ce7d60729
|
splitting up filters
|
2022-02-09 23:46:07 +00:00 |
|
Florian Roth
|
11af922740
|
Update win_file_permission_modifications.yml
|
2022-02-09 23:17:32 +01:00 |
|
Florian Roth
|
0dc9234176
|
Merge pull request #2675 from redsand/fp_win_apt_bluemashroom
Adds false positive filter to win apt bluemashroom
|
2022-02-09 23:11:55 +01:00 |
|