Nasreddine Bencherchali
|
52fcb59198
|
Merge pull request #3864 from redsand/fp_manageengine_admanager
fix: fp manageengine, landesk and varonis
|
2023-01-04 10:35:32 +01:00 |
|
Nasreddine Bencherchali
|
0fe4f16dfb
|
fix: update filter based on ##3865 and #3866
|
2023-01-04 10:28:50 +01:00 |
|
Nasreddine Bencherchali
|
f5aeffa83a
|
Merge pull request #3863 from redsand/fp_aws_worker_posh_ps_susp
FP: call of window style hidden is embedded in AWS code.
|
2023-01-04 00:49:03 +01:00 |
|
Nasreddine Bencherchali
|
a737737d92
|
fix: enhance filter
|
2023-01-04 00:46:54 +01:00 |
|
Nasreddine Bencherchali
|
4d6aec82a6
|
fix: enhance fp filter
|
2023-01-04 00:43:40 +01:00 |
|
Tim Shelton
|
0c520dc930
|
FP: manage engine admanager postgres calling archive.bat
|
2023-01-03 22:04:52 +00:00 |
|
Tim Shelton
|
705782ee9b
|
FP: call of window style hidden is embedded in AWS code.
|
2023-01-03 20:52:10 +00:00 |
|
Nasreddine Bencherchali
|
3cec388841
|
Merge pull request #3861 from bobby-tablez/patch-2
Update posh_ps_susp_invocation_generic.yml
|
2023-01-03 17:54:07 +01:00 |
|
Nasreddine Bencherchali
|
d1fcf96d7d
|
fix: update modified field
|
2023-01-03 17:47:15 +01:00 |
|
Nasreddine Bencherchali
|
843506c9f0
|
fix: update modified field
|
2023-01-03 17:46:39 +01:00 |
|
Tim (Bobby-Tablez) Peck
|
0391f127c4
|
Update posh_pm_susp_invocation_generic.yml
|
2023-01-03 09:38:26 -07:00 |
|
Tim (Bobby-Tablez) Peck
|
0bf6645387
|
Update posh_ps_susp_invocation_generic.yml
|
2023-01-03 09:35:36 -07:00 |
|
Nasreddine Bencherchali
|
343e3f0934
|
Merge pull request #3859 from D3F7A5105/master
Change Evtx Location Used Wevtutil
|
2023-01-03 13:23:57 +01:00 |
|
Vadim
|
eabad66768
|
Delete proc_creation_win_change_evtx_location.yml
|
2023-01-03 15:15:52 +03:00 |
|
Vadim
|
4329b9ad49
|
Update proc_creation_win_susp_eventlog_clear.yml
|
2023-01-03 15:11:33 +03:00 |
|
Vadim
|
5dc77bad7a
|
Update rule for detects change location evtx
|
2023-01-03 15:10:54 +03:00 |
|
Nasreddine Bencherchali
|
f409a8a984
|
fix: update modified date
|
2023-01-03 10:37:09 +01:00 |
|
Vadim
|
052cd2e967
|
Update proc_creation_win_change_evtx_location.yml
|
2023-01-03 12:11:13 +03:00 |
|
Vadim
|
2075962596
|
Update proc_creation_win_change_evtx_location.yml
|
2023-01-03 11:54:30 +03:00 |
|
vadim
|
e620fcbc0b
|
Detects change location evtx used wecutil
|
2023-01-03 11:36:54 +03:00 |
|
Ali Alwashali
|
6c178639f4
|
adding WMIADAP.exe to filters
adding WMIADAP.exe to filters
|
2023-01-03 08:01:11 +03:00 |
|
Nasreddine Bencherchali
|
a6ff066baa
|
fix: unused filter
|
2023-01-03 00:32:02 +01:00 |
|
Florian Roth
|
2b04ae2e35
|
Merge branch 'master' into aurora-false-positive-fixing
|
2023-01-03 00:17:11 +01:00 |
|
Florian Roth
|
fefaa57d3c
|
fix: FPs noticed in CI testing
|
2023-01-03 00:16:32 +01:00 |
|
Nasreddine Bencherchali
|
ac631b2a6b
|
Merge pull request #3855 from frack113/more_test
