Swachchhanda Shrawan Poudel
889b07d952
Merge PR #5943 from @swachchhanda000 - Add regression test count mismatch finder
...
chore: regression test count mismatch finder
2026-04-20 14:38:44 +02:00
github-actions[bot]
37fe8969ae
Merge PR #5890 from @nasbench - chore: archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2026-03-02 13:42:54 +01:00
github-actions[bot]
1df103ce6d
Merge PR #5852 from @nasbench - Open Archive New Rule References
...
chore: archive new rule references and update cache file
-----
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com >
2026-02-10 14:48:39 +05:45
Swachchhanda Shrawan Poudel
478120e7d2
Merge PR #5814 from @swachchhanda000 - Add New Credential Guard Tampering Rules
...
Goodlog Tests / check-baseline-win7 (push) Waiting to run
Goodlog Tests / check-baseline-win10 (push) Waiting to run
Goodlog Tests / check-baseline-win11 (push) Waiting to run
Goodlog Tests / check-baseline-win11-2023 (push) Waiting to run
Goodlog Tests / check-baseline-win2022 (push) Waiting to run
Goodlog Tests / check-baseline-win2022-domain-controller (push) Waiting to run
Goodlog Tests / check-baseline-win2022-0-20348-azure (push) Waiting to run
Regression Tests / true-positive-tests (push) Waiting to run
Create Release / Create Release (push) Waiting to run
Sigma Rule Tests / yamllint (push) Waiting to run
Sigma Rule Tests / test-sigma-logsource (push) Blocked by required conditions
Sigma Rule Tests / test-sigma-legacy (push) Blocked by required conditions
Sigma Rule Tests / sigma-check (push) Blocked by required conditions
Sigma Rule Tests / duplicate-id-check (push) Blocked by required conditions
Validate Sigma rules / sigma-rules-validator (push) Waiting to run
new: Windows Credential Guard Registry Tampering Via CommandLine
new: Windows Credential Guard Related Registry Value Deleted - Registry
new: Windows Credential Guard Disabled - Registry
---------
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com >
2026-01-29 12:52:08 +01:00
Swachchhanda Shrawan Poudel
a4ddc7a414
Merge PR #5842 from @swachchhanda000 - chore: update thor.yml with missing file_change category
...
chore: update thor.yml with missing file_change category
2026-01-29 09:25:27 +01:00
Swachchhanda Shrawan Poudel
77f4b0b2ec
Merge PR #5741 from @swachchhanda000 - Add Splunk Rules for MSIX/AppX
...
new: Successful MSIX/AppX Package Installation
new: Windows AppX Deployment Full Trust Package Installation
new: Windows AppX Deployment Unsigned Package Installation
new: Windows MSIX Package Support Framework AI_STUBS Execution
---------
Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com >
2026-01-24 17:04:41 +01:00
github-actions[bot]
e443d5cbf8
Merge PR #5839 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2026-01-17 13:03:58 +01:00
github-actions[bot]
8afdcc4321
Merge PR #5821 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2026-01-01 12:22:51 +01:00
github-actions[bot]
6d581764e7
Merge PR #5806 from @nasbench - Archive New Rule References
...
chore: archive new rule references and update cache file
---------
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-12-15 16:42:14 +01:00
Swachchhanda Shrawan Poudel
6af6ad8ef7
Merge PR #5803 from @swachchhanda000 - chore: ci: regression test id consistency check
...
chore: ci: regression test id consistency check
---------
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
2025-12-10 09:57:22 +01:00
Nasreddine Bencherchali
5656c48a97
Merge PR #5793 from @nasbench - Rename Auditd Folder Entries and update SYSCALL field
...
chore: rename auditd folders and others
update: Audio Capture - Updated syscall field to SYSCALL in order to make use of enriched logs
update: ASLR Disabled Via Sysctl or Direct Syscall - Linux - Updated syscall field to SYSCALL in order to make use of enriched logs
update: Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
update: System Info Discovery via Sysinfo Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
update: Special File Creation via Mknod Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
update: Webshell Remote Command Execution - Updated syscall field to SYSCALL in order to make use of enriched logs
2025-12-08 16:03:55 +01:00
Swachchhanda Shrawan Poudel
3e9318e23f
Merge PR #5763 from @swachchhanda000 - Update ClickFix/FileFix related rules
...
