frack113
|
39daebffa4
|
Cleanup
|
2021-08-25 20:02:38 +02:00 |
|
pbssubhash
|
3f27295e64
|
Stupid Author field
|
2021-08-25 21:47:33 +05:30 |
|
pbssubhash
|
1bb99b4ece
|
Readd
|
2021-08-25 21:44:23 +05:30 |
|
pbssubhash
|
e3331a4d0a
|
Cleanup
|
2021-08-25 21:40:32 +05:30 |
|
pbssubhash
|
25bcf1695d
|
Changed title to reduce the chars
|
2021-08-25 21:39:20 +05:30 |
|
pbssubhash
|
121c30e516
|
Changed Author to author
|
2021-08-25 21:27:59 +05:30 |
|
pbssubhash
|
d5d28cc85e
|
Merge branch 'SigmaHQ:master' into master
|
2021-08-25 21:12:14 +05:30 |
|
pbssubhash
|
5022fdc085
|
Modified Yaml
|
2021-08-25 21:11:21 +05:30 |
|
pbssubhash
|
6019871a78
|
Adding Rules - Web 2010
|
2021-08-25 20:14:36 +05:30 |
|
frack113
|
f277ecbbeb
|
Merge pull request #1923 from frack113/fix_invalid_tags
Check invalid tags
|
2021-08-25 10:26:43 +02:00 |
|
frack113
|
a6767255c0
|
Merge pull request #1922 from frack113/missing
add gworkspace_user_granted_admin_privileges.yml
|
2021-08-25 09:16:44 +02:00 |
|
frack113
|
a4021842de
|
Fix invalid tags
|
2021-08-25 09:15:57 +02:00 |
|
frack113
|
1d725e8519
|
add gworkspace_user_granted_admin_privileges.yml
|
2021-08-25 08:15:18 +02:00 |
|
frack113
|
061c093f3f
|
Merge pull request #1918 from d4rk-d4nph3/master
Added rule for Arcadyan Router Exploitations
|
2021-08-25 08:10:48 +02:00 |
|
Bhabesh Rai
|
df4180547e
|
Merged rules
|
2021-08-25 11:18:51 +05:45 |
|
Bhabesh Rai
|
a4d0e3453d
|
Fix for CVE tag
|
2021-08-25 10:24:15 +05:45 |
|
frack113
|
e849af9df0
|
Merge pull request #1915 from frack113/tags_cve
fix tags
|
2021-08-25 06:29:48 +02:00 |
|
frack113
|
7028aba3bd
|
Merge pull request #1919 from austinsonger/gworkspace-rules
Role-Based Rules
|
2021-08-24 21:46:15 +02:00 |
|
frack113
|
09a00232fb
|
update references
|
2021-08-24 21:14:59 +02:00 |
|
frack113
|
a5f858b63c
|
update references
|
2021-08-24 21:13:49 +02:00 |
|
frack113
|
962b6ac077
|
Merge pull request #1917 from austinsonger/spelling
Spelling fix
|
2021-08-24 21:06:34 +02:00 |
|
Austin Songer
|
ab8cc52dc6
|
Role-Based Rules
|
2021-08-24 10:53:59 -05:00 |
|
Bhabesh Rai
|
ce6141e318
|
Added rule for Arcadyan Router Exploitations
|
2021-08-24 21:11:46 +05:45 |
|
Austin Songer
|
62f2affd03
|
Spelling fix
|
2021-08-24 14:15:50 +00:00 |
|
Florian Roth
|
9f69cead8a
|
Merge pull request #1916 from SigmaHQ/rule-devel
refactor: changed level of rule, refactored RazerInstaller rule
|
2021-08-24 15:42:26 +02:00 |
|
Florian Roth
|
46e312ff0d
|
fix: error in modifier
|
2021-08-24 15:03:23 +02:00 |
|
Florian Roth
|
cc519552aa
|
refactor: RazorInstaller integrity level system
|
2021-08-24 14:54:07 +02:00 |
|
frack113
|
7753f8c22e
|
fix tags
|
2021-08-24 12:36:31 +02:00 |
|
Florian Roth
