Florian Roth
cb55ed9f93
Merge pull request #3496 from krestinichev/add-new-rule
...
Add new rule: proc_creation_disable_SEP
2022-09-16 10:37:02 +02:00
Florian Roth
c2256845b2
refactor: renamed and changed title
2022-09-16 09:45:56 +02:00
Florian Roth
b4376ea580
refactor: CRLF to LF
2022-09-16 09:22:21 +02:00
Florian Roth
6d9d08e1de
Update proc_creation_disable_SEP.yml
2022-09-16 09:18:27 +02:00
Florian Roth
67072ecc91
Merge pull request #3488 from frack113/redcannary_20220910
...
Add posh_ps_disable_windowsoptionalfeature
2022-09-16 09:13:16 +02:00
frack113
c4d2ed0478
Merge pull request #3497 from bornatalebi/master
...
New Rule: Windows DNS Client Rule command
2022-09-16 06:33:41 +02:00
frack113
c1293c3365
Merge pull request #3495 from nasbench/nasbench-rule-devel
...
Rule Dev (Updates)
2022-09-16 06:32:53 +02:00
Borna Talebi
2af0431efa
Change Title
2022-09-16 00:53:55 +04:30
Borna Talebi
b984d52c65
Fixing conditions
2022-09-16 00:32:47 +04:30
Borna Talebi
0e7085bee5
Update posh_ps_add_dnsclient_rule.yml
2022-09-14 23:23:58 +04:30
Borna Talebi
227c2f6bb9
Update posh_ps_add_dnsclient_rule.yml
2022-09-14 23:11:52 +04:30
Borna Talebi
d078d47360
New Rule: Windows DNS Client Rule
2022-09-14 22:32:35 +04:30
nasreddine.bencherchali@nextron-systems.com
eb4247fdb4
Add missing modified field
2022-09-14 15:03:50 +02:00
krestinichev
02cfd972ed
Add files via upload
2022-09-14 15:37:51 +03:00
nasreddine.bencherchali@nextron-systems.com
653ad66f21
Updates
2022-09-14 12:29:57 +02:00
Nasreddine Bencherchali
fb44c6fa87
Update meta info
2022-09-13 22:14:45 +02:00
phantinuss
2ed0605dc4
Revert "Revert "Merge branch 'master' of github.com:elhoim/sigma""
...
This reverts commit 6c1761a7b7 .
2022-09-13 15:52:07 +02:00
Florian Roth
67bca96744
fix: wrong image selection
2022-09-13 13:13:16 +02:00
Qasim Qlf
3b4fc8c3fd
VS Code Filter Fix - Undo the last commit
...
Previous Filter of Image was wrong. Image can't endsWith (Code.exe and attrib.exe) at the same time. Same condition with other scenario.
CommandLine filter is good.
2022-09-13 16:02:17 +05:00
Nasreddine Bencherchali
8a504bee9e
Add %tmp% env variable
2022-09-13 10:49:14 +02:00
nasreddine.bencherchali@nextron-systems.com
6fa682b619
Create posh_ps_susp_clear_eventlog.yml
2022-09-13 10:02:36 +02:00
nasreddine.bencherchali@nextron-systems.com
0caeaaa122
Update rules
2022-09-13 10:02:32 +02:00
Florian Roth
d0286e210e
Merge pull request #3492 from SigmaHQ/rule-devel
...
Rule devel
2022-09-13 08:50:37 +02:00
Florian Roth
2d7e545cad
fix: list with one element
2022-09-13 08:38:57 +02:00
Florian Roth
c22974205f
Merge branch 'master' into rule-devel
2022-09-13 08:07:35 +02:00
Florian Roth
72aa55f1c7
Merge branch 'master' into aurora-false-positive-fixing
2022-09-13 08:07:26 +02:00
Florian Roth
61422ca237
rule: UAC Bypass via ICMLuaUtil
2022-09-13 08:07:15 +02:00
Florian Roth
072a9d73eb
fix: changes to existing rules
2022-09-13 08:07:03 +02:00
Florian Roth
5f164ebe12
style: indentation
2022-09-12 13:30:14 +02:00
Florian Roth
0bbb679e38
fix: FPs with veam backup shell
2022-09-12 13:29:51 +02:00
Qasim Qlf
1eaad811b6
tag added
2022-09-12 14:15:48 +05:00
frack113
f4da079d13
Add posh_ps_enable_windowsoptionalfeature
2022-09-11 19:43:54 +02:00
frack113
51076b2078
Update posh_ps_disable_windowsoptionalfeature.yml
2022-09-11 19:29:15 +02:00
Florian Roth
a5fe285776
fix: too many FPs during Windows update - User empty
2022-09-11 16:28:04 +02:00
David André
93da67b593
Update proc_creation_win_renamed_vmnat.yml
...
Added accidentaly removed falsepositives
2022-09-11 13:13:58 +02:00
David André
262f046351
Delete image_load_vmware_nondefault_path.yml
...
File added in wrong branch
2022-09-11 13:07:23 +02:00
David André
5656a3a50b
Merge branch 'SigmaHQ:master' into add_renamed_vmnat
2022-09-11 13:06:21 +02:00
David ANDRE
5b0c8f60e2
Removed trailing space
2022-09-11 12:36:44 +02:00
David ANDRE
c98997390b
Changes following advice
2022-09-11 12:35:05 +02:00
frack113
5996fbf4c9
Fix tag
2022-09-10 19:23:58 +02:00
frack113
486fdabe34
Add posh_ps_disable_windowsoptionalfeature
2022-09-10 19:15:36 +02:00
frack113
6e529bb9c8
Merge pull request #3484 from elhoim/add_samtheadmin
...
Add rule to detect samtheadmin computer name used by hacktool
2022-09-10 12:34:51 +02:00
frack113
21435629a0
Merge pull request #3482 from nasbench/nasbench-rule-devel
...
Rule Devel (New+Update)
2022-09-10 12:34:26 +02:00
Florian Roth
e7084eee04
Merge pull request #3487 from SigmaHQ/aurora-false-positive-fixing
...
fix: fixing multiple FPs with the use of VSCode
2022-09-10 12:07:01 +02:00
Florian Roth
0a5cfb93b3
fix: condition
2022-09-10 11:53:42 +02:00
Florian Roth
7dbdd4d1c6
fix: fixing multiple FPs with the use of VSCode
2022-09-10 11:42:44 +02:00
Florian Roth
a053be791c
Update proc_creation_win_user_discovery_get_aduser.yml
2022-09-10 09:49:14 +02:00
Florian Roth
a616647b08
lowered score of scheduled task + SYSTEM rule
2022-09-10 09:48:50 +02:00
Florian Roth
9ed14ce571
tightened the regular expression
2022-09-10 09:34:16 +02:00
Nasreddine Bencherchali
2552b75e72
Delete proc_creation_win_net_add_local_user.yml
2022-09-09 23:11:28 +02:00