removed: FileFix - Suspicious Child Process from Browser File Upload Abuse - Deprecated in favor of b5b29e4e-31fa-4fdf-b058-296e7a1aa0c2
new: DNS Query by Finger Utility
new: Network Connection Initiated via Finger.EXE
fix: Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix - Fix selection to use ParentImage instead of Image field
new: Suspicious FileFix Execution Pattern
update: FileFix - Command Evidence in TypedPaths - Added more markers
update: Potential ClickFix Execution Pattern - Registry - Add 2 new strings, "finger" and "identification"
chore: Update "test_rules.py" filename test with better output formatting
---------
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
Co-authored-by: nasbench <monsteroffire2@gmail.com >
2025-11-27 23:00:25 +01:00
Nasreddine Bencherchali
2cb7375c6b
Merge PR #5719 from @nasbench - Add regression test CI, data and simulation links
...
update: Cred Dump Tools Dropped Files - Add procdump.exe and procdump64a.exe
update: File Download From Browser Process Via Inline URL - Enhance selection by splitting CLI markers for better matching
update: Tor Client/Browser Execution - Add additional PE metadata markers
update: System Information Discovery via Registry Queries - Enhance registry markers
update: PUA - AdFind Suspicious Execution - Add -sc to dclist string for more accurate coverage.
fix: Removal Of Index Value to Hide Schedule Task - Registry - Remove EventType condition that broke the rule.
fix: Removal Of SD Value to Hide Schedule Task - Registry - Remove EventType condition that broke the rule.
fix: Creation of a Local Hidden User Account by Registry - Fix the TargetObject value
fix: Potential Persistence Via New AMSI Providers - Registry - Change logsource and fix the rule logic
fix: Potential COM Object Hijacking Via TreatAs Subkey - Registry - Change logsource and fix the rule logic
fix: Potential Persistence Via Logon Scripts - Registry - Fix incorrect logsource
fix: PUA - Sysinternal Tool Execution - Registry - Fix incorrect logsource
fix: Suspicious Execution Of Renamed Sysinternals Tools - Registry - Fix incorrect logsource
fix: PUA - Sysinternals Tools Execution - Registry - Fix incorrect logsource
chore: add CI script for regression
chore: add regression data
---------
Co-authored-by: swachchhanda000 <87493836+swachchhanda000@users.noreply.github.com >
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
2025-11-25 16:00:53 +01:00
Swachchhanda Shrawan Poudel
64ba98e044
Merge PR #5662 from @swachchhanda000 - Cisco ASA/FP SSL VPN Exploit (CVE-2025-20333 / CVE-2025-20362)
...
new: Cisco ASA/FP SSL VPN Exploit (CVE-2025-20333 / CVE-2025-20362) - Proxy
---------
Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com .>
2025-11-21 13:06:30 +05:45
github-actions[bot]
25710bbb76
Merge PR #5737 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-11-02 00:10:54 +01:00
InTheCyber
4dfbd6b713
Merge PR #5197 from @inthecyber - Add new Fortinet Fortigate rules
...
new: FortiGate - New Administrator Account Created
new: FortiGate - Firewall Address Object Added
new: FortiGate - New Firewall Policy Added
new: FortiGate - New Local User Created
new: FortiGate - New VPN SSL Web Portal Added
new: FortiGate - User Group Modified
new: FortiGate - VPN SSL Settings Modified
---------
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com >
Co-authored-by: Tommaso Tosi <tommaso.tosi@inthecyber.com >
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com >
2025-11-02 00:06:27 +01:00
Nasreddine Bencherchali
a77d3bae4b
Merge PR #5708 from @nasbench - Multiple updates and issue fixes
...
Goodlog Tests / check-baseline-win7 (push) Waiting to run
Goodlog Tests / check-baseline-win10 (push) Waiting to run
Goodlog Tests / check-baseline-win11 (push) Waiting to run
Goodlog Tests / check-baseline-win11-2023 (push) Waiting to run
Goodlog Tests / check-baseline-win2022 (push) Waiting to run
Goodlog Tests / check-baseline-win2022-domain-controller (push) Waiting to run
Goodlog Tests / check-baseline-win2022-0-20348-azure (push) Waiting to run
Create Release / Create Release (push) Waiting to run
Sigma Rule Tests / yamllint (push) Waiting to run
Sigma Rule Tests / test-sigma-logsource (push) Blocked by required conditions
Sigma Rule Tests / test-sigma-legacy (push) Blocked by required conditions
Sigma Rule Tests / sigma-check (push) Blocked by required conditions
Validate Sigma rules / sigma-rules-validator (push) Waiting to run
fix: Turla Group Commands May 2020 - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Dtrack RAT Activity - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Data Exfiltration Activity Via CommandLine Tools - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Suspicious Network Command - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Suspicious SYSTEM User Process Creation - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Snatch Ransomware Activity - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Devil Bait Malware Reconnaissance - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Mint Sandstorm - AsperaFaspex Suspicious Process Execution - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Mint Sandstorm - ManageEngine Suspicious Process Execution - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
update: Powershell Token Obfuscation - Powershell - Move to the TH folder in order to set the right FP expectations.
