Commit Graph

7 Commits

Author SHA1 Message Date
frack113 6abf058185 Merge PR #4765 from @frack113 - Update additional rules to use the cidr modifier
update: Communication To Uncommon Destination Ports - Add link-local address range
update: Dfsvc.EXE Network Connection To Non-Local IPs - Update rule to use cidr modifier
update: Microsoft Sync Center Suspicious Network Connections - Add link-local address range
update: Network Connection Initiated By PowerShell Process - Update rule to use cidr modifier
update: Office Application Initiated Network Connection To Non-Local IP - Update rule to use cidr modifier
update: Outbound Network Connection To Public IP Via Winlogon - Add link-local address range
update: Potential CVE-2023-23397 Exploitation Attempt - SMB - Update rule to use cidr modifier
update: Potentially Suspicious Malware Callback Communication - Add link-local address range
update: Potentially Suspicious Wuauclt Network Connection - Update rule to use cidr modifier
update: Publicly Accessible RDP Service - Add link-local address range
update: RDP Over Reverse SSH Tunnel - Update rule to use cidr modifier
update: Rundll32 Internet Connection - Add link-local address range
update: Script Initiated Connection to Non-Local Network - Update rule to use cidr modifier
update: Search-ms and WebDAV Suspicious Indicators in URL - Add link-local address range
update: Search-ms and WebDAV Suspicious Indicators in URL - Add link-local address range
update: WebDav Put Request - Update rule to use cidr modifier

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2024-03-13 14:51:21 +01:00
phantinuss 188236a4eb Merge PR #4393 from @phantinuss - use explicit CIDR notation for loopback
fix: Search-ms and WebDAV Suspicious Indicators in URL - use explicit CIDR notation for loopback
2023-08-25 10:29:04 +02:00
phantinuss f9893202e5 fix: IPv6 prefix 2023-08-22 13:17:40 +02:00
phantinuss 24e7333f15 fix: typo 2023-08-22 11:43:04 +02:00
Nasreddine Bencherchali 89c6ea2ef0 Update rules/web/proxy_generic/proxy_webdav_search_ms.yml
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-08-22 11:42:08 +02:00
Nasreddine Bencherchali 201066947b feat: update detection & metadata 2023-08-22 11:00:55 +02:00
Micah Babinski 8d16ed2cc2 Added search(-ms)/WebDAV rules 2023-08-04 17:37:54 -07:00