Commit Graph

10082 Commits

Author SHA1 Message Date
frack113 32406c1915 Issue 3552 2022-10-06 06:50:54 +02:00
frack113 b1b7428a30 Merge pull request #3560 from redsand/fp_ec2_windows
FP: ignore amazon aws ec2 scripts
2022-10-06 06:41:22 +02:00
Florian Roth adfb7d58e8 Merge pull request #3563 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG pattern
2022-10-06 00:10:32 +02:00
Florian Roth d2777f4d02 refactor: JuicyPotatoNG pattern 2022-10-06 00:00:46 +02:00
Tim Shelton f65e795e22 FP: ignore amazon aws ec2 scripts 2022-10-05 19:40:37 +00:00
Florian Roth 2391bbf96c Merge pull request #3558 from SigmaHQ/aurora-false-positive-fixing
fix: FPs with MS IPs
2022-10-05 13:00:33 +02:00
Florian Roth a029de0390 fix: FPs noticed in testing env 2022-10-05 12:22:42 +02:00
Florian Roth 50b9a3e073 fix: FPs with MS IPs 2022-10-04 19:21:41 +02:00
Florian Roth ef0e5c76a5 Merge pull request #3557 from SigmaHQ/rule-devel
fix: wrong condition in whoami rule
2022-10-04 16:23:04 +02:00
Florian Roth eee1d2c1cb fix: wrong condition in whoami rule
https://github.com/SigmaHQ/sigma/issues/3556
2022-10-04 16:11:03 +02:00
Florian Roth c42a9548c8 Merge pull request #3555 from SigmaHQ/rule-devel
refactor: add extension
2022-10-04 12:46:58 +02:00
Florian Roth 27ca37ce8f refactor: add extension 2022-10-04 12:29:48 +02:00
Florian Roth 8ed5cc10c1 Merge pull request #3554 from SigmaHQ/rule-devel
rule: suspicious file drop by Exchange
2022-10-04 12:25:51 +02:00
Florian Roth 6088654ec9 docs: added ATT&CK tags 2022-10-04 11:50:45 +02:00
Florian Roth 53aa6295c2 rule: suspicious file drop by Exchange 2022-10-04 11:45:39 +02:00
Florian Roth 029900c284 Merge pull request #3548 from aaronherman/patch-1
Update description typo on "Phishing Pattern ISO in Archive"
2022-10-03 19:55:13 +02:00
securepeacock 161c8e6c2c Update proc_creation_win_lolbins_by_office_applications.yml
Adding msidb.exe references are below.
https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
2022-10-03 11:56:06 -04:00
Florian Roth 93004a3fd5 Update proc_creation_win_archiver_iso_phishing.yml 2022-10-02 10:21:04 +02:00
Aaron Herman 580360b540 Update description typo 2022-10-01 10:52:35 -05:00
Florian Roth 626a362e8f fix: missing condition 2022-10-01 16:09:53 +02:00
Florian Roth 65f531fb30 rule: Exchange Exploitation 2022-10-01 16:08:27 +02:00
Florian Roth b568328103 Merge branch 'master' into rule-devel 2022-10-01 16:08:13 +02:00
Florian Roth cd8ed9870c fix: FPs noticed with Aurora 2022-09-30 20:01:07 +02:00
Florian Roth f84cdd3b74 fix: filter definition 2022-09-29 14:07:38 +02:00
Florian Roth 14fdf75ab5 fix: FPs noticed with THOR 2022-09-29 13:51:09 +02:00
Florian Roth 5b5c261c98 Merge branch 'master' into aurora-false-positive-fixing 2022-09-29 13:41:25 +02:00
Florian Roth c31fe50f4d fix: FPs noticed in THOR testing 2022-09-29 13:41:20 +02:00
Florian Roth d8ff3339aa antSword webshell 2022-09-29 13:31:16 +02:00
Nasreddine Bencherchali 47dbe6081d Update proc_creation_win_susp_conhost.yml 2022-09-29 12:15:10 +02:00
Nasreddine Bencherchali cdd9aff032 Fix FP 2022-09-29 11:20:08 +02:00
Florian Roth a888ecb8b8 Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
2022-09-29 11:01:29 +02:00
Florian Roth 5533d7367f Merge pull request #3539 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-09-29 11:01:13 +02:00
Florian Roth ec329f403a fix: Aurora FPs with Nvidia update 2022-09-28 19:31:22 +02:00
Florian Roth 428cb6ab74 Merge pull request #3538 from SigmaHQ/rule-devel
fix: filter definition in userinit rule
2022-09-28 17:26:34 +02:00
Florian Roth a563422c82 fix: filter definition in userinit rule 2022-09-28 17:08:23 +02:00
Nasreddine Bencherchali 4a5dcf8586 Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-09-28 13:37:42 +02:00
Nasreddine Bencherchali 69b31b19b1 Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-09-28 13:37:36 +02:00
Florian Roth 5391a5cab4 changed casing, increased level 2022-09-28 13:28:53 +02:00
Florian Roth 5ee44a6992 increased level 2022-09-28 13:27:23 +02:00
Florian Roth ea25382110 increased level 2022-09-28 13:26:23 +02:00
Nasreddine Bencherchali b71644d0c8 New rules + small mitre update 2022-09-28 11:52:07 +02:00
Nasreddine Bencherchali df6c167b17 New Rules 2022-09-28 10:48:51 +02:00
Nasreddine Bencherchali e3b3265240 Update image_load_side_load_from_non_system_location.yml 2022-09-28 10:48:30 +02:00
frack113 a9dd6f7ff0 Add registry_set_change_winevt_channelaccess (#3505) 2022-09-28 09:53:46 +02:00
nasreddine.bencherchali@nextron-systems.com d262ea2df8 New rules 2022-09-28 09:51:13 +02:00
nasreddine.bencherchali@nextron-systems.com e987c669d0 Updates 2022-09-28 09:50:56 +02:00
frack113 ec6d237cd0 Merge pull request #3522 from frack113/redcannary_20220925
Add redcannary rules
2022-09-28 08:45:06 +02:00
Florian Roth e583d9fc39 Update proc_creation_win_w32tm.yml 2022-09-27 23:52:22 +02:00
Florian Roth 58b7c910dc Update proc_creation_win_w32tm.yml 2022-09-27 23:50:35 +02:00
Florian Roth 46ef664ec6 Merge pull request #3530 from securepeacock/patch-28
Update proc_creation_win_susp_psexesvc_as_system.yml
2022-09-27 23:47:45 +02:00