Commit Graph

4256 Commits

Author SHA1 Message Date
mlp1515 4f49f03460 Update sysmon_abusing_debug_privilege.yml
French language settings
2021-08-26 12:46:15 +00:00
mlp1515 a31422db74 Update win_susp_schtask_creation.yml
French language settings
2021-08-26 12:45:24 +00:00
mlp1515 5f419d6f35 Update win_susp_taskmgr_localsystem.yml
French language settings
2021-08-26 12:44:35 +00:00
mlp1515 5545403a9b Update win_whoami_as_system.yml
French language settings
2021-08-26 12:43:33 +00:00
mlp1515 7ad927f28e Update win_wmiprvse_spawning_process.yml
French language settings
2021-08-26 12:42:47 +00:00
mlp1515 644397e65c Update win_exploit_cve_2019_1388.yml
French language settings
2021-08-26 12:41:36 +00:00
frack113 a4021842de Fix invalid tags 2021-08-25 09:15:57 +02:00
frack113 e849af9df0 Merge pull request #1915 from frack113/tags_cve
fix tags
2021-08-25 06:29:48 +02:00
Florian Roth 9f69cead8a Merge pull request #1916 from SigmaHQ/rule-devel
refactor: changed level of rule, refactored RazerInstaller rule
2021-08-24 15:42:26 +02:00
Florian Roth 46e312ff0d fix: error in modifier 2021-08-24 15:03:23 +02:00
Florian Roth cc519552aa refactor: RazorInstaller integrity level system 2021-08-24 14:54:07 +02:00
frack113 7753f8c22e fix tags 2021-08-24 12:36:31 +02:00
Florian Roth 6ca30619ac Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-08-24 12:30:42 +02:00
Florian Roth 3cdb88ad55 refactor: level of suspicious parent for powershell rule 2021-08-24 12:30:40 +02:00
frack113 5b869a3f42 Update cve tags 2021-08-24 10:50:01 +02:00
frack113 ace46c17be Update cve tags 2021-08-24 10:27:27 +02:00
frack113 c2302a15da fix cve tags 2021-08-24 10:10:45 +02:00
Florian Roth 0c69fd9c41 Merge pull request #1898 from SigmaHQ/rule-devel
rule: EfsPotato Named Pipe, splwow64, RazerInstaller
2021-08-24 09:20:54 +02:00
Florian Roth 272625a005 Update win_susp_splwow64.yml 2021-08-24 08:34:08 +02:00
frack113 a04fbe2a99 Merge pull request #1901 from frack113/redcanary
Redcanary Powershell Suspicious Win32_PnPEntity T1120
2021-08-23 19:44:16 +02:00
Florian Roth 998ebbe1f3 fix: typo in name 2021-08-23 18:46:05 +02:00
Florian Roth 6b86dacc9e rule: razor installer 2021-08-23 18:44:15 +02:00
frack113 be316db84d Merge pull request #1899 from secDre4mer/master
feat: Add rule for malicious CSR export on Exchange
2021-08-23 17:26:16 +02:00
SomeOne 037f33b5e2 Replace by default windows fieldnames 2021-08-23 15:24:48 +02:00
Florian Roth 91b42f9077 fix: indentation 2021-08-23 15:03:59 +02:00
SomeOne 45f30cb2b4 Add fields to event log cleared 2021-08-23 15:00:07 +02:00
frack113 25072e37b3 update references 2021-08-23 13:30:46 +02:00
frack113 33c6ff6b5f add powershell_suspicious_win32_pnpentity 2021-08-23 13:17:35 +02:00
Max Altgelt 82dde594d1 feat: Add rule for malicious CSR export on Exchange 2021-08-23 11:20:30 +02:00
Florian Roth a0f72e5f6f rule: suspicious splwow64 process starts 2021-08-23 10:41:42 +02:00
Florian Roth dc3ed771b5 rule: EfsPotato Named Pipe 2021-08-23 08:32:50 +02:00
frack113 fc9666fb4e Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
2021-08-22 18:56:08 +02:00
frack113 0a410010a2 Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
2021-08-22 18:50:58 +02:00
SomeOne 295054dcbe Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
frack113 064c65cb1f Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
2021-08-21 18:04:52 +02:00
frack113 07a87aa7f8 Merge pull request #1858 from frack113/fix_pr718
Replace pr718
2021-08-21 18:02:30 +02:00
frack113 a44206bfa0 Some cleanup 2021-08-21 17:33:39 +02:00
pbssubhash eee497f656 Title modification 2021-08-21 20:04:03 +05:30
pbssubhash a415463f5b Modified rule 2021-08-21 19:37:28 +05:30
pbssubhash fba54b8d69 First Rule commit 2021-08-21 17:47:56 +05:30
frack113 42c90b9d20 fix powershell_psattack error 2021-08-21 10:05:47 +02:00
frack113 2f683b9ab7 fix powershell_clear_powershell_history error 2021-08-21 10:00:48 +02:00
frack113 0fb6c35b1f Cleanup PS rules 2021-08-21 09:58:58 +02:00
frack113 da839775fe Update PS rules 2021-08-21 09:50:59 +02:00
frack113 6c529f7ab2 Update PS rules 2021-08-21 09:33:52 +02:00
frack113 cb95582077 Update PowerShell rule 2021-08-21 09:08:38 +02:00
Florian Roth b92346ba5f Merge pull request #1882 from austinsonger/win_susp_bitstransfer.yml
win_susp_bitstransfer.yml
2021-08-20 16:53:52 +02:00
frack113 7ebd411190 update ref from conti_leak 2021-08-20 14:22:17 +02:00
Austin Songer fe0e1353e0 Update win_susp_bitstransfer.yml 2021-08-19 22:24:23 -05:00
Austin Songer 8d57ae5ffd Create win_susp_bitstransfer.yml 2021-08-19 21:57:37 -05:00