Commit Graph

187 Commits

Author SHA1 Message Date
frack113 2cfa9a2d1f Merge PR #4847 from @frack113 - Update test Workflow to use pySigma-validators-sigmahq
chore: update workflow to use "pySigma-validators-sigmahq"
2024-05-10 10:32:54 +02:00
Hongbo 9e6952ec6a Merge PR #4789 from @ya0guang - Fix typo in test_rules.py
chore: fix typo in `test_rules.py` condition
2024-04-15 16:58:02 +02:00
Hongbo a235795ddd Merge PR #4790 from @ya0guang - Update test_rules.py
chore: fix typo in `test_rules.py`
2024-04-15 16:56:41 +02:00
jstnk9 3bb3b9cb5b Merge PR #4615 from @jstnk9 - Update WMIC Discovery Rule + New System Discovery Rules For MacOS
new: System Information Discovery Using Ioreg
new: System Information Discovery Using sw_vers
new: Potential Base64 Decoded From Images
new: System Information Discovery Via Wmic.EXE
update: Uncommon System Information Discovery Via Wmic.EXE - Updated logic to focus on more specific WMIC query sequence to increase the level and added a related rule to cover the missing gaps in d85ecdd7-b855-4e6e-af59-d9c78b5b861e
---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-12-21 11:09:47 +01:00
frack113 3990060d02 Merge PR #4609 from @frack113 - Add More PySigma Validators
chore: Add more pySigma Validator
2023-12-01 15:11:24 +01:00
Nasreddine Bencherchali 1559c9d95c Merge PR #4583 from @nasbench - Add CVE-2023-4966 Related Rules
new: CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
new: CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
new: CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
new: CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-11-28 15:54:33 +01:00
frack113 56ac238027 Merge PR #4591 from @frack113 - Update tests to pySigma 0.10.9
chore: update tests to pySigma 0.10.9
chore: add Summiting the Pyramid v1.0.0 tags

---------

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-11-27 09:08:01 +01:00
frack113 2d63859aed Merge PR #4574 from @frack113 - ci: 🤖 add new sigma-cli 0.7.10 validators
chore: Add new validators from sigma-cli 0.7.10 and remove obsolete tests in test_rules.py

---------

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-11-17 16:46:50 +01:00
frack113 d577872761 Merge PR #4551 from @frack113 - chore: move more tests to pySigma
chore: Add attacktag and tlptag to pySigma tests
---------

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-11-15 16:40:33 +01:00
frack113 f6eca9a262 Merge PR #4541 from @frack113 - Update SIGMA tests
chore: remove duplicate tests that already covered by pysigma validation
2023-11-06 13:06:55 +01:00
Nasreddine Bencherchali edf0ff5cc8 Merge PR #4491 from @nasbench - Rule Updates & Fixes
new: Lazarus APT DLL Sideloading Activity
new: File Download From IP Based URL Via CertOC.EXE
new: File Download From IP URL Via Curl.EXE
update: Remote Thread Creation By Uncommon Source Image
update: Remote Thread Creation In Uncommon Target Image
update: ADSI-Cache File Creation By Uncommon Tool
update: Files With System Process Name In Unsuspected Locations
update: PowerShell Module File Created By Non-PowerShell Process
update: PSScriptPolicyTest Creation By Uncommon Process
update: Suspicious LNK Double Extension File Created
update: PowerShell Profile Modification
update: Alternate PowerShell Hosts Pipe
update: File Download via CertOC.EXE
update: Suspicious File Download From IP Via Curl.EXE
update: Arbitrary File Download Via GfxDownloadWrapper.EXE
update: Potentially Suspicious Office Document Executed From Trusted Location

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-10-23 10:35:57 +02:00
Nasreddine Bencherchali 7364ce00b1 Merge PR #4476 from @nasbench - re-organize cloud folder and other things
fix: Azure Active Directory Hybrid Health AD FS New Server - Update Logsource to align with the rest of the azure rules
fix: Azure Active Directory Hybrid Health AD FS Service Delete - Update Logsource to align with the rest of the azure rules
fix: Number Of Resource Creation Or Deployment Activities - Update Logsource to align with the rest of the azure rules
fix: Granting Of Permissions To An Account - Update Logsource to align with the rest of the azure rules
fix: Rare Subscription-level Operations In Azure - Update Logsource to align with the rest of the azure rules
fix: Google Workspace Application Removed - Update logsource product field to `gcp`
fix: Google Workspace Granted Domain API Access - Update logsource product field to `gcp`
fix: Google Workspace MFA Disabled - Update logsource product field to `gcp`
fix: Google Workspace Role Modified or Deleted - Update logsource product field to `gcp`
fix: Google Workspace Role Privilege Deleted - Update logsource product field to `gcp`
fix: Google Workspace User Granted Admin Privileges - Update logsource product field to `gcp`
2023-10-12 13:32:24 +02:00
Mark Morowczynski f28b89c084 Merge PR #4445 from @MarkMorow - New Azure PIM Rules
new: Stale Accounts In A Privileged Role
new: Invalid PIM License
new: Roles Assigned Outside PIM
new: Roles Activated Too Frequently
new: Roles Activation Doesn't Require MFA
new: Roles Are Not Being Used
new: Too Many Global Admins