More test
|
2023-01-02 21:40:40 +01:00 |
|
Nasreddine Bencherchali
|
9f2b1e081b
|
Merge pull request #3853 from D3F7A5105/master
Rules for detecting changes in the storage paths of evtx logs
|
2023-01-02 15:55:35 +01:00 |
|
frack113
|
8720356684
|
Update field name
|
2023-01-02 15:49:45 +01:00 |
|
Nasreddine Bencherchali
|
579b450d17
|
fix: add missing date
|
2023-01-02 15:26:41 +01:00 |
|
Nasreddine Bencherchali
|
6819d264cc
|
fix: update evtx tamper rules
|
2023-01-02 15:25:19 +01:00 |
|
Nasreddine Bencherchali
|
083d30c19d
|
fix: title and add python filter
|
2023-01-02 15:02:28 +01:00 |
|
Nasreddine Bencherchali
|
e23a63a60e
|
fix: typo in field name
|
2023-01-02 14:52:35 +01:00 |
|
Nasreddine Bencherchali
|
3749416a30
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2023-01-02 14:50:27 +01:00 |
|
Nasreddine Bencherchali
|
a99b5082e1
|
feat: updates and enhancements
|
2023-01-02 14:49:45 +01:00 |
|
frack113
|
b13a74adc9
|
Update from review
|
2023-01-02 12:05:54 +01:00 |
|
frack113
|
5e09d46226
|
Update rules/windows/builtin/dns_server_analytical/win_apt_gallium.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-01-02 11:56:08 +01:00 |
|
vadim
|
440706e971
|
Rules for detecting changes in the storage paths of evtx logs
|
2023-01-02 13:21:33 +03:00 |
|
frack113
|
e09850f968
|
fix field name
|
2023-01-02 11:06:57 +01:00 |
|
frack113
|
0e8d1f9b0d
|
Check field name
|
2023-01-02 10:59:51 +01:00 |
|
frack113
|
0aad498425
|
Last lolbin (#3845)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-31 19:53:44 +01:00 |
|
Nasreddine Bencherchali
|
f67cd766d0
|
Merge pull request #3846 from fukusuket/fix-invalid-regex-escape
fix: remove incorrect backslash escape(in `|re` block)
|
2022-12-31 18:35:36 +01:00 |
|
fukusuket
|
04ecbbded9
|
fix: typo modified
|
2022-12-31 21:57:05 +09:00 |
|
fukusuket
|
9298295c15
|
fix: remove invalid backslash escape
|
2022-12-31 21:35:07 +09:00 |
|
Fukusuke Takahashi
|
1ab7324ca0
|
fix: remove unneeded double backslash escape (#3844)
|
2022-12-31 08:32:46 +01:00 |
|
signalblur
|
73f56c2f0e
|
Hidden Linux Binary Execution (#3108)
Co-authored-by: Florian Roth <venom14@gmail.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-31 08:27:32 +01:00 |
|
Nasreddine Bencherchali
|
7dab38b19f
|
fix: add missing modified date
|
2022-12-30 20:56:21 +01:00 |
|
fukusuket
|
bd6243be7d
|
fix: remove unneeded backslash escape in character class.
|
2022-12-31 00:33:00 +09:00 |
|
Nasreddine Bencherchali
|
261bb8758a
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2022-12-30 11:49:08 +01:00 |
|
frack113
|
aee5ca7afc
|
Fix invalid field cast or name (#3841)
|
2022-12-30 11:46:21 +01:00 |
|
Nasreddine Bencherchali
|
d4b9df608b
|
fix: broken selection
|
2022-12-30 10:30:15 +01:00 |
|
Nasreddine Bencherchali
|
58f47b9875
|
fix: add known children appvlp
|
2022-12-30 10:24:25 +01:00 |
|