|
6ca30619ac
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-08-24 12:30:42 +02:00 |
|
Florian Roth
|
3cdb88ad55
|
refactor: level of suspicious parent for powershell rule
|
2021-08-24 12:30:40 +02:00 |
|
frack113
|
5b869a3f42
|
Update cve tags
|
2021-08-24 10:50:01 +02:00 |
|
frack113
|
ace46c17be
|
Update cve tags
|
2021-08-24 10:27:27 +02:00 |
|
frack113
|
c2302a15da
|
fix cve tags
|
2021-08-24 10:10:45 +02:00 |
|
frack113
|
8f85ac0fde
|
tags update
|
2021-08-24 09:35:04 +02:00 |
|
Florian Roth
|
0c69fd9c41
|
Merge pull request #1898 from SigmaHQ/rule-devel
rule: EfsPotato Named Pipe, splwow64, RazerInstaller
|
2021-08-24 09:20:54 +02:00 |
|
frack113
|
679651bdf9
|
Merge pull request #1913 from neu5ron/add_zeek_dce_rpc_printnightmare_print_driver_install
Zeek DCE_RPC PrintNightmare
|
2021-08-24 08:37:02 +02:00 |
|
frack113
|
e76c11da7f
|
Merge pull request #1908 from neu5ron/patch-7
improve rule logic zeek_default_cobalt_strike_certificate.yml
|
2021-08-24 08:36:33 +02:00 |
|
frack113
|
293f422243
|
Merge pull request #1906 from neu5ron/patch-5
improve zeek_dce_rpc_smb_spoolss_named_pipe
|
2021-08-24 08:36:18 +02:00 |
|
frack113
|
81ec546e42
|
Merge pull request #1905 from neu5ron/patch-4
improve rule
|
2021-08-24 08:36:04 +02:00 |
|
Florian Roth
|
272625a005
|
Update win_susp_splwow64.yml
|
2021-08-24 08:34:08 +02:00 |
|
frack113
|
15aa0cb70e
|
add modified
|
2021-08-24 08:02:24 +02:00 |
|
frack113
|
ade7295cab
|
Merge pull request #1911 from austinsonger/gworkspace_granted_domain_api_access.yml
gworkspace_granted_domain_api_access.yml
|
2021-08-24 08:01:34 +02:00 |
|
frack113
|
4ee4f12f30
|
add modified
|
2021-08-24 08:01:01 +02:00 |
|
frack113
|
8ab90d8012
|
add modified
|
2021-08-24 07:59:36 +02:00 |
|
frack113
|
be43ecd70d
|
Remove empty element in list
Otherwise get a `null` when convert to some backend (es-rule,...)
|
2021-08-24 07:57:16 +02:00 |
|
frack113
|
d8befe3a13
|
Update References
|
2021-08-24 07:34:33 +02:00 |
|
frack113
|
07dc04b1db
|
Merge pull request #1910 from austinsonger/gworkspace_user_assigned_admin_role.yml
gworkspace_user_assigned_admin_role.yml
|
2021-08-24 07:22:25 +02:00 |
|
frack113
|
831a473c0d
|
Merge pull request #1904 from austinsonger/365
Microsoft 365 Rules
|
2021-08-24 07:17:24 +02:00 |
|
neu5ron
|
9e588fdcf6
|
Zeek dce_rpc.log Detection of print driver installs over RPC (ie: possible PrintNightmare) using the three existing known RPC functions, as well as few others "discussed" but not directly related to PrintNightmare PoC or public post-compromise write-ups.
|
2021-08-24 00:58:36 -04:00 |
|
Austin Songer
|
facd58bd0a
|
Delete gworkspace_user_granted_admin_privileges.yml
|
2021-08-23 21:19:51 -05:00 |
|