github-actions[bot]
9367349016
Merge PR #5101 from @nasbench - Promote older rules status from experimental to test
...
chore: promote older rules status from experimental to test
Co-authored-by: nasbench <nasbench@users.noreply.github.com >
2024-12-01 13:40:32 +01:00
Nasreddine Bencherchali
598d29f811
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
...
chore: change tags, date, modified fields to comply with v2 of the Sigma spec.
chore: update the related type from `obsoletes` to `obsolete`.
chore: update local json schema to the latest version.
2024-08-12 12:02:50 +02:00
Bryan Lim
24b9ed72c1
Merge PR #4621 from @zestsg - Add New GCP / Google Workspace Related Rules
...
new: GCP Break-glass Container Workload Deployed
new: Google Workspace Application Access Levels Modified
new: GCP Access Policy Deleted
---------
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com >
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com >
2024-01-12 12:49:02 +01:00
frack113
020fc8061f
Merge PR #4479 From @frack113 - Upgrade Rules Status
...
chore: Upgrade status level from `experimental` to `test` for rules that have not changed in 300 days
---------
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2023-10-17 14:35:26 +02:00
Nasreddine Bencherchali
7364ce00b1
Merge PR #4476 from @nasbench - re-organize cloud folder and other things
...
fix: Azure Active Directory Hybrid Health AD FS New Server - Update Logsource to align with the rest of the azure rules
fix: Azure Active Directory Hybrid Health AD FS Service Delete - Update Logsource to align with the rest of the azure rules
fix: Number Of Resource Creation Or Deployment Activities - Update Logsource to align with the rest of the azure rules
fix: Granting Of Permissions To An Account - Update Logsource to align with the rest of the azure rules
fix: Rare Subscription-level Operations In Azure - Update Logsource to align with the rest of the azure rules
fix: Google Workspace Application Removed - Update logsource product field to `gcp`
fix: Google Workspace Granted Domain API Access - Update logsource product field to `gcp`
fix: Google Workspace MFA Disabled - Update logsource product field to `gcp`
fix: Google Workspace Role Modified or Deleted - Update logsource product field to `gcp`
fix: Google Workspace Role Privilege Deleted - Update logsource product field to `gcp`
fix: Google Workspace User Granted Admin Privileges - Update logsource product field to `gcp`
2023-10-12 13:32:24 +02:00
frack113
7060db3d47
Promotion rules ( #3821 )
...
* Promotion rules
* fix missing null
* fix: modified date
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com >
2022-12-27 12:29:10 +01:00
frack113
646351808e
Refractor ( #3794 )
...
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com >
2022-12-18 21:00:14 +01:00
frack113
556dd8f400
Order yaml field
2022-10-25 07:34:10 +02:00
frack113
931fb30853
old experimental rule promotion
2022-10-09 16:54:04 +02:00
David ANDRE
0b0190ccb1
Added quotes to strings
2022-09-01 15:22:26 +02:00
phantinuss
112b715dd6
chore: test rules: reactivate single value list check
2022-05-10 17:13:04 +02:00
phantinuss
7cbfc7f16a
fix: remove . from title
2022-04-06 17:04:10 +02:00
Austin Songer
2f42753b6c
Update gcp_kubernetes_admission_controller.yml
2021-11-26 10:35:04 -06:00
Austin Songer
2c271f5be8
Update gcp_kubernetes_admission_controller.yml
2021-11-26 10:32:11 -06:00
Austin Songer
60743f75da
Update gcp_kubernetes_admission_controller.yml
2021-11-26 10:31:33 -06:00
frack113
34626e41de
Update gcp_kubernetes_admission_controller.yml
2021-11-25 09:11:09 +01:00
Austin Songer
0873483e25
Update gcp_kubernetes_admission_controller.yml
2021-11-25 00:14:52 -06:00
Austin Songer
9a5f3b415e
Update gcp_kubernetes_admission_controller.yml
2021-11-25 00:06:36 -06:00
Austin Songer
f54b618cd4
Update gcp_kubernetes_admission_controller.yml
2021-11-25 00:05:54 -06:00
Austin Songer
8d50ab9e5f
Create gcp_kubernetes_admission_controller.yml
2021-11-24 23:53:57 -06:00
Austin Songer
5c118eef46
Create gcp_kubernetes_cronjob.yml
2021-11-22 22:39:39 -06:00
frack113
7dfd6b1417
Add gcp product
2021-11-14 10:54:14 +01:00
austinsonger
7fc1c50901
gcp_sql_database_modified_or_deleted.yml
2021-10-15 18:53:45 -05:00
frack113
3c906b52a0
fix filename
2021-09-22 16:21:07 +02:00
Austin Songer
842ade16be
Forgot to add my username to some of the rules.
