Commit Graph

4287 Commits

Author SHA1 Message Date
Cyb3rEng 5508ff45b6 Add files via upload 2021-08-30 21:47:36 -06:00
Florian Roth 36a227796a Merge pull request #1945 from SigmaHQ/rule-devel
rules: cobalt strike rules refactored
2021-08-30 15:48:01 +02:00
Florian Roth 98de92ceaf refactor: global rule match on system and security 2021-08-30 15:17:53 +02:00
Florian Roth 1ded4eb913 rules: cobalt strike rules refactored 2021-08-30 15:10:30 +02:00
frack113 4c414b2e8b fix Base backend doesn't support multiple conditions (33) 2021-08-29 08:52:54 +02:00
frack113 970dfa2f92 Merge pull request #1938 from EvanYu0816/upstream-fixes
Fix Pass the Hash and NotPetya Ransomware rule
2021-08-28 21:02:04 +02:00
frack113 a7456d4d6c Merge pull request #1940 from frack113/fix_ps_fp
Powershell correction
2021-08-28 20:48:07 +02:00
frack113 3e355c64db Merge pull request #1939 from SigmaHQ/rule-devel
rule: UAC bypass by mocking dirs
2021-08-28 20:47:27 +02:00
frack113 68237dffc4 fix HostApplication 2021-08-28 08:18:47 +02:00
frack113 ef6e0c5a4c Fix error and FP 2021-08-28 08:02:16 +02:00
Florian Roth f78225c394 rule: UAC bypass by mocking dirs 2021-08-27 18:12:21 +02:00
Evan Yu 178d82e9cd Fix NotPetya Ransomware rule 2021-08-27 11:53:50 -04:00
Evan Yu 8bdd3e3987 Simplify Pass the Pash rule 2021-08-27 11:53:28 -04:00
frack113 ff37a49dc0 Merge pull request #1930 from SigmaHQ/rule-devel
fix: FPs with whoami rule and 4688 event IDs without parent info
2021-08-27 06:27:30 +02:00
Roberto Rodriguez f05cf20b12 Merge branch 'master' into feature/AADHealth-Agent-HybridADFSServices 2021-08-26 16:12:38 -04:00
Roberto Rodriguez f98970ef06 adding basic rules to detect behavior around AAD health agents and AAD Hybrid Health AD FS services in Azure 2021-08-26 16:10:42 -04:00
frack113 a6149462d8 Merge pull request #1931 from phantinuss/master
More malleable CobaltStrike C2 profiles from new source/reference
2021-08-26 17:18:19 +02:00
frack113 59000b993d Merge pull request #1932 from mlp1515/french_user
Add French user
2021-08-26 17:12:39 +02:00
phantinuss e59b8e1e3e add applicable pipe names from regex rule 2021-08-26 14:53:20 +02:00
mlp1515 cce7cfc79a Update win_tool_psexec.yml
French language settings
2021-08-26 12:51:45 +00:00
mlp1515 e1aa82b412 Update win_susp_tscon_localsystem.yml
French language settings
2021-08-26 12:50:24 +00:00
mlp1515 e9ed5f592c Update sysmon_always_install_elevated_windows_installer.yml
French language settings
2021-08-26 12:48:59 +00:00
mlp1515 4f49f03460 Update sysmon_abusing_debug_privilege.yml
French language settings
2021-08-26 12:46:15 +00:00
mlp1515 a31422db74 Update win_susp_schtask_creation.yml
French language settings
2021-08-26 12:45:24 +00:00
mlp1515 5f419d6f35 Update win_susp_taskmgr_localsystem.yml
French language settings
2021-08-26 12:44:35 +00:00
mlp1515 5545403a9b Update win_whoami_as_system.yml
French language settings
2021-08-26 12:43:33 +00:00
mlp1515 7ad927f28e Update win_wmiprvse_spawning_process.yml
French language settings
2021-08-26 12:42:47 +00:00
mlp1515 644397e65c Update win_exploit_cve_2019_1388.yml
French language settings
2021-08-26 12:41:36 +00:00
phantinuss dc19268583 remove becasue of possible conflict
with a legitimate tool (https://labs.nettitude.com/blog/cve-2017-16245-cve-2017-16246-avecto-defendpoint-multiple-vulnerabilities/)
2021-08-26 14:25:12 +02:00
Florian Roth 6c7d355ef5 Try to add more pipe names to this non-regex rule 2021-08-26 14:00:57 +02:00
Florian Roth 2d36d62e88 Merge pull request #1928 from frack113/fix_name_case
fix file name case
2021-08-26 13:55:12 +02:00
Florian Roth 24d8701f15 fix: null cannot be used in a list with other values 2021-08-26 13:54:18 +02:00
Florian Roth a231aa73b3 fix: FPs with whoami rule and 4688 event IDs without parent info 2021-08-26 13:33:25 +02:00
Florian Roth 54997553ba Merge pull request #1929 from SigmaHQ/rule-devel
refactor: Mimikatz keyword rule refactoring
2021-08-26 13:33:02 +02:00
phantinuss 217dbc768a More malleable CobaltStrike C2 profiles from new source/reference 2021-08-26 12:53:43 +02:00
Florian Roth 8b318b9273 refactor: Mimikatz keyword rule refactoring 2021-08-26 12:51:45 +02:00
f.hubaut e66007a43d fix file name case 2021-08-26 11:15:33 +02:00
frack113 a4021842de Fix invalid tags 2021-08-25 09:15:57 +02:00
frack113 e849af9df0 Merge pull request #1915 from frack113/tags_cve
fix tags
2021-08-25 06:29:48 +02:00
Florian Roth 9f69cead8a Merge pull request #1916 from SigmaHQ/rule-devel
refactor: changed level of rule, refactored RazerInstaller rule
2021-08-24 15:42:26 +02:00
Florian Roth 46e312ff0d fix: error in modifier 2021-08-24 15:03:23 +02:00
Florian Roth cc519552aa refactor: RazorInstaller integrity level system 2021-08-24 14:54:07 +02:00
frack113 7753f8c22e fix tags 2021-08-24 12:36:31 +02:00
Florian Roth 6ca30619ac Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-08-24 12:30:42 +02:00
Florian Roth 3cdb88ad55 refactor: level of suspicious parent for powershell rule 2021-08-24 12:30:40 +02:00
frack113 5b869a3f42 Update cve tags 2021-08-24 10:50:01 +02:00
frack113 ace46c17be Update cve tags 2021-08-24 10:27:27 +02:00
frack113 c2302a15da fix cve tags 2021-08-24 10:10:45 +02:00
Florian Roth 0c69fd9c41 Merge pull request #1898 from SigmaHQ/rule-devel
rule: EfsPotato Named Pipe, splwow64, RazerInstaller
2021-08-24 09:20:54 +02:00
Florian Roth 272625a005 Update win_susp_splwow64.yml 2021-08-24 08:34:08 +02:00