Commit Graph

14175 Commits

Author SHA1 Message Date
Hendrik Baecker 3da07164ce test-rules: Execute get_mitre_data() as part of unittest
Catching the data as part of the unittest class is more
IDE friendly cause they won't call __main__ but using the
test methods directly.
2023-01-04 15:58:35 +01:00
Nasreddine Bencherchali 52fcb59198 Merge pull request #3864 from redsand/fp_manageengine_admanager
fix: fp manageengine, landesk and varonis
2023-01-04 10:35:32 +01:00
Nasreddine Bencherchali 0fe4f16dfb fix: update filter based on ##3865 and #3866 2023-01-04 10:28:50 +01:00
Nasreddine Bencherchali f5aeffa83a Merge pull request #3863 from redsand/fp_aws_worker_posh_ps_susp
FP: call of window style hidden is embedded in AWS code.
2023-01-04 00:49:03 +01:00
Nasreddine Bencherchali a737737d92 fix: enhance filter 2023-01-04 00:46:54 +01:00
Nasreddine Bencherchali 4d6aec82a6 fix: enhance fp filter 2023-01-04 00:43:40 +01:00
Tim Shelton 0c520dc930 FP: manage engine admanager postgres calling archive.bat 2023-01-03 22:04:52 +00:00
Tim Shelton 705782ee9b FP: call of window style hidden is embedded in AWS code. 2023-01-03 20:52:10 +00:00
Nasreddine Bencherchali 3cec388841 Merge pull request #3861 from bobby-tablez/patch-2
Update posh_ps_susp_invocation_generic.yml
2023-01-03 17:54:07 +01:00
Nasreddine Bencherchali 20a8ecabfb Merge pull request #3862 from bobby-tablez/patch-3
Update posh_pm_susp_invocation_generic.yml
2023-01-03 17:52:30 +01:00
Nasreddine Bencherchali d1fcf96d7d fix: update modified field 2023-01-03 17:47:15 +01:00
Nasreddine Bencherchali 843506c9f0 fix: update modified field 2023-01-03 17:46:39 +01:00
Tim (Bobby-Tablez) Peck 0391f127c4 Update posh_pm_susp_invocation_generic.yml 2023-01-03 09:38:26 -07:00
Tim (Bobby-Tablez) Peck 0bf6645387 Update posh_ps_susp_invocation_generic.yml 2023-01-03 09:35:36 -07:00
Nasreddine Bencherchali 343e3f0934 Merge pull request #3859 from D3F7A5105/master
Change Evtx Location Used Wevtutil
2023-01-03 13:23:57 +01:00
Vadim eabad66768 Delete proc_creation_win_change_evtx_location.yml 2023-01-03 15:15:52 +03:00
Vadim 4329b9ad49 Update proc_creation_win_susp_eventlog_clear.yml 2023-01-03 15:11:33 +03:00
Vadim 5dc77bad7a Update rule for detects change location evtx 2023-01-03 15:10:54 +03:00
Nasreddine Bencherchali ac500a1fcf Merge pull request #3858 from alwashali/patch-1
adding WMIADAP.exe to filters
2023-01-03 10:45:40 +01:00
Nasreddine Bencherchali f409a8a984 fix: update modified date 2023-01-03 10:37:09 +01:00
Vadim f2d472e560 Change Evtx Location Used Wevtutil
Change Evtx Location Used Wevtutil
2023-01-03 12:31:44 +03:00
Vadim 052cd2e967 Update proc_creation_win_change_evtx_location.yml 2023-01-03 12:11:13 +03:00
Vadim 2075962596 Update proc_creation_win_change_evtx_location.yml 2023-01-03 11:54:30 +03:00
vadim e620fcbc0b Detects change location evtx used wecutil 2023-01-03 11:36:54 +03:00
frack113 d3dae24e9d Merge pull request #3856 from nasbench/nasbench-rule-devel
feat: add bitlocker channel
2023-01-03 06:25:30 +01:00
Ali Alwashali 6c178639f4 adding WMIADAP.exe to filters
adding WMIADAP.exe to filters
2023-01-03 08:01:11 +03:00
Nasreddine Bencherchali add1521920 Merge pull request #3857 from SigmaHQ/aurora-false-positive-fixing
fix: Nextron CI testing FPs
2023-01-03 00:37:38 +01:00
Nasreddine Bencherchali a6ff066baa fix: unused filter 2023-01-03 00:32:02 +01:00
Florian Roth 2b04ae2e35 Merge branch 'master' into aurora-false-positive-fixing 2023-01-03 00:17:11 +01:00
Florian Roth fefaa57d3c fix: FPs noticed in CI testing 2023-01-03 00:16:32 +01:00
Nasreddine Bencherchali 3bd12552bb feat: add bitlocker channel 2023-01-02 22:19:32 +01:00
Nasreddine Bencherchali ac631b2a6b Merge pull request #3855 from frack113/more_test
More test
2023-01-02 21:40:40 +01:00
Nasreddine Bencherchali 15798527e2 fix: typo in message 2023-01-02 21:33:15 +01:00
frack113 c261c1773d Update mapping 2023-01-02 19:33:24 +01:00
frack113 3527436897 Update mapping 2023-01-02 19:31:00 +01:00
frack113 c62d624892 Use W3C cs-uri-query 2023-01-02 18:56:34 +01:00
frack113 41c850e00b Use W3C cs-uri-query 2023-01-02 18:45:50 +01:00
frack113 a1a94a0b66 Update W3C field name 2023-01-02 16:39:55 +01:00
frack113 a6659bc7d8 Update W3C field name 2023-01-02 16:00:29 +01:00
frack113 99172a99e2 Update W3C field name 2023-01-02 15:56:10 +01:00
Nasreddine Bencherchali 9f2b1e081b Merge pull request #3853 from D3F7A5105/master
Rules for detecting changes in the storage paths of evtx logs
2023-01-02 15:55:35 +01:00
Nasreddine Bencherchali 241abb519e Merge pull request #3854 from nasbench/nasbench-rule-devel
feat: updates and enhancements
2023-01-02 15:51:54 +01:00
frack113 8720356684 Update field name 2023-01-02 15:49:45 +01:00
Nasreddine Bencherchali 579b450d17 fix: add missing date 2023-01-02 15:26:41 +01:00
Nasreddine Bencherchali 6819d264cc fix: update evtx tamper rules 2023-01-02 15:25:19 +01:00
Nasreddine Bencherchali 083d30c19d fix: title and add python filter 2023-01-02 15:02:28 +01:00
Nasreddine Bencherchali e23a63a60e fix: typo in field name 2023-01-02 14:52:35 +01:00
Nasreddine Bencherchali 3749416a30 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-02 14:50:27 +01:00
Nasreddine Bencherchali a99b5082e1 feat: updates and enhancements 2023-01-02 14:49:45 +01:00
Nasreddine Bencherchali b2180af63b Merge pull request #3852 from frack113/field_check
Field check
2023-01-02 12:30:29 +01:00