Commit Graph

3803 Commits

Author SHA1 Message Date
Florian Roth 8d9c11b26e Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2022-10-11 11:40:07 +02:00
Florian Roth 5ad51c4dea refactor: additional Rubeus indicators 2022-10-11 11:40:03 +02:00
Florian Roth 0df87d76f2 fix: duplicate, list with one entry 2022-10-10 22:49:34 +02:00
Florian Roth b2c012146e rules: pchunter, process hacker 2022-10-10 17:21:17 +02:00
Florian Roth cb73e9725a Merge pull request #3570 from SigmaHQ/rule-devel
IOX and NPS tunneling tools
2022-10-10 00:26:48 +02:00
frack113 cf7a348028 Fix related 2022-10-09 17:28:05 +02:00
frack113 931fb30853 old experimental rule promotion 2022-10-09 16:54:04 +02:00
Florian Roth e009ba937e rule: NPS tunneling tool 2022-10-08 09:49:51 +02:00
Florian Roth deb5540816 rules: refactored FRP, new IOX 2022-10-08 09:32:36 +02:00
Nasreddine Bencherchali 8dbd03ff32 Fix FP In Testing 2022-10-07 13:26:33 +02:00
Florian Roth 6623778a61 fix: wrong log source 2022-10-07 10:44:35 +02:00
Florian Roth c073388472 rule: lpe - tabtip indicator 2022-10-07 10:41:04 +02:00
Florian Roth b634e1a3f9 Merge pull request #3562 from nasbench/pysigma-fix
PySigma Issues Fix
2022-10-07 09:21:15 +02:00
frack113 7539d29e8b Merge pull request #3559 from nasbench/nasbench-rule-devel
Rule Dev
2022-10-07 06:07:43 +02:00
Florian Roth d5e2991a4c Merge pull request #3551 from frack113/redcannary_20221002
Redcannary rules
2022-10-06 13:02:46 +02:00
Florian Roth 8a0cf2e7e6 Update proc_creation_win_hh_chm_http.yml 2022-10-06 09:28:17 +02:00
Florian Roth c0ff746d99 change: make uppercase in Sysmon version 2022-10-06 09:27:26 +02:00
Florian Roth f0196039ba Update proc_creation_win_susp_logoff.yml 2022-10-06 09:24:15 +02:00
Florian Roth f1435ea16b Update proc_creation_win_susp_logoff.yml 2022-10-06 09:23:37 +02:00
Florian Roth 881dd0c6d0 Update proc_creation_win_pdq_deploy.yml 2022-10-06 09:22:44 +02:00
Florian Roth 15232621b1 refactor: another JuicyPotatoNG pattern 2022-10-06 08:47:23 +02:00
Florian Roth b6270dfcf0 Merge branch 'master' into rule-devel 2022-10-06 08:43:02 +02:00
Florian Roth e92f2475b6 refactor: JuicyPotatoNG imphashes 2022-10-06 08:30:48 +02:00
frack113 32406c1915 Issue 3552 2022-10-06 06:50:54 +02:00
frack113 b1b7428a30 Merge pull request #3560 from redsand/fp_ec2_windows
FP: ignore amazon aws ec2 scripts
2022-10-06 06:41:22 +02:00
Nasreddine Bencherchali dadec8b9f0 Update incorrect mitre tags 2022-10-06 00:35:40 +02:00
Florian Roth adfb7d58e8 Merge pull request #3563 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG pattern
2022-10-06 00:10:32 +02:00
Florian Roth d2777f4d02 refactor: JuicyPotatoNG pattern 2022-10-06 00:00:46 +02:00
Nasreddine Bencherchali 2c26614ce4 Update Wildcard + Int to Str fields 2022-10-05 23:15:20 +02:00
Tim Shelton f65e795e22 FP: ignore amazon aws ec2 scripts 2022-10-05 19:40:37 +00:00
Nasreddine Bencherchali 68937161a0 Add GMER + PCHunter 2022-10-05 12:04:11 +02:00
Nasreddine Bencherchali 40dcb9a4c9 Update + Rename 2022-10-05 10:42:29 +02:00
Nasreddine Bencherchali 2ecf9ec7e1 Updates 2022-10-04 20:57:11 +02:00
Florian Roth ef0e5c76a5 Merge pull request #3557 from SigmaHQ/rule-devel
fix: wrong condition in whoami rule
2022-10-04 16:23:04 +02:00
Florian Roth eee1d2c1cb fix: wrong condition in whoami rule
https://github.com/SigmaHQ/sigma/issues/3556
2022-10-04 16:11:03 +02:00
Florian Roth 029900c284 Merge pull request #3548 from aaronherman/patch-1
Update description typo on "Phishing Pattern ISO in Archive"
2022-10-03 19:55:13 +02:00
securepeacock 161c8e6c2c Update proc_creation_win_lolbins_by_office_applications.yml
Adding msidb.exe references are below.
https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
2022-10-03 11:56:06 -04:00
frack113 5bd9dd76aa Redcannary rules 2022-10-02 11:34:33 +02:00
Florian Roth 93004a3fd5 Update proc_creation_win_archiver_iso_phishing.yml 2022-10-02 10:21:04 +02:00
Aaron Herman 580360b540 Update description typo 2022-10-01 10:52:35 -05:00
Florian Roth 65f531fb30 rule: Exchange Exploitation 2022-10-01 16:08:27 +02:00
Nasreddine Bencherchali 7880e3a2b6 Fix FP
Make the FP fix more broad to cover more future cases
2022-09-29 22:29:47 +02:00
Nasreddine Bencherchali bfc1d6a5b7 Create proc_creation_win_hh_chm_http.yml 2022-09-29 22:06:11 +02:00
Nasreddine Bencherchali 47dbe6081d Update proc_creation_win_susp_conhost.yml 2022-09-29 12:15:10 +02:00
Florian Roth a888ecb8b8 Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
2022-09-29 11:01:29 +02:00
Florian Roth 428cb6ab74 Merge pull request #3538 from SigmaHQ/rule-devel
fix: filter definition in userinit rule
2022-09-28 17:26:34 +02:00
Florian Roth a563422c82 fix: filter definition in userinit rule 2022-09-28 17:08:23 +02:00
Nasreddine Bencherchali 4a5dcf8586 Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-09-28 13:37:42 +02:00
Nasreddine Bencherchali 69b31b19b1 Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-09-28 13:37:36 +02:00
Florian Roth 5391a5cab4 changed casing, increased level 2022-09-28 13:28:53 +02:00