2021-08-20 02:09:31 +00:00
Austin Songer
36406d5781
Fixed Spelling
2021-08-18 18:53:28 +00:00
frack113
2521ae2ed1
Merge pull request #1859 from austinsonger/gcp_vpn_tunnel_modified_or_deleted.yml
...
gcp_vpn_tunnel_modified_or_deleted.yml
2021-08-17 06:24:49 +02:00
Austin Songer
c7831a3d70
Update gcp_vpn_tunnel_modified_or_deleted.yml
2021-08-16 09:45:31 -05:00
frack113
c57ded1ecd
Merge pull request #1852 from austinsonger/gcp_dns_zone_modified_or_deleted.yml
...
gcp_dns_zone_modified_or_deleted.yml
2021-08-16 07:37:28 +02:00
frack113
37b8040e76
cleanup gcp_dlp_re-identifies_sensitive_information
...
Remove list with only 1 value
2021-08-16 06:28:40 +02:00
Austin Songer
ae12f1f328
Update gcp_dlp_re-identifies_sensitive_information.yml
2021-08-15 22:57:54 -05:00
Austin Songer
85dc62070b
Update gcp_dlp_re-identifies_sensitive_information.yml
2021-08-15 16:02:12 -05:00
Austin Songer
219be99847
Update gcp_dns_zone_modified_or_deleted.yml
2021-08-15 16:02:04 -05:00
Austin Songer
e4314aa4b8
Update gcp_dns_zone_modified_or_deleted.yml
2021-08-15 16:01:10 -05:00
Austin Songer
3c770c6e4d
Update gcp_dlp_re-identifies_sensitive_information.yml
2021-08-15 15:55:46 -05:00
Austin Songer
a37ec60f76
Update gcp_dlp_re-identifies_sensitive_information.yml
2021-08-15 15:44:20 -05:00
Austin Songer
dae3d3b446
Update gcp_dlp_re-identifies_sensitive_information.yml
2021-08-15 15:42:15 -05:00
Austin Songer
3d332b8171
Create gcp_vpn_tunnel_modified_or_deleted.yml
2021-08-15 14:37:08 -05:00
Austin Songer
7605795a9f
Create gcp_dns_zone_modified_or_deleted.yml
2021-08-15 14:30:23 -05:00
Austin Songer
ba8e9c9fcb
Create gcp_dlp_re-identifies_sensitive_information.yml
2021-08-15 14:28:10 -05:00
frack113
5390ff85c7
Merge pull request #1846 from austinsonger/gcp_service_account_modified.yml
...
gcp_service_account_modified.yml
2021-08-15 08:34:47 +02:00
frack113
17fa9f87cc
Merge pull request #1847 from austinsonger/gcp_service_account_disabled_or_deleted.yml
...
gcp_service_account_disabled_or_deleted.yml
2021-08-15 08:30:57 +02:00
frack113
39fe9c4525
Merge pull request #1840 from austinsonger/gcp_firewall_rule_modified_or_deleted.yml
...
gcp_firewall_rule_modified_or_deleted.yml
2021-08-15 08:09:04 +02:00
frack113
88e8fea1b7
Merge pull request #1841 from austinsonger/gcp_full_network_traffic_packet_capture.yml
...
gcp_full_network_traffic_packet_capture.yml
2021-08-15 08:08:53 +02:00
frack113
f34c3ef9fd
remove disable as in another rule
2021-08-15 08:08:16 +02:00
frack113
d940417e58
fix error
2021-08-15 08:05:03 +02:00
frack113
db3eda51dd
fix errors
2021-08-15 08:02:51 +02:00
frack113
5d22d3ea19
Merge pull request #1848 from austinsonger/gcp_bucket_enumeration.yml
...
gcp_bucket_enumeration.yml
2021-08-15 07:52:15 +02:00
Austin Songer
3e151410ca
Update gcp_service_account_modified.yml
2021-08-14 22:31:47 -05:00
Austin Songer
552e1544e4
Update gcp_service_account_modified.yml
2021-08-14 22:30:10 -05:00