fix: Kerberoasting Activity - Initial Query - Fix issue with filter names and logic
chore: add sorting to the rule archiver script
---------
Thanks: KingKDot
Thanks: zambomarcell
Thanks: Koifman
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
2025-10-29 11:45:19 +01:00
mm-abdelghani
c470105fbf
Merge PR #5686 from @mm-abdelghani - Unsigned or Unencrypted SMB Connection to Share Established
...
new: Unsigned or Unencrypted SMB Connection to Share Established
---------
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
2025-10-23 13:43:15 +02:00
Swachchhanda Shrawan Poudel
d36fc36e08
Merge PR #5660 from @swachchhanda000 - feat: add rule to detect deletion of RunMRU registry key
...
new: RunMRU Registry Key Deletion
new: RunMRU Registry Key Deletion - Registry
---------
Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com >
2025-10-22 18:31:35 +05:45
Swachchhanda Shrawan Poudel
c2d9e95e83
Merge PR #5532 from @swachchhanda000 - fix: refine detections and filters; update Account Tampering with SubStatus field
...
fix: SMB Create Remote File Admin Share - filter out local IP
fix: Alternate PowerShell Hosts - PowerShell Module - filter out more legit powershell host
fix: CurrentVersion NT Autorun Keys Modification - filter svchost making legitimate registry change
fix: Potentially Suspicious Desktop Background Change Via Registry - filter EC2Launch.exe
update: Account Tampering - Suspicious Failed Logon Reasons - add SubStatus field
2025-10-17 08:12:25 +05:45
github-actions[bot]
b4c6facc1d
Merge PR #5693 from @nasbench - chore: archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-10-15 09:51:23 +02:00
github-actions[bot]
019971e1c9
Merge PR #5667 from @nasbench - chore: archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-10-01 10:01:54 +02:00
Andreas Braathen
35d80c39bd
Merge PR #5175 from @netgrain - Add WDAC Policy File Creation In CodeIntegrity Folder
...
new: WDAC Policy File Creation In CodeIntegrity Folder
---------
Co-authored-by: Andreas Braathen <andreasb@mnemonic.io >
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com >
2025-09-22 11:48:53 +02:00
github-actions[bot]
f76a82ddc9
Merge PR #5638 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-09-22 11:41:18 +02:00
github-actions[bot]
1751ef8673
Merge PR #5597 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-08-29 10:31:14 +02:00
phantinuss
4f4f468c4a
Merge PR #5557 from @phantinuss - Bump pySigma-validators-sigmahq to 0.10
...
chore: bump pySigma-validators-sigmahq to 0.10
2025-08-14 14:29:11 +02:00
github-actions[bot]
f9d2a493f9
Merge PR #5573 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-08-14 14:06:15 +02:00
github-actions[bot]
43304188c2
chore: archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-07-15 11:38:58 +02:00
github-actions[bot]
ff2c7bf284
Merge PR #5507 from @nasbench - archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-07-01 10:53:58 +02:00
github-actions[bot]
df556b9675
Merge PR #5480 from @phantinuss - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
2025-06-16 12:55:39 +02:00
Ariel Otilibili
a1c9827a35
Merge PR #5402 from @ariel-anieli - feat: add JSON output format for deprecated rule summary
...
chore: tests/deprecated_rules.py - add json output format
chore: add deprecated/deprecated.json
chore: update README and workflow job accordingly
---------
Signed-off-by: Ariel Otilibili <otilibil@eurecom.fr >
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
2025-06-13 10:59:34 +02:00
Swachchhanda Shrawan Poudel
73ce21b574
Merge PR #5416 from @swachchhanda000 - Detection of SAP NetViewer CVE-2025-31324 exploitation via webserver logs
...
new: Potential SAP NetViewer Webshell Command Execution
new: Potential Java WebShell Upload in SAP NetViewer Server
chore: unpin pySigma validator version
---------
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com >
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-06-11 11:28:24 +02:00
github-actions[bot]
f3948c7bdf
Merge PR #5449 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-06-02 13:29:26 +02:00
Swachchhanda Shrawan Poudel
5f894dfa0b
Merge PR #5431 from swachchhanda000 - chore: fix broken links
...
chore: fix broken links
2025-05-26 10:21:19 +02:00
github-actions[bot]
e9aa3eb2b3
Merge PR #5398 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-05-20 23:03:44 +02:00
phantinuss
e58ebd048f
chore: sort each block
2025-05-05 10:17:12 +02:00
phantinuss
9aeb2bab8a
chore: whitelist new test issues
...
the rules are all valid and have a sound detection logic
2025-05-05 10:17:02 +02:00
phantinuss
f47604b735
chore: update pySigma validators
2025-04-30 11:31:22 +02:00
github-actions[bot]
36394d43a0
Merge PR #5250 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-04-17 00:41:06 +02:00
github-actions[bot]
4a3cb8b774
Merge PR #5230 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-03-16 03:08:28 +01:00
frack113
3ce034bb20
Merge PR #4858 from @frack113 - Add summary csv file, workflow and generation script for deprecated rules
...
chore: add summary csv file, workflow and generation script for deprecated rules
---------
Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com >
2025-03-05 00:59:36 +01:00
github-actions[bot]
2b421e3fd7
Merge PR #5217 from @nasbench - Archive new rule references and update cache file
...
