frack113
|
32406c1915
|
Issue 3552
|
2022-10-06 06:50:54 +02:00 |
|
frack113
|
85d33e4af9
|
Merge pull request #3525 from vastlimits/feature/ame-7.0
Updated uberAgent backend to support version 7.0.
|
2022-10-06 06:42:57 +02:00 |
|
frack113
|
b1b7428a30
|
Merge pull request #3560 from redsand/fp_ec2_windows
FP: ignore amazon aws ec2 scripts
|
2022-10-06 06:41:22 +02:00 |
|
frack113
|
e9ed7d05e1
|
Merge pull request #3561 from redsand/backend_hawk_cfg_update
BACKEND: updating production config
|
2022-10-06 06:40:17 +02:00 |
|
Florian Roth
|
adfb7d58e8
|
Merge pull request #3563 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG pattern
|
2022-10-06 00:10:32 +02:00 |
|
Florian Roth
|
d2777f4d02
|
refactor: JuicyPotatoNG pattern
|
2022-10-06 00:00:46 +02:00 |
|
Tim Shelton
|
febeadfb4c
|
BACKEND: updating production config
|
2022-10-05 19:43:39 +00:00 |
|
Tim Shelton
|
f65e795e22
|
FP: ignore amazon aws ec2 scripts
|
2022-10-05 19:40:37 +00:00 |
|
Florian Roth
|
2391bbf96c
|
Merge pull request #3558 from SigmaHQ/aurora-false-positive-fixing
fix: FPs with MS IPs
|
2022-10-05 13:00:33 +02:00 |
|
Florian Roth
|
a029de0390
|
fix: FPs noticed in testing env
|
2022-10-05 12:22:42 +02:00 |
|
Florian Roth
|
50b9a3e073
|
fix: FPs with MS IPs
|
2022-10-04 19:21:41 +02:00 |
|
Florian Roth
|
ef0e5c76a5
|
Merge pull request #3557 from SigmaHQ/rule-devel
fix: wrong condition in whoami rule
|
2022-10-04 16:23:04 +02:00 |
|
Florian Roth
|
eee1d2c1cb
|
fix: wrong condition in whoami rule
https://github.com/SigmaHQ/sigma/issues/3556
|
2022-10-04 16:11:03 +02:00 |
|
Florian Roth
|
c42a9548c8
|
Merge pull request #3555 from SigmaHQ/rule-devel
refactor: add extension
|
2022-10-04 12:46:58 +02:00 |
|
Florian Roth
|
27ca37ce8f
|
refactor: add extension
|
2022-10-04 12:29:48 +02:00 |
|
Florian Roth
|
8ed5cc10c1
|
Merge pull request #3554 from SigmaHQ/rule-devel
rule: suspicious file drop by Exchange
|
2022-10-04 12:25:51 +02:00 |
|
Florian Roth
|
6088654ec9
|
docs: added ATT&CK tags
|
2022-10-04 11:50:45 +02:00 |
|
Florian Roth
|
53aa6295c2
|
rule: suspicious file drop by Exchange
|
2022-10-04 11:45:39 +02:00 |
|
Florian Roth
|
029900c284
|
Merge pull request #3548 from aaronherman/patch-1
Update description typo on "Phishing Pattern ISO in Archive"
|
2022-10-03 19:55:13 +02:00 |
|
Florian Roth
|
fe6c4cac9b
|
Merge pull request #3553 from securepeacock/patch-29
Update proc_creation_win_lolbins_by_office_applications.yml
|
2022-10-03 19:54:52 +02:00 |
|
securepeacock
|
161c8e6c2c
|
Update proc_creation_win_lolbins_by_office_applications.yml
Adding msidb.exe references are below.
