frack113
3268a6c9b0
Fix ShareName
2022-08-11 19:19:07 +02:00
frack113
8cf1d92c84
Fix ShareName
2022-08-11 19:07:47 +02:00
Florian Roth
b199e50898
Merge pull request #3358 from frack113/fix_3351
...
Fix condition
2022-08-11 18:24:43 +02:00
Florian Roth
3fd33a6e1f
Merge pull request #3360 from martinspielmann/master
...
Reduced False Positives for Java Running with Remote Debugging Rule
2022-08-11 18:23:59 +02:00
Martin
41d79d4d1b
Update proc_creation_win_vul_java_remote_debugging.yml
...
simplified rule
2022-08-11 13:29:15 +02:00
Martin
8da1502e5d
Update proc_creation_win_vul_java_remote_debugging.yml
...
For Java Running with Remote Debugging, add filtering to vulnerable jvm versions. Later jvm versions limit remote debugging access to localhost by default.
2022-08-11 13:20:40 +02:00
phantinuss
a75e9a41a2
fix: FP with office click to run
2022-08-11 09:53:25 +02:00
frack113
80df54d092
Fix condition
2022-08-11 06:59:01 +02:00
frack113
1a57509e85
Merge pull request #3346 from nasbench/nasbench-rule-devel
...
Updates + New Rules
2022-08-11 06:26:57 +02:00
frack113
634397e855
Merge pull request #3353 from nasbench/tune-fp-short-path-rules
...
Fix FP - Short Path Rules
2022-08-11 06:26:41 +02:00
frack113
4d6eda3488
Merge pull request #3348 from lawndoc/master
...
BloodHound Collection Files
2022-08-11 06:26:05 +02:00
Nasreddine Bencherchali
f34a60b215
Update proc_creation_win_rundll32_unc_path.yml
2022-08-10 22:08:03 +01:00
Nasreddine Bencherchali
f51547fe96
Update proc_creation_win_rundll32_unc_path.yml
2022-08-10 21:15:12 +01:00
Nasreddine Bencherchali
3201b68004
Final update
2022-08-10 18:33:17 +01:00
Nasreddine Bencherchali
0f8ad22b9a
Update proc_creation_win_susp_wmic_proc_create.yml
2022-08-10 17:53:09 +01:00
Nasreddine Bencherchali
021c297e96
Update title and description
2022-08-10 17:48:48 +01:00
Nasreddine Bencherchali
80ee1192e6
Update file_event_win_error_handler_cmd_persistence.yml
2022-08-10 17:45:25 +01:00
phantinuss
6d1dad51fe
fix: typo in filter name
2022-08-10 18:09:55 +02:00
phantinuss
b0f07faa85
fix: FP with poqexec.exe
2022-08-10 17:28:03 +02:00
phantinuss
7b9cd0e74c
fix: remove TargetObject restriction bc of too many FPs
2022-08-10 17:28:02 +02:00
phantinuss
5cde4a2d7e
fix: FP with Avast
2022-08-10 17:28:02 +02:00
Nasreddine Bencherchali
babdecc642
Update proc_creation_win_ntfs_short_name_use_image.yml
2022-08-10 15:25:10 +01:00
Nasreddine Bencherchali
14277c5b6d
Fix FP
2022-08-10 15:15:49 +01:00
Florian Roth
c2b415601e
Merge pull request #3344 from phantinuss/master
...
fix: FP found in testing
2022-08-10 14:04:37 +02:00
Nasreddine Bencherchali
405ed7e6d2
Update file_event_win_error_handler_cmd_persistence.yml
2022-08-10 13:02:08 +01:00
phantinuss
8e63a4b2e1
fix: another Win7 i386 path
2022-08-10 13:54:19 +02:00
Nasreddine Bencherchali
b5c15c5137
More additions and updates
2022-08-10 12:52:49 +01:00
phantinuss
342ec1c9cc
fix: FP with wrongly matching folders
2022-08-10 11:23:42 +02:00
frack113
d666a18615
Fix issue 3342
2022-08-10 07:52:50 +02:00
frack113
519e4a8f47
Fix issue 3339
2022-08-10 07:44:56 +02:00
C.J. May
d1b123c16a
removed slashes from strings
2022-08-09 17:56:28 -05:00
C.J. May
402882c764
Create file_event_bloodhound_collection.yml
2022-08-09 17:49:06 -05:00
Nasreddine Bencherchali
b7e5e128c7
Update proc_creation_win_disable_service.yml
2022-08-09 18:42:39 +01:00
Nasreddine Bencherchali
b905df6bc7
Updates + New Rules
2022-08-09 18:35:45 +01:00
phantinuss
df4b8eadbf
fix: FP in testing
2022-08-09 18:34:53 +02:00
phantinuss
bfeb23e622
fix: FP found in testing
2022-08-09 17:53:48 +02:00
phantinuss
68a768f829
Merge pull request #3335 from nasbench/nasbench-rule-devel
...
Update Ntfs Short Name rule
2022-08-09 17:53:05 +02:00
Nasreddine Bencherchali
f5d0753167
Add extensions
2022-08-09 16:05:36 +01:00
phantinuss
bde259619e
Merge pull request #3333 from frack113/short_path
...
Use short name path
2022-08-09 16:49:23 +02:00
phantinuss
84e234575e
Merge pull request #3341 from phantinuss/master
...
fix: use wildcard * instead of plaintext *
2022-08-09 11:10:03 +02:00
phantinuss
7ff91656ed
fix: remove duplicate filter
2022-08-09 10:56:58 +02:00
phantinuss
43ac43c70d
fix: FP found in testing
2022-08-09 10:56:00 +02:00
phantinuss
a90ba27a1c
fix: do not use wildcard, where not needed
2022-08-09 10:55:05 +02:00
frack113
dcfc0b4095
Merge pull request #3336 from frack113/DbgManagedDebugger
...
Add registry_set_dbgmanageddebugger_persistence.yml
2022-08-08 18:49:47 +02:00
phantinuss
ef1f2b13ec
fix: use wildcard * instead of plaintext *
...
the changed files seem like they used an esacped * by mistake
2022-08-08 17:54:46 +02:00
phantinuss
eaa0f339ac
fix: remove TargetObject, too many occurences in testing
2022-08-08 13:57:32 +02:00
frack113
39fa020092
Add registry_set_dbgmanageddebugger_persistence.yml
2022-08-07 10:30:30 +02:00
frack113
f1eba85780
Add short name path
2022-08-07 08:37:58 +02:00
Nasreddine Bencherchali
be896d1013
rename rule
2022-08-06 18:43:59 +01:00
Nasreddine Bencherchali
3388b675ac
Create proc_creation_win_ntfs_short_name_use_image.yml
2022-08-06 18:43:33 +01:00