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-03-05 00:23:03 +01:00
github-actions[bot]
c0aa75845b
Merge PR #5194 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-02-17 12:04:58 +01:00
github-actions[bot]
1d8c84387f
Merge PR #5178 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-02-03 18:22:38 +01:00
github-actions[bot]
f3a3392bd2
Merge PR #5161 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-01-19 21:43:16 +01:00
github-actions[bot]
952d518f66
Merge PR #5150 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2025-01-06 15:35:53 +01:00
github-actions[bot]
0cb8e32d26
Merge PR #5130 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2024-12-16 13:42:23 +01:00
github-actions[bot]
4075c508d1
Merge PR #5101 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2024-12-01 13:39:50 +01:00
frack113
d804e9cba1
Merge PR #5088 from @frack113 - Remove custom dedicated hash fields from sigmac
...
update: GALLIUM IOCs - remove custom dedicated hash fields
update: Malicious DLL Load By Compromised 3CXDesktopApp - remove custom dedicated hash fields
update: Potential Compromised 3CXDesktopApp Execution - remove custom dedicated hash fields
update: HackTool Named File Stream Created - remove custom dedicated hash fields
update: PUA - Process Hacker Driver Load - remove custom dedicated hash fields
update: PUA - System Informer Driver Load - remove custom dedicated hash fields
update: Vulnerable HackSys Extreme Vulnerable Driver Load - remove custom dedicated hash fields
update: Vulnerable WinRing0 Driver Load - remove custom dedicated hash fields
update: WinDivert Driver Load - remove custom dedicated hash fields
update: HackTool - SharpEvtMute DLL Load - remove custom dedicated hash fields
update: HackTool - CoercedPotato Execution - remove custom dedicated hash fields
update: HackTool - CreateMiniDump Execution - remove custom dedicated hash fields
update: Hacktool Execution - Imphash - remove custom dedicated hash fields
update: HackTool - GMER Rootkit Detector and Remover Execution - remove custom dedicated hash fields
update: HackTool - HandleKatz LSASS Dumper Execution - remove custom dedicated hash fields
update: HackTool - Impersonate Execution - remove custom dedicated hash fields
update: HackTool - LocalPotato Execution - remove custom dedicated hash fields
update: HackTool - PCHunter Execution - remove custom dedicated hash fields
update: HackTool - PPID Spoofing SelectMyParent Tool Execution - remove custom dedicated hash fields
update: HackTool - Stracciatella Execution - remove custom dedicated hash fields
update: HackTool - SysmonEOP Execution - remove custom dedicated hash fields
update: HackTool - UACMe Akagi Execution - remove custom dedicated hash fields
update: HackTool - Windows Credential Editor (WCE) Execution - remove custom dedicated hash fields
update: MpiExec Lolbin - remove custom dedicated hash fields
update: PUA - Fast Reverse Proxy (FRP) Execution - remove custom dedicated hash fields
update: PUA- IOX Tunneling Tool Execution - remove custom dedicated hash fields
update: PUA - Nimgrab Execution - remove custom dedicated hash fields
update: PUA - NPS Tunneling Tool Execution - remove custom dedicated hash fields
update: PUA - Process Hacker Execution - remove custom dedicated hash fields
update: PUA - System Informer Execution - remove custom dedicated hash fields
update: Remote Access Tool - NetSupport Execution From Unusual Location - remove custom dedicated hash fields
update: Renamed AdFind Execution - remove custom dedicated hash fields
update: Renamed AutoIt Execution - remove custom dedicated hash fields
update: Renamed NetSupport RAT Execution - remove custom dedicated hash fields
update: Renamed PAExec Execution - remove custom dedicated hash fields
update: Potential SquiblyTwo Technique Execution - remove custom dedicated hash fields
---------
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2024-11-25 09:30:14 +01:00
github-actions[bot]
4ec3e69de0
Merge PR #5080 from @nasbench - Archive new rule references and update cache file
...
chore: archive new rule references and update cache file
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2024-11-17 23:44:45 +01:00