Florian Roth
423f81c912
Update win_mouse_lock.yml
2020-09-02 14:49:37 +02:00
Florian Roth
73bc514f60
fix: 1 of them / one selection
2020-09-02 12:34:35 +02:00
Yugoslavskiy Daniil
11e0f794d9
review windows/process_creation part 4
2020-09-02 02:34:34 +02:00
aw350m3
7c6c5263ab
fix duplication of key modified in win_malware_emotet.yml
2020-09-01 17:09:54 +00:00
aw350m3
8ed3eb1494
att&ck tags review: windows/process_creation part 3
2020-09-01 17:02:59 +00:00
grikos
65d201b1e4
att&ck tags review: windows/process_creation part 7
2020-08-30 19:17:38 +03:00
Yugoslavskiy Daniil
e04b896cbc
fix tags
2020-08-29 21:34:20 +02:00
grikos
a95c4347d9
fixed typo in tag
2020-08-29 20:19:46 +03:00
grikos
6092bfcec1
att&ck tags review: windows/process_creation part 9
2020-08-29 19:22:09 +03:00
aw350m3
ae99a2b207
Removed extra space that broke tests
2020-08-29 04:46:12 +00:00
aw350m3
4ed3db8d23
Merge branch 'master' of github.com:oscd-initiative/sigma
2020-08-29 04:39:45 +00:00
aw350m3
da766a245f
att&ck tags review: windows/process_creation part 2
2020-08-29 04:39:30 +00:00
grikos
293662810e
att&ck tags review: windows/process_creation part 8
2020-08-28 17:14:26 +03:00
vh
a2fec9f3b9
Fix sysmon backend
2020-08-28 12:26:40 +03:00
Alexey Lednyov
880b10cce1
att&ck tags review: windows/process_creation part 1, network
2020-08-27 20:43:47 +03:00
Florian Roth
7d3a6293f5
rule: Snatch ransomware
2020-08-26 09:42:34 +02:00
Florian Roth
bc74ac1f8a
Update win_susp_rasdial_activity.yml
2020-08-18 14:40:37 +02:00
Florian Roth
da54e89f30
Merge pull request #976 from diskurse/rule-devel
...
Rule devel
2020-08-17 15:02:31 +02:00
Florian Roth
8a02541b0a
style: removed lists where unnecessary
2020-08-17 15:02:16 +02:00
Florian Roth
6dc8dbb6d8
style: removed lists where unnecessary
2020-08-17 15:01:52 +02:00
Bar Haim
bd96b1c5ad
Update win_susp_rasdial_activity.yml
...
`rasdial` is an `exe`, and probably appear as `rasdial.exe`
`LIKE` is more fit in this case
2020-08-16 16:17:49 +03:00
Bar Haim
c7dc9df87e
Update sysmon_apt_muddywater_dnstunnel.yml
2020-08-16 12:39:04 +03:00
Bar Haim
4168f1e430
Update win_new_service_creation.yml
2020-08-16 11:44:40 +03:00
Cian Heasley
b378b3d62b
win_mouse_lock.yml
...
In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
2020-08-13 12:09:07 +01:00
Cian Heasley
d1e9f01d23
win_dnscat2_powershell_implementation.yml
...
The PowerShell implementation of DNSCat2 calls nslookup to craft queries. Counting nslookup processes spawned by PowerShell will show hundreds or thousands of instances if PS DNSCat2 is active locally.
2020-08-13 12:06:48 +01:00
Thomas Patzke
f827a557f2
Merge pull request #936 from rtkmokuka/typo_wmiprvse_spawning_process
...
Change fitler typo from 'Username' to 'User' for Wmiprvse Spawning Process rule
2020-08-05 23:26:14 +02:00
Florian Roth
4529e4cd52
Merge pull request #966 from Neo23x0/rule-devel
...
rule: TAIDOOR malware load
2020-08-04 14:54:24 +02:00
Florian Roth
052379a512
fix: tightened TAIDOOR rule
2020-08-04 14:37:18 +02:00
Florian Roth
c4953409aa
rule: TAIDOOR malware load
...
https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a
2020-08-04 14:31:29 +02:00
IPv777
a52583dc68
.002 = SMB/Windows Admin Shares
2020-08-03 17:43:14 +02:00
Florian Roth
df3bfb1b37
rule: Winnti Pipemon
2020-07-30 18:55:47 +02:00
Florian Roth
5abf101c0b
Merge pull request #954 from Neo23x0/rule-devel
...
Rule devel
2020-07-28 10:22:52 +02:00
Florian Roth
8970d03f6f
Merge pull request #952 from Neo23x0/devel
...
feat: Detect duplicate rule tags
2020-07-28 10:21:59 +02:00
Florian Roth
80f4b4ec71
fix: rules with duplicate tags
2020-07-27 11:44:47 +02:00
IPv777
77a8ac59ef
remove duplicate
2020-07-24 16:38:08 +02:00
Florian Roth
8a4b53eb3a
fix: rule leads to FPs on systems that don't log the cmdline parameters
2020-07-23 17:04:16 +02:00
Daniel Masse
13cf0488ae
Add 'contains' for the ps encoded chars rule
2020-07-22 10:49:22 -04:00
Florian Roth
769a9212a5
Merge pull request #943 from diskurse/rule-devel
...
Webshell Recon Detection Via CommandLine & ProcessesAdd files via upload
2020-07-22 13:02:44 +02:00
Cian Heasley
023bf76363
Add files via upload
...
Looking for processes spawned by web server components that indicate reconnaissance by popular public domain webshells for whether perl, python or wget are installed.
2020-07-22 09:05:50 +01:00
Aidan Bracher
ff3f9fe9b3
Updated tags
2020-07-18 03:02:43 +01:00
Aidan Bracher
4ffe9cb042
Updated tags with sub-techniques
2020-07-18 02:53:46 +01:00
Aidan Bracher
3bd768e49b
Updated tags with sub-techniques
2020-07-18 02:52:15 +01:00
Aidan Bracher
1442812681
Updated tags
2020-07-18 02:44:53 +01:00
Aidan Bracher
30bd591c96
Update win_apt_ke3chang to include sub-techniques
2020-07-18 02:37:56 +01:00
Marko Okuka
1d39b40fd1
Fixing typo in rule: Username to User
2020-07-16 10:09:29 -04:00
Florian Roth
3025d6850c
Merge pull request #932 from rtkdmasse/rule-selection-typos
...
Change the selection from Command to CommandLine in a couple of rules
2020-07-16 09:10:15 +02:00
Florian Roth
b1de627e94
Update win_apt_zxshell.yml
2020-07-16 08:47:24 +02:00
Daniel Masse
0489a50bd0
Change the selection from Command to CommandLine in a couple of rules
2020-07-15 15:55:26 -04:00
Florian Roth
8f66803ddf
Merge pull request #927 from Neo23x0/rule-devel
...
improved CVE-2020-1350 rule
2020-07-15 12:06:31 +02:00
Florian Roth
1c103a749f
fix: more FPs based on feedback
...
https://twitter.com/GossiTheDog/status/1283341486680166400
2020-07-15 12:05:50 +02:00