Commit Graph

469 Commits

Author SHA1 Message Date
Pawel Mazur 4bbe4962b0 New Rule - Linux - Auditd - Clipboard Collection 2021-09-24 18:40:10 +02:00
Pawel Mazur e20e5033e7 New Rule - Linux - Auditd - Screencapture with Import Tool 2021-09-21 18:55:48 +02:00
zakibro e47a7d9826 Update lnx_auditd_screencaputre_xwd.yml 2021-09-13 19:08:23 +02:00
Pawel Mazur a8f9617ccd New Rule - Linux - Auditd - Screen Capture with xwd 2021-09-13 18:56:33 +02:00
zakibro 6412ddaaee Update lnx_auditd_steghide_extract_steganography.yml 2021-09-11 11:19:21 +02:00
zakibro d0741f9f3a Update lnx_auditd_steghide_embed_steganography.yml
Formatting and detection changes
2021-09-11 11:18:08 +02:00
Pawel Mazur 89f15c01f9 New Linux Auditd Rules - Steghide Steganography 2021-09-11 10:56:17 +02:00
zakibro a4dffc14d4 Update lnx_auditd_unzip_hidden_zip_files_steganography.yml
Fixing formatting
2021-09-10 07:54:56 +02:00
zakibro 0b5e8cb980 Update lnx_auditd_hidden_zip_files_steganography.yml
Formatting changes
2021-09-10 07:52:35 +02:00
Pawel Mazur 5a5769cce6 New Rule - Linux - Steganography Unzip Hidden Information From Picture File 2021-09-09 20:38:25 +02:00
zakibro 3fbe5478c3 Update and rename lnx_auditd_hidden_files_steganography.yml to lnx_auditd_hidden_zip_files_steganography.yml
Splitting the rule into separate rules
2021-09-09 20:34:20 +02:00
zakibro 458973af81 Update lnx_auditd_hidden_files_steganography.yml
Adding missing field: action
2021-09-09 16:52:58 +02:00
zakibro 62db796fc2 Update lnx_auditd_hidden_files_steganography.yml
Formatting changes
2021-09-09 16:46:41 +02:00
zakibro 0971fe1d49 Update lnx_auditd_hidden_files_steganography.yml
Fixing the listing issue
2021-09-09 16:27:57 +02:00
Pawel Mazur 41458d8a5a New Rule - Linux Auditd Hidden Files - Steganography 2021-09-09 16:13:27 +02:00
zakibro bba66ca762 Update lnx_auditd_hidden_files_directories.yml
Updating arguments section
2021-09-07 07:57:50 +02:00
zakibro e9fa5bde2b Update lnx_auditd_hidden_files_directories.yml
Correction of tag
2021-09-06 18:55:58 +02:00
Pawel Mazur 7c2895c73f New Rule - Linux Hidden Files and Directories 2021-09-06 18:43:49 +02:00
Pawel Mazur 59eb7ce032 Merge branch 'master' of https://github.com/zakibro/sigma 2021-09-06 18:41:19 +02:00
Pawel Mazur 9f5f25e480 New Rule - Linux Hidden Files and Directories 2021-09-06 18:40:39 +02:00
zakibro f52860d6ab Merge branch 'SigmaHQ:master' into master 2021-09-06 18:40:02 +02:00
Pawel Mazur 3eb354e34c Merge branch 'master' of https://github.com/zakibro/sigma 2021-09-06 18:37:45 +02:00
Pawel Mazur ef3efd8fd3 New Rule Linux - Hidden Files and Directories 2021-09-06 18:37:02 +02:00
Florian Roth 6b2bacd2cc Merge pull request #1979 from frack113/test_global
Change ID in global action rule
2021-09-06 08:44:14 +02:00
zakibro 5042ba65ac Update lnx_auditd_audio_capture.yml
Added more references about arecord.
2021-09-05 09:28:53 +02:00
Pawel Mazur caf78b5ea1 New Rule - Linux-Audio-Capture 2021-09-04 22:10:34 +02:00
frack113 769451dc03 Add missing id 2021-09-03 13:42:15 +02:00
frack113 815134df7f Cleanup 2021-09-03 13:30:10 +02:00
zakibro 8bd859f550 Update lnx_auditd_system_info_discovery.yml 2021-09-03 13:07:42 +02:00
Pawel Mazur 864286e206 New Rule - Linux-Auditd-System Information Discovery 2021-09-03 11:33:18 +02:00
frack113 086a15fc45 Update global ID 2021-09-02 20:07:03 +02:00
f.hubaut e66007a43d fix file name case 2021-08-26 11:15:33 +02:00
frack113 5b869a3f42 Update cve tags 2021-08-24 10:50:01 +02:00
SomeOne 295054dcbe Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
frack113 eb406ba36f Merge pull request #1844 from frack113/cleanup
Add more compliance test
2021-08-16 17:17:25 +02:00
frack113 e45557316e Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
Max Altgelt ce326cb903 fix: Correct broken rules, add documentation 2021-08-13 15:46:30 +02:00
Max Altgelt 6f05e33feb fix: Correct incorrect message / keyword usage
Correct a number of rules where message or keyword were incorrectly used
as field names in events (typically windows event logs). However, neither
field actually exists and as such these strings could never match.
2021-08-12 16:28:07 +02:00
frack113 f2cdbb5aa7 Rename rule service:auditd 2021-07-07 13:53:51 +02:00
leegengyu 3791ab4b12 Updated ART reference links from .yaml to .md 2021-07-06 17:43:20 +08:00
leegengyu 69d5d9734d Updated ART reference links from .yaml 2021-07-06 17:39:25 +08:00
frack113 f91abf8929 Fix auditd is a service 2021-05-30 08:58:25 +02:00
Florian Roth b5352ac5f7 fix: duplicate UUIDs 2021-05-27 10:29:21 +02:00
phantinuss 4b520de373 new rule detecting ld.so preload persistence by keyword 2021-05-05 15:12:07 +02:00
Florian Roth 8497c8a9e6 fix: linux keywords rule 2021-05-05 12:56:24 +02:00
Florian Roth 15ab1d5e8b Create lnx_symlink_etc_passwd.yml 2021-05-05 11:55:49 +02:00
Florian Roth 161180c357 refactor: extended shellshock rule 2021-04-28 11:47:24 +02:00
Florian Roth 47504fbd56 fix: shellshock expression 2021-04-28 11:46:49 +02:00
Cedric Hien bbdbab700d Fix invalid logsource on lnx_system_info_discovery rule 2021-04-17 12:57:30 +02:00
Thomas Patzke 90efe974b8 Fixes and improvements 2021-04-03 00:08:55 +02:00