Florian Roth
|
6aed1a0d2a
|
fix: FPs noticed with Aurora
|
2021-12-02 14:57:06 +01:00 |
|
Florian Roth
|
4a136fdce6
|
simplified condition
|
2021-12-01 14:06:09 +01:00 |
|
Florian Roth
|
f2199eacad
|
fix: FPs noticed with Aurora
|
2021-12-01 13:39:53 +01:00 |
|
Florian Roth
|
6d155ad2ce
|
fix: simplified and extended rule
|
2021-11-30 20:12:07 +01:00 |
|
Florian Roth
|
9b235f6873
|
fix: Granted Access 0x410 in different rules
|
2021-11-30 19:20:37 +01:00 |
|
Florian Roth
|
e89646a696
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2021-11-30 19:15:20 +01:00 |
|
Florian Roth
|
112c3522d8
|
fix: FPs noticed with Aurora
|
2021-11-30 19:14:49 +01:00 |
|
Florian Roth
|
9209051f94
|
fix: FPs noticed with Aurora
|
2021-11-29 18:25:34 +01:00 |
|
Florian Roth
|
b8985a222f
|
fix: FPs noticed with Aurora
|
2021-11-29 16:13:24 +01:00 |
|
Florian Roth
|
dcf9d8c828
|
fix: FPs noticed with Aurora
|
2021-11-29 15:38:43 +01:00 |
|
Florian Roth
|
17d6528f41
|
Merge branch 'master' into aurora-false-positive-fixing
|
2021-11-29 13:09:38 +01:00 |
|
Florian Roth
|
820cc0ccf8
|
Merge branch 'master' into rule-devel
|
2021-11-29 11:00:25 +01:00 |
|
Florian Roth
|
ef7810fa8b
|
fix: fixing issues with wildcard symbol
https://github.com/SigmaHQ/sigma/issues/2339
|
2021-11-29 10:57:01 +01:00 |
|
Florian Roth
|
142437d9dc
|
fix: FPs noticed with Aurora
|
2021-11-28 14:57:54 +01:00 |
|
Florian Roth
|
e41c195ca5
|
Merge pull request #2335 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2021-11-28 10:03:48 +01:00 |
|
Florian Roth
|
19aa434cbd
|
fix: update modified date
|
2021-11-28 01:17:09 +01:00 |
|
Florian Roth
|
8f22165f26
|
fix: FPs noticed with Aurora
|
2021-11-28 01:16:18 +01:00 |
|
Florian Roth
|
330fcf485c
|
Merge branch 'master' into promote_status
|
2021-11-27 17:15:56 +01:00 |
|
Florian Roth
|
227d99ff58
|
Merge pull request #2333 from SigmaHQ/rule-devel
Suspicious LSASS Process Clone
|
2021-11-27 14:42:14 +01:00 |
|
Florian Roth
|
bd772975f7
|
rule: LSASS access from program in suspicious folder
|
2021-11-27 14:09:11 +01:00 |
|
Florian Roth
|
1f6fa6dd58
|
rule: ATPMiniDump extensions
|
2021-11-27 14:02:42 +01:00 |
|
Florian Roth
|
2844e58369
|
fix: FPs noticed with Aurora
|
2021-11-27 11:52:48 +01:00 |
|
frack113
|
01dc930c17
|
Change status for old rules
|
2021-11-27 11:33:14 +01:00 |
|
Florian Roth
|
97207bdf81
|
Merge branch 'master' into aurora-false-positive-fixing
|
2021-11-27 09:22:15 +01:00 |
|
Florian Roth
|
0ad9f9a859
|
fix: FPs noticed with Aurora
|
2021-11-27 09:13:53 +01:00 |
|
Florian Roth
|
11b8ccfe8f
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-11-26 20:47:22 +01:00 |
|
Florian Roth
|
eae38d08f0
|
fix: FPs
|
2021-11-26 20:46:52 +01:00 |
|
Florian Roth
|
1702c057c6
|
Merge branch 'master' into rule-devel
|
2021-11-26 20:02:40 +01:00 |
|
Florian Roth
|
03cddbba29
|
fix: FPs
|
2021-11-26 20:00:55 +01:00 |
|
Florian Roth
|
f60e8e5d17
|
fix: more false positive filters
|
2021-11-24 16:58:53 +01:00 |
|
Florian Roth
|
f2585f44da
|
fix: bug in filter
|
2021-11-22 21:30:19 +01:00 |
|
Florian Roth
|
7468d495ff
|
fix: FP with LSASS access rule
|
2021-11-22 21:29:21 +01:00 |
|
Florian Roth
|
8fc93d3340
|
refactor: generic lsass access filter
|
2021-11-22 15:05:56 +01:00 |
|
Florian Roth
|
ff6bb3acea
|
extended filters and descriptions
|
2021-11-22 14:01:30 +01:00 |
|
Florian Roth
|
37ff832fda
|
fix: FPs with LSASS access rule
|
2021-11-22 13:43:20 +01:00 |
|
Florian Roth
|
cda13acc83
|
Revert "refactor: add another flag set"
This reverts commit ca62fe586f.
|
2021-11-22 12:51:16 +01:00 |
|
Florian Roth
|
ca62fe586f
|
refactor: add another flag set
|
2021-11-22 12:21:19 +01:00 |
|
Florian Roth
|
a5b7a92d91
|
fix: FPs with Aurora
|
2021-11-22 12:20:21 +01:00 |
|
Florian Roth
|
d3ec743906
|
fix: changed modified date
|
2021-11-22 11:38:37 +01:00 |
|
Florian Roth
|
fbd8df5768
|
rule: lsass access suspicious flags
|
2021-11-22 11:37:09 +01:00 |
|
Florian Roth
|
7432aa37a0
|
refactor: lsass query info access
|
2021-11-22 11:02:01 +01:00 |
|
Florian Roth
|
e73816bb22
|
fix: too many false positives with in-memory detection rule
|
2021-11-20 15:07:20 +01:00 |
|
Florian Roth
|
15a4938294
|
fix: wrong condition
|
2021-11-20 15:05:06 +01:00 |
|
Florian Roth
|
f1d2903ec2
|
fix: FPs with rules
|
2021-11-20 12:32:15 +01:00 |
|
Florian Roth
|
6c040f0844
|
fix: more false positives
|
2021-11-20 12:00:18 +01:00 |
|
Florian Roth
|
1fffb57df0
|
fix: FPs with different rules
|
2021-11-20 11:33:43 +01:00 |
|
frack113
|
1cfca93354
|
Missing status in rules (#2284)
* add missing status
|
2021-11-19 22:32:26 +01:00 |
|
Florian Roth
|
7d4e3fd2ed
|
fix: more false positive fixes
|
2021-11-16 23:27:00 +01:00 |
|
Florian Roth
|
8d6d8c2c92
|
fix: several FPs
|
2021-11-16 17:30:23 +01:00 |
|
frack113
|
b267504708
|
Merge pull request #2179 from frack113/fix_sysmon_in_memory_assembly_execution
Fix sysmon in memory assembly execution
|
2021-10-23 10:11:08 +02:00 |
|