Nasreddine Bencherchali
|
2ecf9ec7e1
|
Updates
|
2022-10-04 20:57:11 +02:00 |
|
Nasreddine Bencherchali
|
7880e3a2b6
|
Fix FP
Make the FP fix more broad to cover more future cases
|
2022-09-29 22:29:47 +02:00 |
|
Nasreddine Bencherchali
|
bfc1d6a5b7
|
Create proc_creation_win_hh_chm_http.yml
|
2022-09-29 22:06:11 +02:00 |
|
Nasreddine Bencherchali
|
47dbe6081d
|
Update proc_creation_win_susp_conhost.yml
|
2022-09-29 12:15:10 +02:00 |
|
Florian Roth
|
a888ecb8b8
|
Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
|
2022-09-29 11:01:29 +02:00 |
|
Florian Roth
|
428cb6ab74
|
Merge pull request #3538 from SigmaHQ/rule-devel
fix: filter definition in userinit rule
|
2022-09-28 17:26:34 +02:00 |
|
Florian Roth
|
a563422c82
|
fix: filter definition in userinit rule
|
2022-09-28 17:08:23 +02:00 |
|
Nasreddine Bencherchali
|
4a5dcf8586
|
Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:42 +02:00 |
|
Nasreddine Bencherchali
|
69b31b19b1
|
Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:36 +02:00 |
|
Florian Roth
|
5391a5cab4
|
changed casing, increased level
|
2022-09-28 13:28:53 +02:00 |
|
Florian Roth
|
5ee44a6992
|
increased level
|
2022-09-28 13:27:23 +02:00 |
|
Nasreddine Bencherchali
|
b71644d0c8
|
New rules + small mitre update
|
2022-09-28 11:52:07 +02:00 |
|
Nasreddine Bencherchali
|
df6c167b17
|
New Rules
|
2022-09-28 10:48:51 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
d262ea2df8
|
New rules
|
2022-09-28 09:51:13 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
e987c669d0
|
Updates
|
2022-09-28 09:50:56 +02:00 |
|
frack113
|
ec6d237cd0
|
Merge pull request #3522 from frack113/redcannary_20220925
Add redcannary rules
|
2022-09-28 08:45:06 +02:00 |
|
Florian Roth
|
e583d9fc39
|
Update proc_creation_win_w32tm.yml
|
2022-09-27 23:52:22 +02:00 |
|
Florian Roth
|
58b7c910dc
|
Update proc_creation_win_w32tm.yml
|
2022-09-27 23:50:35 +02:00 |
|
securepeacock
|
e90c91668d
|
Update proc_creation_win_susp_psexesvc_as_system.yml
Typo Fixed
|
2022-09-27 13:45:53 -04:00 |
|
Qasim Qlf
|
ec657a3118
|
Merge branch 'master' into master
|
2022-09-27 16:26:22 +05:00 |
|
Florian Roth
|
e2aacfea35
|
Merge pull request #3519 from SigmaHQ/rule-devel
Rule devel
|
2022-09-27 12:05:22 +02:00 |
|
Florian Roth
|
be9fb6a6bd
|
Merge pull request #3523 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-09-27 11:10:11 +02:00 |
|
Florian Roth
|
d2f7ff8059
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-09-27 10:47:21 +02:00 |
|
Florian Roth
|
5e6a926ac3
|
fix: FPs
|
2022-09-27 10:47:19 +02:00 |
|
Florian Roth
|
43d9f3a13b
|
Merge branch 'master' into rule-devel
|
2022-09-27 10:29:03 +02:00 |
|
Qasim Qlf
|
de517ba8a2
|
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 13:21:48 +05:00 |
|
Qasim Qlf
|
600494adbc
|
Fix the filter
|
2022-09-27 13:11:08 +05:00 |
|
Florian Roth
|
408bf97181
|
Update proc_creation_win_susp_renamed_createdump.yml
|
2022-09-27 09:12:44 +02:00 |
|
Florian Roth
|
b53f08b081
|
Update proc_creation_win_process_dump_rundll32_comsvcs.yml
|
2022-09-27 09:12:06 +02:00 |
|
Florian Roth
|
9b091811dd
|
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 00:22:34 +02:00 |
|
Florian Roth
|
f9322f342c
|
Update proc_creation_win_susp_sharpview.yml
|
2022-09-27 00:22:10 +02:00 |
|
Florian Roth
|
224ea52dcd
|
Update proc_creation_win_cmstp_com_object_access.yml
|
2022-09-27 00:21:33 +02:00 |
|
Florian Roth
|
e6d7ba8224
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-09-27 00:20:07 +02:00 |
|
Florian Roth
|
0503e2b8f7
|
fix: FPs on Azure
|
2022-09-27 00:17:53 +02:00 |
|
Florian Roth
|
e1375467c5
|
fix: FPs with Azure hosts
|
2022-09-26 23:52:48 +02:00 |
|
frack113
|
9b0189b5f7
|
Add redcannary rules
|
2022-09-25 16:14:21 +02:00 |
|
frack113
|
a55749f27d
|
Merge pull request #3516 from veramine/patch-1
Update proc_creation_win_commandline_path_traversal_evasion.yml
|
2022-09-21 18:20:23 +02:00 |
|
Florian Roth
|
eeca6a898b
|
fix: mitre attack tags
|
2022-09-21 18:16:02 +02:00 |
|
Florian Roth
|
2ffca9c8da
|
fix: condition
|
2022-09-21 18:08:24 +02:00 |
|
Florian Roth
|
026844026f
|
fix: condition in sharpersist rule
|
2022-09-21 18:04:18 +02:00 |
|
Florian Roth
|
61a4a48ac0
|
fix: CommandLine field types
|
2022-09-21 18:02:42 +02:00 |
|
Florian Roth
|
8e011540b0
|
rule: createdump renamed
|
2022-09-21 16:30:47 +02:00 |
|
phantinuss
|
b7f20b884c
|
fix: FPs from new evtx-baseline
|
2022-09-21 13:51:19 +02:00 |
|
Nasreddine Bencherchali
|
4a74129048
|
Fix after review
|
2022-09-21 13:12:21 +02:00 |
|
Nasreddine Bencherchali
|
d9cd98838f
|
Add descriptions
|
2022-09-21 12:02:15 +02:00 |
|
Nasreddine Bencherchali
|
59530f49d4
|
Fix more FP in testing
|
2022-09-21 11:53:39 +02:00 |
|
Veramine
|
5fbebce703
|
Update proc_creation_win_commandline_path_traversal_evasion.yml
Removed extra space after the hyphen
|
2022-09-20 21:45:45 -07:00 |
|
Veramine
|
411d79017e
|
Update proc_creation_win_commandline_path_traversal_evasion.yml
Changed to simpler CommandLine|contains and updated modified date.
|
2022-09-20 21:33:16 -07:00 |
|
frack113
|
d8dcddea25
|
Merge pull request #3513 from gs3cl/gsec-mod
new rule for the winpeas tool
|
2022-09-21 06:20:28 +02:00 |
|
Veramine
|
fda2ca4308
|
Update proc_creation_win_commandline_path_traversal_evasion.yml
Fix FP with Citrix launcher
|
2022-09-20 17:20:19 -07:00 |
|