grikos
|
65d201b1e4
|
att&ck tags review: windows/process_creation part 7
|
2020-08-30 19:17:38 +03:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
Maxime Thiebaut
|
4600bf73dc
|
Update rules to follow the Sigma state specification
The [Sigma specification's status component](https://github.com/Neo23x0/sigma/wiki/Specification#status-optional) states the following:
> Declares the status of the rule:
> - stable: the rule is considered as stable and may be used in production systems or dashboards.
> - test: an almost stable rule that possibly could require some fine tuning.
> - experimental: an experimental rule that could lead to false results or be noisy, but could also identify interesting events.
However the Sigma Rx YAML specification states the following:
> ```yaml
> status:
> type: //any
> of:
> - type: //str
> value: stable
> - type: //str
> value: testing
> - type: //str
> value: experimental
> ```
The specification confuses the `test` and `testing` state. This commit changes the `test` state into the `testing` state which is already used in the code-base:
- [`sigma/sigma-schema.rx.yml`](https://github.com/Neo23x0/sigma/blob/a805d18bbae60d3e4f291c8a18304104ed2e71c7/sigma-schema.rx.yml#L49)
- [`sigma/tools/sigma/filter.py`](https://github.com/Neo23x0/sigma/blob/f3c60a63099f80296c8750aaba667e98ac71a4f7/tools/sigma/filter.py#L26)
- [`sigma/tools/sigmac`](https://github.com/Neo23x0/sigma/blob/4e42bebb3480720966a59528cd8482c6271e603c/tools/sigmac#L98)
Although not modifyable through a PR, the specification should furthermore be updated to use the `testing` state.
|
2020-04-24 20:50:31 +02:00 |
|
vesche
|
3889be6255
|
Replace reference link for win_susp_netsh_dll_persistence
|
2020-04-10 01:05:10 -05:00 |
|
vesche
|
82db80bee6
|
Remove wrong mitre technique
|
2020-04-10 01:02:43 -05:00 |
|
vesche
|
72b821e046
|
Update win_susp_netsh_dll_persistence.yml
|
2020-04-09 11:16:18 -05:00 |
|
Thomas Patzke
|
373424f145
|
Rule fixes
Made tests pass the new CI tests. Added further allowed lower case words
in rule test.
|
2020-02-20 23:00:16 +01:00 |
|
Thomas Patzke
|
8d6a507ec4
|
OSCD QA wave 1
* Checked all rules against Mordor and EVTX samples datasets
* Added field names
* Some severity adjustments
* Fixes
|
2020-01-11 00:11:27 +01:00 |
|
Thomas Patzke
|
924e1feb54
|
UUIDs + moved unsupported logic
* Added UUIDs to all contributed rules
* Moved unsupported logic directory out of rules/ because this breaks CI
testing.
|
2019-12-19 23:56:36 +01:00 |
|
yugoslavskiy
|
b9991bb2ec
|
Update win_susp_netsh_dll_persistence.yml
|
2019-11-10 21:21:42 +03:00 |
|
stvetro
|
dcaacd07bf
|
4 rules to cover ART
|
2019-10-25 15:38:47 +04:00 |
|