Commit Graph

7343 Commits

Author SHA1 Message Date
frack113 3268a6c9b0 Fix ShareName 2022-08-11 19:19:07 +02:00
frack113 8cf1d92c84 Fix ShareName 2022-08-11 19:07:47 +02:00
Florian Roth b199e50898 Merge pull request #3358 from frack113/fix_3351
Fix condition
2022-08-11 18:24:43 +02:00
Florian Roth 3fd33a6e1f Merge pull request #3360 from martinspielmann/master
Reduced False Positives for Java Running with Remote Debugging Rule
2022-08-11 18:23:59 +02:00
Martin 41d79d4d1b Update proc_creation_win_vul_java_remote_debugging.yml
simplified rule
2022-08-11 13:29:15 +02:00
Martin 8da1502e5d Update proc_creation_win_vul_java_remote_debugging.yml
For Java Running with Remote Debugging, add filtering to vulnerable jvm versions. Later jvm versions limit remote debugging access to localhost by default.
2022-08-11 13:20:40 +02:00
phantinuss a75e9a41a2 fix: FP with office click to run 2022-08-11 09:53:25 +02:00
frack113 80df54d092 Fix condition 2022-08-11 06:59:01 +02:00
frack113 1a57509e85 Merge pull request #3346 from nasbench/nasbench-rule-devel
Updates + New Rules
2022-08-11 06:26:57 +02:00
frack113 634397e855 Merge pull request #3353 from nasbench/tune-fp-short-path-rules
Fix FP - Short Path Rules
2022-08-11 06:26:41 +02:00
frack113 4d6eda3488 Merge pull request #3348 from lawndoc/master
BloodHound Collection Files
2022-08-11 06:26:05 +02:00
Nasreddine Bencherchali f34a60b215 Update proc_creation_win_rundll32_unc_path.yml 2022-08-10 22:08:03 +01:00
Nasreddine Bencherchali f51547fe96 Update proc_creation_win_rundll32_unc_path.yml 2022-08-10 21:15:12 +01:00
Nasreddine Bencherchali 3201b68004 Final update 2022-08-10 18:33:17 +01:00
Nasreddine Bencherchali 0f8ad22b9a Update proc_creation_win_susp_wmic_proc_create.yml 2022-08-10 17:53:09 +01:00
Nasreddine Bencherchali 021c297e96 Update title and description 2022-08-10 17:48:48 +01:00
Nasreddine Bencherchali 80ee1192e6 Update file_event_win_error_handler_cmd_persistence.yml 2022-08-10 17:45:25 +01:00
phantinuss 6d1dad51fe fix: typo in filter name 2022-08-10 18:09:55 +02:00
phantinuss b0f07faa85 fix: FP with poqexec.exe 2022-08-10 17:28:03 +02:00
phantinuss 7b9cd0e74c fix: remove TargetObject restriction bc of too many FPs 2022-08-10 17:28:02 +02:00
phantinuss 5cde4a2d7e fix: FP with Avast 2022-08-10 17:28:02 +02:00
Nasreddine Bencherchali babdecc642 Update proc_creation_win_ntfs_short_name_use_image.yml 2022-08-10 15:25:10 +01:00
Nasreddine Bencherchali 14277c5b6d Fix FP 2022-08-10 15:15:49 +01:00
Florian Roth c2b415601e Merge pull request #3344 from phantinuss/master
fix: FP found in testing
2022-08-10 14:04:37 +02:00
Nasreddine Bencherchali 405ed7e6d2 Update file_event_win_error_handler_cmd_persistence.yml 2022-08-10 13:02:08 +01:00
phantinuss 8e63a4b2e1 fix: another Win7 i386 path 2022-08-10 13:54:19 +02:00
Nasreddine Bencherchali b5c15c5137 More additions and updates 2022-08-10 12:52:49 +01:00
phantinuss 342ec1c9cc fix: FP with wrongly matching folders 2022-08-10 11:23:42 +02:00
frack113 d666a18615 Fix issue 3342 2022-08-10 07:52:50 +02:00
frack113 519e4a8f47 Fix issue 3339 2022-08-10 07:44:56 +02:00
C.J. May d1b123c16a removed slashes from strings 2022-08-09 17:56:28 -05:00
C.J. May 402882c764 Create file_event_bloodhound_collection.yml 2022-08-09 17:49:06 -05:00
Nasreddine Bencherchali b7e5e128c7 Update proc_creation_win_disable_service.yml 2022-08-09 18:42:39 +01:00
Nasreddine Bencherchali b905df6bc7 Updates + New Rules 2022-08-09 18:35:45 +01:00
phantinuss df4b8eadbf fix: FP in testing 2022-08-09 18:34:53 +02:00
phantinuss bfeb23e622 fix: FP found in testing 2022-08-09 17:53:48 +02:00
phantinuss 68a768f829 Merge pull request #3335 from nasbench/nasbench-rule-devel
Update Ntfs Short Name rule
2022-08-09 17:53:05 +02:00
Nasreddine Bencherchali f5d0753167 Add extensions 2022-08-09 16:05:36 +01:00
phantinuss bde259619e Merge pull request #3333 from frack113/short_path
Use short name path
2022-08-09 16:49:23 +02:00
phantinuss 84e234575e Merge pull request #3341 from phantinuss/master
fix: use wildcard * instead of plaintext *
2022-08-09 11:10:03 +02:00
phantinuss 7ff91656ed fix: remove duplicate filter 2022-08-09 10:56:58 +02:00
phantinuss 43ac43c70d fix: FP found in testing 2022-08-09 10:56:00 +02:00
phantinuss a90ba27a1c fix: do not use wildcard, where not needed 2022-08-09 10:55:05 +02:00
frack113 dcfc0b4095 Merge pull request #3336 from frack113/DbgManagedDebugger
Add registry_set_dbgmanageddebugger_persistence.yml
2022-08-08 18:49:47 +02:00
phantinuss ef1f2b13ec fix: use wildcard * instead of plaintext *
the changed files seem like they used an esacped * by mistake
2022-08-08 17:54:46 +02:00
phantinuss eaa0f339ac fix: remove TargetObject, too many occurences in testing 2022-08-08 13:57:32 +02:00
frack113 39fa020092 Add registry_set_dbgmanageddebugger_persistence.yml 2022-08-07 10:30:30 +02:00
frack113 f1eba85780 Add short name path 2022-08-07 08:37:58 +02:00
Nasreddine Bencherchali be896d1013 rename rule 2022-08-06 18:43:59 +01:00
Nasreddine Bencherchali 3388b675ac Create proc_creation_win_ntfs_short_name_use_image.yml 2022-08-06 18:43:33 +01:00