https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
|
2022-10-03 11:56:06 -04:00 |
|
Thomas Patzke
|
5703e04e3a
|
Merge pull request #3537 from mpgn/master
Update datadog sigmac
|
2022-10-03 14:16:49 +02:00 |
|
Florian Roth
|
93004a3fd5
|
Update proc_creation_win_archiver_iso_phishing.yml
|
2022-10-02 10:21:04 +02:00 |
|
Florian Roth
|
abfcf34d5c
|
Merge pull request #3550 from aaronherman/patch-2
Update README for rule usage section
|
2022-10-01 20:17:17 +02:00 |
|
Florian Roth
|
0612aec224
|
Update README.md
|
2022-10-01 20:10:41 +02:00 |
|
Aaron Herman
|
97fab49d09
|
Update README for rule usage section
Based on line 3 where it mentions being inside of `./tools` directory, updating line 4 to include working example that I used
|
2022-10-01 12:03:11 -05:00 |
|
Aaron Herman
|
580360b540
|
Update description typo
|
2022-10-01 10:52:35 -05:00 |
|
Florian Roth
|
3ae076f08d
|
Merge pull request #3547 from SigmaHQ/rule-devel
rules: Exchange exploitation, antSword UA
|
2022-10-01 16:16:29 +02:00 |
|
Florian Roth
|
626a362e8f
|
fix: missing condition
|
2022-10-01 16:09:53 +02:00 |
|
Florian Roth
|
65f531fb30
|
rule: Exchange Exploitation
|
2022-10-01 16:08:27 +02:00 |
|
Florian Roth
|
b568328103
|
Merge branch 'master' into rule-devel
|
2022-10-01 16:08:13 +02:00 |
|
Florian Roth
|
76276f5bcb
|
Merge pull request #3546 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
|
2022-09-30 20:12:04 +02:00 |
|
Florian Roth
|
cd8ed9870c
|
fix: FPs noticed with Aurora
|
2022-09-30 20:01:07 +02:00 |
|
Florian Roth
|
8341d505c4
|
Merge pull request #3543 from SigmaHQ/aurora-false-positive-fixing
THOR false positive fixing
|
2022-09-29 14:45:22 +02:00 |
|
Florian Roth
|
f84cdd3b74
|
fix: filter definition
|
2022-09-29 14:07:38 +02:00 |
|
Florian Roth
|
14fdf75ab5
|
fix: FPs noticed with THOR
|
2022-09-29 13:51:09 +02:00 |
|
Florian Roth
|
5b5c261c98
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-09-29 13:41:25 +02:00 |
|
Florian Roth
|
c31fe50f4d
|
fix: FPs noticed in THOR testing
|
2022-09-29 13:41:20 +02:00 |
|
Florian Roth
|
d8ff3339aa
|
antSword webshell
|
2022-09-29 13:31:16 +02:00 |
|
Florian Roth
|
5e1b91a616
|
Merge pull request #3542 from nasbench/fix-false-positives
Fix False Positives
|
2022-09-29 12:54:29 +02:00 |
|
Nasreddine Bencherchali
|
47dbe6081d
|
Update proc_creation_win_susp_conhost.yml
|
2022-09-29 12:15:10 +02:00 |
|
Nasreddine Bencherchali
|
cdd9aff032
|
Fix FP
|
2022-09-29 11:20:08 +02:00 |
|
Nasreddine Bencherchali
|
e6d0f35c82
|
Merge branch 'SigmaHQ:master' into fix-false-positives
|
2022-09-29 11:16:56 +02:00 |
|
Nasreddine Bencherchali
|
6131c3df88
|
Revert "fix fp from testing"
This reverts commit 94ec3126f7.
|
2022-09-29 11:16:42 +02:00 |
|
Nasreddine Bencherchali
|
94ec3126f7
|
fix fp from testing
|
2022-09-29 11:15:10 +02:00 |
|
Florian Roth
|
a888ecb8b8
|
Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
|
2022-09-29 11:01:29 +02:00 |
|
Florian Roth
|
5533d7367f
|
Merge pull request #3539 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-09-29 11:01:13 +02:00 |
|
Florian Roth
|
ec329f403a
|
fix: Aurora FPs with Nvidia update
|
2022-09-28 19:31:22 +02:00 |
|
Florian Roth
|
428cb6ab74
|
Merge pull request #3538 from SigmaHQ/rule-devel
fix: filter definition in userinit rule
|
2022-09-28 17:26:34 +02:00 |
|
Florian Roth
|
a563422c82
|
fix: filter definition in userinit rule
|
2022-09-28 17:08:23 +02:00 |
|