Commit Graph

1734 Commits

Author SHA1 Message Date
Florian Roth 5d039dd138 rule: Cobalt Strike patterns 2021-07-27 11:24:40 +02:00
Florian Roth 21c4d241a1 HiveNightmare and Relay attack tools adjustments 2021-07-26 10:59:35 +02:00
Florian Roth ae80f747ae fix: adding experimental status 2021-07-24 12:34:33 +02:00
Florian Roth 3eb37c014c rule: Impacket tools and Relay attack tools 2021-07-24 11:08:35 +02:00
Florian Roth ddb4744613 regsvr32 anomaly rule update
https://twitter.com/BlackMatter23/status/1417545425297580045
2021-07-20 21:14:48 +02:00
Florian Roth 66aaa2210c refactor: widened PS1 Empire cmdlines rule 2021-07-20 11:26:22 +02:00
Florian Roth b7b4c4555f fix: bug in regsvr anomaly rule 2021-07-18 12:59:31 +02:00
Florian Roth 53c25969ab added more legitimate extensions to regsvr32 rule 2021-07-17 11:20:05 +02:00
Florian Roth b911175f28 Suspicious mshta patterns 2021-07-17 09:04:41 +02:00
Florian Roth 6c79115ce0 Regsvr32 Anomalies extended 2021-07-17 09:04:31 +02:00
Florian Roth 021f211c14 fix: FP with WCE and Windows Cluster Service 2021-07-15 12:09:28 +02:00
Florian Roth e516aecc74 fix: error in selector 2021-07-14 15:58:55 +02:00
Florian Roth 530e04faec rule: Script Execution from Temp Folder 2021-07-14 15:52:52 +02:00
Florian Roth 0d794357e8 rule: reg disable security services 2021-07-14 15:52:35 +02:00
Florian Roth 04370c7e91 refactor: improved Raccine uninstall rule 2021-07-14 09:56:35 +02:00
Florian Roth e0f166aba2 rule: Serv-U exploitation
https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/
2021-07-14 08:35:25 +02:00
Florian Roth 25dec8a17b Merge pull request #1649 from leegengyu/patch-9
Update win_apt_apt29_thinktanks.yml - Links
2021-07-07 18:10:27 +02:00
Florian Roth c3c152d457 Merge pull request #1652 from SigmaHQ/rule-devel
refactor: changed cmdkey rule
2021-07-07 18:09:44 +02:00
frack113 8a96aa7855 Add 2 defense-evasion T1562.001 rules 2021-07-07 15:43:55 +02:00
Florian Roth 0c7661e8bc refactor: changed cmdkey rule 2021-07-07 14:45:03 +02:00
G Y 1adac5b036 Update win_apt_apt29_thinktanks.yml - Links
Reference links updated with grammar corrections.
2021-07-07 20:21:41 +08:00
frack113 bb970de5b7 fix invalid fields name 2021-07-07 09:05:00 +02:00
Florian Roth ff0f1a0222 Merge pull request #1633 from leegengyu/art_convert_yaml_to_md
Convert ART reference links from .yaml to .md
2021-07-06 13:39:37 +02:00
leegengyu 1f19f79da9 Convert ART reference links from .yaml to .md 2021-07-06 17:56:38 +08:00
Florian Roth 705415c2bd Merge pull request #1632 from frack113/process_creation_OriginalFileName
change OriginalFilename case
2021-07-06 11:45:21 +02:00
leegengyu 69d5d9734d Updated ART reference links from .yaml 2021-07-06 17:39:25 +08:00
leegengyu 5eb9547d5b Updated ART reference links from .yaml to .md and sub-technique links. 2021-07-06 17:30:57 +08:00
leegengyu 7557732ca2 Updated ART reference links from .yaml to .md and sub-technique links. 2021-07-06 17:21:22 +08:00
frack113 cfccdea28e change OriginalFilename case 2021-07-06 10:09:47 +02:00
frack113 9c94cf42fe childimage do not exist in sysmon schema 2021-07-06 09:26:43 +02:00
Florian Roth 8069b53e5e Merge pull request #1625 from SigmaHQ/rule-devel
Kaseya patterns, PrinterNightmare Mimikatz update
2021-07-05 13:29:23 +02:00
Florian Roth 7fab22ddc2 rule: more Kaseya patterns 2021-07-05 12:03:35 +02:00
Florian Roth a02b7a2390 Merge pull request #1617 from SigmaHQ/rule-devel
rule: REvil Kaseya patterns
2021-07-03 17:32:18 +02:00
Florian Roth 1d82ac50e4 refactor: additional pattern, extended description 2021-07-03 17:03:40 +02:00
Florian Roth 57b816f49d rule: REvil Kaseya patterns 2021-07-03 16:34:02 +02:00
frack113 02100f1a3c Tune detection in win_renamed_powershell.yml 2021-07-03 15:18:01 +02:00
frack113 895a2f6154 fix 3 times the same name file 2021-07-02 11:01:07 +02:00
Florian Roth 9899dd9b82 Merge pull request #1579 from frack113/fix_pr_1022
Fix file from PR 1022
2021-06-29 12:51:08 +02:00
Florian Roth 863941bff5 Merge pull request #1586 from BlackB0lt/patch-7
Update sysmon_rclone_execution.yml
2021-06-29 12:46:24 +02:00
Florian Roth 1425ede905 Merge pull request #1588 from SigmaHQ/rule-devel
CVE-2021-1675 Print Spooler Exploitation
2021-06-29 12:31:37 +02:00
Sittikorn S 56004fc49b Update sysmon_rclone_execution.yml
Add RClone Command that used by DarkSide malware
2021-06-29 13:44:03 +07:00
Florian Roth 9e3caf4ceb refactor: non-interactive Powershell to "low" 2021-06-28 16:38:34 +02:00
Florian Roth f4ac416ef4 Merge pull request #1582 from SigmaHQ/rule-devel
Rule devel
2021-06-28 11:36:21 +02:00
Florian Roth d1f1e8e7c4 rule: reg add run key 2021-06-28 09:39:12 +02:00
Florian Roth ab0502f893 refactor: add wscript.exe to mshta rule 2021-06-28 09:39:04 +02:00
Florian Roth d48009748f rule: mshta shell spawn 2021-06-28 09:32:28 +02:00
Florian Roth e7d9f1b427 Merge pull request #1577 from austinsonger/master
Update win_susp_disable_eventlog.yml
2021-06-28 08:46:17 +02:00
Florian Roth faf5e4a514 Update win_run_virtualbox.yml 2021-06-28 08:42:09 +02:00
Austin Songer 8e6ab7fd79 Update win_susp_disable_eventlog.yml 2021-06-28 00:59:53 -05:00
Austin Songer bfe969f071 Update win_susp_disable_eventlog.yml 2021-06-28 00:53:52 -05:00