---------

Co-authored-by: gleeiamglo <142270304+gleeiamglo@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-09-14 22:02:30 +02:00
Nasreddine Bencherchali 9f82e581a1 fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-06-20 11:26:41 +02:00
frack113 8c5dba3740 Update tags
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-06-20 07:31:54 +02:00
Nasreddine Bencherchali 098746574c feat: add typo check for related field 2023-06-07 12:29:02 +02:00
Nasreddine Bencherchali 1299b21561 feat: rule and tests update 2023-05-31 13:46:13 +02:00
Nasreddine Bencherchali de9f3a3521 feat: update logsource and rule
- Add 2 new event log
  - Microsoft-Windows-CAPI2/Operational
  - Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational
- Update required tests and rules
2023-05-19 00:05:05 +02:00
Nasreddine Bencherchali e51b548938 fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-05-12 10:33:05 +02:00
Nasreddine Bencherchali cab7dcc9f4 fix: unused selection and increase filename size 2023-05-11 20:51:33 +02:00
phantinuss e6d734e7fc chore: use relative paths for rules test again 2023-04-26 13:22:01 +02:00
Nasreddine Bencherchali 1ed9743e7c fix: test issues 2023-04-25 19:18:38 +02:00
Nasreddine Bencherchali 16d4d0b6ea Update test_rules.py 2023-04-25 18:59:24 +02:00
phantinuss 1d6ad79f06 fix: adding executable bit 2023-04-24 08:41:56 +02:00
Nasreddine Bencherchali 7f88625c3c feat: update tests for new folder struct 2023-04-21 15:01:47 +02:00
Nasreddine Bencherchali d591bf662a fix: update tests 2023-04-21 15:01:47 +02:00
Nasreddine Bencherchali 9890de995a feat: update tests for new folder struct 2023-04-21 15:00:37 +02:00
Nasreddine Bencherchali f4e406c1b6 fix: update tests 2023-04-21 15:00:37 +02:00
Tess 0ade5feae9 add test for duplicate references 2023-04-20 10:45:51 -04:00
Nick Moore 463d9fff82 feat: new rule Potential Okta Password in AlternateID Field (#4158) 2023-04-05 13:21:03 +02:00
Thomas Patzke 0e8e5a0bd5 Restored thor.yml and fixed reference to it 2023-04-02 01:22:10 +02:00
Nasreddine Bencherchali 2883c2e714 fix: test errors 2023-03-07 14:23:44 +01:00
Nasreddine Bencherchali 05adb156e7 feat: update test 2023-03-07 14:14:21 +01:00
Nasreddine Bencherchali f0afc4cce6 fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-02-20 12:06:37 +01:00
Nasreddine Bencherchali 6a0b38291f fix: fp found in baseline 2023-02-17 23:16:42 +01:00
Nasreddine Bencherchali 82d0b9e10c fix: add missing modified and improve test 2023-02-10 00:56:07 +01:00
Thomas Patzke ef9d4f702d Merge pull request #3878 from DCSO/rule_test_add_re_escape_tests
Test: Check 're' rules against unwanted/unneeded escapes
2023-02-04 08:59:16 +01:00
Nasreddine Bencherchali f2643c6043 Merge pull request #3940 from mbabinski/master
feat: add external remote service logon from public IP rule.
2023-01-31 11:04:50 +01:00
Nasreddine Bencherchali 2817c6085c feat: add cidr modifier to the test 2023-01-31 10:58:29 +01:00
Nasreddine Bencherchali 6de8009c88 fix: update metadata and prefix test 2023-01-30 10:23:13 +01:00
Nasreddine Bencherchali 8b38e3ac2c fix: assertion logic 2023-01-12 12:36:33 +01:00
Nasreddine Bencherchali dca48fc125 fix: assert function in test 2023-01-12 12:29:38 +01:00
Nasreddine Bencherchali 30c658e2a4 fix: broken logic in test
- Fix ` test_duplicate_detections` test
- Add new test `test_broken_thor_logsource_config` to test for broken Windows eventlog sources
2023-01-12 12:21:58 +01:00
Hendrik Baecker 874032c2bf Test: Check 're' rules against unwanted/unneeded escapes 2023-01-06 16:25:27 +01:00
Hendrik Baecker 9985905f54 rule_tests: Rule directory relative to test_* file 2023-01-04 16:25:07 +01:00
Hendrik Baecker c998945b34 test-rules: use cti directory relative to test file
This little change will use 'cti/' relative to the executing
test_*.py file and doesn't care if the testfile is executed
from sigma/ or sigma/tests/.
2023-01-04 16:02:57 +01:00
Hendrik Baecker 3da07164ce test-rules: Execute get_mitre_data() as part of unittest
Catching the data as part of the unittest class is more
IDE friendly cause they won't call __main__ but using the
test methods directly.
2023-01-04 15:58:35 +01:00
Nasreddine Bencherchali 3bd12552bb feat: add bitlocker channel 2023-01-02 22:19:32 +01:00
frack113 014684ddcd add win_dns_analytic_ prefix 2023-01-02 12:16:09 +01:00
frack113 4a0b571598 add new test 2022-12-30 16:31:41 +01:00