Wagga
691aae2638
Update proc_creation_win_ntfs_short_name_path_use_image.yml
2022-08-29 20:13:14 +02:00
Wagga
8a9d63bba1
Update proc_creation_win_wmic_remote_service.yml
2022-08-29 18:50:04 +02:00
Wagga
86b448b715
Update proc_creation_win_lolbin_register_app.yml
2022-08-29 18:49:17 +02:00
Wagga
351d8bcc40
Update proc_creation_win_wmic_unquoted_service_search.yml
2022-08-29 18:48:29 +02:00
Wagga
7c0bd62e9f
Update proc_creation_win_cmd_redirection_susp_folder.yml
2022-08-29 18:47:44 +02:00
Wagga
eb572e8b0c
Update proc_creation_win_wpbbin_persistence.yml
2022-08-29 18:45:49 +02:00
Wagga
86876adad4
Update proc_creation_win_cmd_dosfuscation.yml
2022-08-29 18:45:00 +02:00
Wagga
7b0eb71563
Update proc_creation_win_vmtoolsd_susp_child_process.yml
2022-08-29 18:44:19 +02:00
Wagga
0d92b047ff
Update proc_creation_win_susp_powershell_webclient_casing.yml
2022-08-29 12:11:33 +02:00
Wagga
7c6bf47757
Update proc_creation_win_susp_rundll32_user32_dll.yml
2022-08-29 07:59:45 +02:00
Wagga
39edfddce4
Update proc_creation_win_lolbin_diantz_ads.yml
2022-08-29 07:58:05 +02:00
Wagga
9d3d718c27
Update proc_creation_win_icacls_deny.yml
2022-08-29 07:57:34 +02:00
Wagga
d5724fb583
Update proc_creation_win_susp_advancedrun.yml
2022-08-29 07:56:59 +02:00
Wagga
11e24a6e66
Update proc_creation_win_susp_advancedrun_priv_user.yml
2022-08-29 07:56:27 +02:00
Wagga
cffc6fa947
Update proc_creation_win_susp_nmap.yml
2022-08-29 07:55:38 +02:00
Wagga
5515dc7397
Update proc_creation_win_fsutil_drive_enumeration.yml
2022-08-29 07:54:56 +02:00
Wagga
da82c739c5
Update proc_creation_win_attrib_system_susp_paths.yml
2022-08-29 07:54:18 +02:00
Wagga
c0b3cd847f
Update proc_creation_win_lolbin_cl_mutexverifiers.yml
2022-08-29 07:53:15 +02:00
Wagga
37230eabee
Update proc_creation_win_lolbin_cl_loadassembly.yml
2022-08-29 07:52:56 +02:00
Wagga
762ac06eea
Update proc_creation_win_lolbin_wlrmdr.yml
2022-08-29 07:52:12 +02:00
Wagga
b0af5fbc8f
Update proc_creation_win_lolbin_squirrel.yml
2022-08-29 07:50:55 +02:00
Wagga
3f3705164f
Update proc_creation_win_net_user_add_never_expire.yml
2022-08-29 07:47:56 +02:00
Wagga
1a26c174f2
Update proc_creation_win_inline_base64_mz_header.yml
2022-08-29 07:47:27 +02:00
Wagga
c820429bdb
Update proc_creation_win_windows_terminal_susp_children.yml
2022-08-29 07:46:30 +02:00
Wagga
8594d926b1
Update proc_creation_win_set_policies_to_unsecure_level.yml
2022-08-29 07:43:52 +02:00
Wagga
d8852f6fa6
Update proc_creation_win_dll_sideload_vmware_xfer.yml
2022-08-29 07:27:21 +02:00
Wagga
f5a0c0e012
Update proc_creation_win_lolbin_winword.yml
2022-08-29 07:26:44 +02:00
Wagga
c8a5414412
Update proc_creation_win_dll_sideload_defender.yml
2022-08-29 07:26:03 +02:00
Florian Roth
00305d6727
Merge pull request #3438 from frack113/redcannary_20220828
...
Redcannary 20220828
2022-08-28 19:53:08 +02:00
Florian Roth
ff88a7e177
fix: FP with VSCode extensions
2022-08-28 19:33:49 +02:00
Florian Roth
bd03d86695
Update proc_creation_win_nimgrab.yml
2022-08-28 11:40:05 +02:00
frack113
b9a2c720a8
Redcannary 20220828
2022-08-28 11:16:24 +02:00
Florian Roth
46d917f2ca
Merge pull request #3435 from nasbench/nasbench-rule-devel
...
Rule Dev (New + Update)
2022-08-27 08:56:23 +02:00
Florian Roth
33cd3e9fd9
Merge branch 'master' into rule-devel
2022-08-26 22:49:54 +02:00
Florian Roth
bc46de2685
Delete proc_creation_win_sliver_default_shell_command.yml
2022-08-26 20:52:05 +02:00
Florian Roth
dcec3280fc
merge: Nasreddine's Sliver rules
2022-08-26 20:51:39 +02:00
Nasreddine Bencherchali
40ce21f3e8
Update proc_creation_win_schtasks_system.yml
2022-08-26 19:03:50 +01:00
Nasreddine Bencherchali
fcd9236bae
Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel
2022-08-26 19:02:04 +01:00
frack113
bdbce73c9d
Merge pull request #3434 from nasbench/revert-3433-patch-1
...
Revert "Fixing selection_user to match NT AUTHORITY\SYSTEM"
2022-08-26 19:56:59 +02:00
Florian Roth
3c363f6bf4
refactor: sliver service rule, fix: FP
2022-08-26 18:09:11 +02:00
Florian Roth
3424c191fc
revert: deleted rule
2022-08-26 18:04:02 +02:00
Florian Roth
bee8468f6c
rule: sysaidserver child
2022-08-26 18:03:14 +02:00
Florian Roth
0dddfab086
rule: MuddyWater rules
2022-08-26 17:49:58 +02:00
Florian Roth
c374703ff5
rules: more sliver rules
2022-08-26 17:48:02 +02:00
phantinuss
e80116e704
fix: FPs found in testing environment
2022-08-26 17:29:49 +02:00
Nasreddine Bencherchali
11a322f4f0
New + Update
2022-08-26 15:38:43 +01:00
Nasreddine Bencherchali
060fbcda31
Revert "Fixing selection_user to match NT AUTHORITY\SYSTEM"
2022-08-26 11:25:41 +01:00
jkb
f316469cd7
Fixing selection_user to match NT AUTHORITY\SYSTEM
...
This should be 'SYSTEM' not ' SYSTEM ' - these leading/trailing spaces are making this detection invalid since the /RU parameter value will be "NT AUTHORITY\SYSTEM".
2022-08-26 00:25:04 +02:00
Florian Roth
a40cce9a63
rule: Sliver implant shell activity pattern
2022-08-25 17:50:47 +02:00
Florian Roth
c5e183cf2e
Merge pull request #3432 from SigmaHQ/rule-devel
...
Create Stream Hash Rules
2022-08-25 14:17:50 +02:00