Nasreddine Bencherchali
|
80098113d0
|
Update image_load_susp_cmstp.yml
|
2022-08-31 09:53:07 +02:00 |
|
Nasreddine Bencherchali
|
343b0ef199
|
Update net_connection_win_susp_cmstp.yml
|
2022-08-31 09:46:18 +02:00 |
|
Nasreddine Bencherchali
|
77c5640839
|
Update net_connection_win_susp_cmstp.yml
|
2022-08-31 09:42:25 +02:00 |
|
Nasreddine Bencherchali
|
399a18b762
|
Update net_connection_win_susp_cmstp.yml
|
2022-08-31 09:41:25 +02:00 |
|
Nasreddine Bencherchali
|
ea183cae13
|
Updates+New Rules
|
2022-08-31 09:39:16 +02:00 |
|
Florian Roth
|
f62d53e670
|
Merge pull request #3448 from SigmaHQ/rule-devel
rules: wmic extended, defendercheck, sharpldapwhoami
|
2022-08-30 11:38:45 +02:00 |
|
Florian Roth
|
35d9e5f36a
|
fix: syntax error, docs: change fp text
|
2022-08-30 11:29:11 +02:00 |
|
Florian Roth
|
b5c57e97fc
|
Merge branch 'master' into rule-devel
|
2022-08-30 09:14:37 +02:00 |
|
Florian Roth
|
52c5851ef6
|
rules: wmic extended, defendercheck, sharpldapwhoami
|
2022-08-30 09:13:25 +02:00 |
|
frack113
|
da72e3b7c0
|
Merge pull request #3441 from ionsor/patch-6
Update net_connection_win_dead_drop_resolvers.yml
|
2022-08-30 08:38:17 +02:00 |
|
frack113
|
f9b79161a5
|
Merge pull request #3444 from danielgottt/patch-7
Create proc_creation_win_deviceenroller_evasion.yml
|
2022-08-30 08:24:24 +02:00 |
|
frack113
|
45a87dd22d
|
Update net_connection_win_dead_drop_resolvers.yml
|
2022-08-30 08:22:10 +02:00 |
|
Wagga
|
4573ab0a21
|
Fix a lot of typos in rules text and comments #Part 3 (#3446)
|
2022-08-30 08:21:25 +02:00 |
|
Gott
|
8809fc6a8e
|
Update proc_creation_win_deviceenroller_evasion.yml
Made corrections frack presented
|
2022-08-29 15:23:17 -04:00 |
|
Florian Roth
|
36eadcae87
|
Merge pull request #3442 from phantinuss/master
fix: FP found in testing environment
|
2022-08-29 20:37:35 +02:00 |
|
Florian Roth
|
d9a5265ce7
|
Merge pull request #3445 from wagga40/master
Fix a lot of typos in rules text and comments
|
2022-08-29 20:37:14 +02:00 |
|
Wagga
|
9db9d25b68
|
Update file_event_win_susp_winword_startup.yml
|
2022-08-29 20:16:41 +02:00 |
|
Wagga
|
6c42bfb64b
|
Update file_event_win_powershell_startup_shortcuts.yml
|
2022-08-29 20:15:54 +02:00 |
|
Wagga
|
8dbeedf728
|
Update file_event_win_powershell_startup_shortcuts.yml
|
2022-08-29 20:14:47 +02:00 |
|
Wagga
|
691aae2638
|
Update proc_creation_win_ntfs_short_name_path_use_image.yml
|
2022-08-29 20:13:14 +02:00 |
|
Wagga
|
a693e181ff
|
Update registry_set_disable_uac_registry.yml
|
2022-08-29 20:12:10 +02:00 |
|
Wagga
|
277032b460
|
Update registry_set_mpnotify_persistence.yml
|
2022-08-29 20:11:29 +02:00 |
|
Wagga
|
63ea4d7fb6
|
Update registry_set_fax_dll_persistance.yml
|
2022-08-29 20:10:25 +02:00 |
|
Wagga
|
cb4f834845
|
Update posh_ps_nishang_malicious_commandlets.yml
Typo in detection : https://github.com/samratashok/nishang/blob/master/Utility/Add-Persistence.ps1
|
2022-08-29 18:53:22 +02:00 |
