root
|
01c4c7cdbd
|
modifed win_susp_msoffice.yml
|
2019-10-26 08:11:09 +02:00 |
|
root
|
bea2daac45
|
modifed win_susp_msoffice.yml
|
2019-10-26 07:55:44 +02:00 |
|
root
|
fc7f8ecea3
|
add win_susp_msoffice.yml
|
2019-10-26 07:48:38 +02:00 |
|
root
|
611c193826
|
modifed win_susp_odbcconf.yml
|
2019-10-26 07:45:53 +02:00 |
|
Thomas Patzke
|
30948b9c1a
|
Added sigma-similarity tool
Fixed also bug in backend base class that was triggered by the way
backends are used by this tool.
|
2019-10-25 21:59:03 +02:00 |
|
root
|
aa9a22e662
|
add win_susp_odbcconf.yml
|
2019-10-25 19:02:17 +02:00 |
|
alexpetrov12
|
8c2b7e9f85
|
fix
|
2019-10-25 18:30:40 +03:00 |
|
alexpetrov12
|
7aa804fe90
|
added new rules
Packet capture Windows command prompt, ODBCCONF execution dll, Windows Registry Persistence - COM key linking
|
2019-10-25 18:01:36 +03:00 |
|
zinint
|
6e94e798be
|
t1010
|
2019-10-25 16:12:51 +03:00 |
|
zinint
|
aef5fa3c2b
|
Rename powershell_winlogon_helper_dll.yaml to powershell_winlogon_helper_dll.yml
|
2019-10-24 16:37:38 +03:00 |
|
Florian Roth
|
a5ec6722a1
|
rule: the actual changes to hwp rule
|
2019-10-24 15:35:13 +02:00 |
|
zinint
|
5a98fdbbbd
|
ART t1004
|
2019-10-24 16:33:29 +03:00 |
|
zinint
|
317e9d3df9
|
PS Data Compressed attack.t1002
PS Data Compressed attack.t1002
|
2019-10-24 15:43:46 +03:00 |
|
zinint
|
7c5dc0ca01
|
Update win_data_compressed.yml
|
2019-10-24 15:34:13 +03:00 |
|
Florian Roth
|
86c1b4ae4b
|
rule: hwp exploits
|
2019-10-24 11:46:56 +02:00 |
|
alexpetrov12
|
cc998aa667
|
fix
|
2019-10-24 00:48:43 +03:00 |
|
alexpetrov12
|
f1ccf296f4
|
fix
|
2019-10-24 00:40:58 +03:00 |
|
alexpetrov12
|
d3715a508b
|
fix
|
2019-10-23 18:15:46 +03:00 |
|
alexpetrov12
|
4c84412944
|
added new rule
silenttrinity_stage_ use, sysmon_mimikatz_сreds_dump, sysmon_registry_persistence_key_linking, sysmon_сreds_dump
|
2019-10-23 18:08:30 +03:00 |
|
alexpetrov12
|
bc943343df
|
update win_sysmon_driver_unload
|
2019-10-23 15:41:14 +03:00 |
|
alexpetrov12
|
215e500894
|
fix
|
2019-10-23 14:43:01 +03:00 |
|
alexpetrov12
|
193c95a11a
|
add new rule1
|
2019-10-23 14:27:52 +03:00 |
|
root
|
edcbc49ce8
|
add rule win_susp_open with_execution.yml win_susp_devt oolslauncher_execution.yml
|
2019-10-23 13:00:21 +02:00 |
|
alexpetrov12
|
043e3f7ca6
|
fix
|
2019-10-23 13:48:44 +03:00 |
|
alexpetrov12
|
e38540a37f
|
fix
|
2019-10-23 13:28:04 +03:00 |
|
alexpetrov12
|
c1cfbacd24
|
fix
|
2019-10-23 13:18:57 +03:00 |
|
alexpetrov12
|
ad9b98541c
|
fix
|
2019-10-23 13:05:38 +03:00 |
|
alexpetrov12
|
fa4a8c974d
|
fix
|
2019-10-23 12:45:06 +03:00 |
|
alexpetrov12
|
f4ea01217e
|
fix
|
2019-10-23 02:47:04 +03:00 |
|
alexpetrov12
|
ebe4fe0377
|
fix
|
2019-10-23 02:42:37 +03:00 |
|
alexpetrov12
|
29cd7fed3e
|
fix
|
2019-10-23 02:39:40 +03:00 |
|
alexpetrov12
|
5a260db459
|
fix
|
2019-10-23 02:27:14 +03:00 |
|
alexpetrov12
|
6c4f4ce309
|
fix
|
2019-10-23 02:25:04 +03:00 |
|
alexpetrov12
|
8d0c89b598
|
added new rules
add rule MiniDumpWriteDump via COM+, renamed_binary_description, cobalt_execute_assembly, win_sysmon_driver_onload
|
2019-10-23 01:55:03 +03:00 |
|
Florian Roth
|
3d4ce9d175
|
rule: another reference link for 'execution by ordinal'
|
2019-10-22 15:18:19 +02:00 |
|
zinint
|
49f9b797a7
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 15:20:15 +03:00 |
|
zinint
|
a8bd2c8e78
|
Update win_data_compressed.yml
|
2019-10-22 14:57:53 +03:00 |
|
zinint
|
74d1fef8b8
|
Update win_data_compressed.yml
|
2019-10-22 14:53:43 +03:00 |
|
zinint
|
cc6d4b05ac
|
OSCD Task 7 : ART T1002 Exfiltration With Rar
OSCD Task 7 : ART T1002 Compress Data for Exfiltration With Rar
|
2019-10-22 14:00:52 +03:00 |
|
Florian Roth
|
b3654947bc
|
rule: suspicious call by ordinal (rundll32)
|
2019-10-22 12:40:26 +02:00 |
|
Florian Roth
|
0f02f2bdfc
|
rule: adjusted very noisy rule on AppLocker whitelist bypass
|
2019-10-22 12:32:37 +02:00 |
|
root
|
00a757959e
|
add rule win_susp_capture_screenshots.yml
|
2019-10-22 06:06:07 +02:00 |
|
root
|
2bd9d8a9d8
|
add rule sysmon_webshell_creation_detect.yml
|
2019-10-22 05:56:37 +02:00 |
|
root
|
fb53855ae5
|
add rule sysmon_webshell_creation_detect.yml
|
2019-10-22 05:50:49 +02:00 |
|
zinint
|
daf1034621
|
Update win_possible_applocker_bypass.yml
|
2019-10-22 00:54:29 +03:00 |
|
zinint
|
789782ef59
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 00:08:46 +03:00 |
|
zinint
|
56f807cb44
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 00:06:54 +03:00 |
|
zinint
|
0d8eff0d86
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 00:06:10 +03:00 |
|
zinint
|
a1d72f20c8
|
Update sysmon_xsl_script_processing.yml
|
2019-10-21 23:51:39 +03:00 |
|
zinint
|
5248f83fb3
|
Update sysmon_xsl_script_processing.yml
|
2019-10-21 23:46:11 +03:00 |
|