|
Wagga
|
8a9d63bba1
|
Update proc_creation_win_wmic_remote_service.yml
|
2022-08-29 18:50:04 +02:00 |
|
Wagga
|
86b448b715
|
Update proc_creation_win_lolbin_register_app.yml
|
2022-08-29 18:49:17 +02:00 |
|
Wagga
|
351d8bcc40
|
Update proc_creation_win_wmic_unquoted_service_search.yml
|
2022-08-29 18:48:29 +02:00 |
|
Wagga
|
7c0bd62e9f
|
Update proc_creation_win_cmd_redirection_susp_folder.yml
|
2022-08-29 18:47:44 +02:00 |
|
Wagga
|
6494e185cf
|
Update image_load_vmware_xfer_load_dll_from_nondefault_path.yml
|
2022-08-29 18:46:34 +02:00 |
|
Wagga
|
eb572e8b0c
|
Update proc_creation_win_wpbbin_persistence.yml
|
2022-08-29 18:45:49 +02:00 |
|
Wagga
|
86876adad4
|
Update proc_creation_win_cmd_dosfuscation.yml
|
2022-08-29 18:45:00 +02:00 |
|
Wagga
|
7b0eb71563
|
Update proc_creation_win_vmtoolsd_susp_child_process.yml
|
2022-08-29 18:44:19 +02:00 |
|
Gott
|
4f2205d4f2
|
Update proc_creation_win_deviceenroller_evasion.yml
correction to falsepositive
|
2022-08-29 11:55:36 -04:00 |
|
Gott
|
0f75a16ea3
|
Update proc_creation_win_deviceenroller_evasion.yml
correction to mitre tag
|
2022-08-29 11:46:25 -04:00 |
|
Gott
|
2a6c27b7b5
|
Create proc_creation_win_deviceenroller_evasion.yml
|
2022-08-29 11:35:54 -04:00 |
|
phantinuss
|
5367e74eef
|
fix: FP found in testing environment
|
2022-08-29 16:58:12 +02:00 |
|
Feathers
|
4d3d9b10ea
|
Update net_connection_win_dead_drop_resolvers.yml
Added the domain cdn.discordapp.com since is commonly used by malware families
|
2022-08-29 12:41:57 +02:00 |
|
Wagga
|
0d92b047ff
|
Update proc_creation_win_susp_powershell_webclient_casing.yml
|
2022-08-29 12:11:33 +02:00 |
|
Florian Roth
|
130ec65dde
|
Merge pull request #3440 from wagga40/master
Fix a lot of typos in rules text and comments
|
2022-08-29 08:24:38 +02:00 |
|
Wagga
|
7c6bf47757
|
Update proc_creation_win_susp_rundll32_user32_dll.yml
|
2022-08-29 07:59:45 +02:00 |
|
Wagga
|
39edfddce4
|
Update proc_creation_win_lolbin_diantz_ads.yml
|
2022-08-29 07:58:05 +02:00 |
|
Wagga
|
9d3d718c27
|
Update proc_creation_win_icacls_deny.yml
|
2022-08-29 07:57:34 +02:00 |
|
Wagga
|
d5724fb583
|
Update proc_creation_win_susp_advancedrun.yml
|
2022-08-29 07:56:59 +02:00 |
|
Wagga
|
11e24a6e66
|
Update proc_creation_win_susp_advancedrun_priv_user.yml
|
2022-08-29 07:56:27 +02:00 |
|
Wagga
|
cffc6fa947
|
Update proc_creation_win_susp_nmap.yml
|
2022-08-29 07:55:38 +02:00 |
|
Wagga
|
5515dc7397
|
Update proc_creation_win_fsutil_drive_enumeration.yml
|
2022-08-29 07:54:56 +02:00 |
|
Wagga
|
da82c739c5
|
Update proc_creation_win_attrib_system_susp_paths.yml
|
2022-08-29 07:54:18 +02:00 |
|
Wagga
|
c0b3cd847f
|
Update proc_creation_win_lolbin_cl_mutexverifiers.yml
|
2022-08-29 07:53:15 +02:00 |
|
Wagga
|
37230eabee
|
Update proc_creation_win_lolbin_cl_loadassembly.yml
|
2022-08-29 07:52:56 +02:00 |
|
Wagga
|
762ac06eea
|
Update proc_creation_win_lolbin_wlrmdr.yml
|
2022-08-29 07:52:12 +02:00 |
|