Commit Graph

850 Commits

Author SHA1 Message Date
Yugoslavskiy Daniil d8a6048492 update /macos_create_hidden_account.yml 2020-10-16 02:05:22 +02:00
Alejandro Ortuno 2ef52dbfd8 Initial Sigma Rule 2020-10-14 10:24:59 +02:00
Alejandro Ortuno bf8426d71b Initial commit of sigma rule 2020-10-14 10:14:00 +02:00
Alejandro Ortuno 75a05db446 Add slash to bypass testing 2020-10-14 08:50:15 +02:00
remotephone@gmail.com 8e7fbbd147 fixing UUID and description 2020-10-14 00:54:51 -05:00
remotephone@gmail.com ed22c8e0fe adding macos screencapture rule 2020-10-14 00:51:55 -05:00
remotephone@gmail.com 8bbde90328 adding line at end of file 2020-10-14 00:05:28 -05:00
remotephone@gmail.com 3cddb86b70 updating tags 2020-10-14 00:01:30 -05:00
remotephone@gmail.com 7343936653 adding gui input capture, first iteration 2020-10-13 23:59:53 -05:00
remotephone@gmail.com df20d2a5d2 adding new line at end of file 2020-10-13 22:44:02 -05:00
remotephone@gmail.com 7e002fcb5f updating selections to make query more efficient and less prone to evasion 2020-10-13 22:17:26 -05:00
remotephone@gmail.com 56952ecdd4 updating to select commandline arguments correctly for macos rule, and cleaning up description across both rules 2020-10-13 22:09:37 -05:00
Alejandro Ortuno c03a696762 additional modifications on commands and process names 2020-10-13 11:00:06 +02:00
Alejandro Ortuno 50fde8c13f minor changes on command line 2020-10-13 10:55:29 +02:00
Alejandro Ortuno 30bd626d76 Split command line and do contains all. 2020-10-13 10:51:00 +02:00
Alejandro Ortuno 7459bcd08c Use process_creation for the detection 2020-10-13 10:41:50 +02:00
remotephone@gmail.com a85c19db17 updating files to cover broader network discovery logic, renaming alert, adding recommended changes 2020-10-13 00:39:53 -05:00
remotephone@gmail.com 7d49db3988 updating falsepositives documentation to remove line that's not applicable 2020-10-12 23:19:02 -05:00
remotephone@gmail.com 89c8a589a5 updating search syntax, splitting process name and cmdline and adding category 2020-10-12 22:49:19 -05:00
remotephone@gmail.com 476a3c04d9 Adding t1070_002 2020-10-12 00:01:10 -05:00
remotephone@gmail.com 781c7ce6dc Cleaning up falsepositives section of both rules 2020-10-11 23:52:47 -05:00
remotephone@gmail.com 48edc674bd updating keywords to CommandLine|contains and splitting rule into two 2020-10-11 22:43:28 -05:00
Yugoslavskiy Daniil e52baddda2 improve descriptin 2020-10-11 22:11:03 +02:00
Yugoslavskiy Daniil 7dec19afca add macos_create_hidden_account.yml; part of the oscd initiative task number 63 of the issue #1012 2020-10-11 22:01:05 +02:00
Alejandro Ortuno d17faf8234 Local groups discovery sigma rules 2020-10-11 18:15:53 +02:00
Alejandro Ortuno 3358dd47ea macos local account creation 2020-10-11 17:56:29 +02:00
Alejandro Ortuno 418a9d5a02 Use endswith with processname 2020-10-11 09:37:08 +02:00
Alejandro Ortuno 748dccc289 additional changes to split processname and commandline 2020-10-10 13:11:17 +02:00
Alejandro Ortuno 04f415c80b Added the sigma rules per OS 2020-10-08 13:23:11 +02:00
Alejandro Ortuno c5605ae8b6 Scheduled Cron Task/Job sigma rule 2020-10-08 13:15:02 +02:00
remotephone@gmail.com e967cce211 change new lines to LF instead of CLRF 2020-10-07 23:02:03 -05:00
remotephone@gmail.com 9802704a2b not sure why i'm failing the tests on a line I didn't change. copying format from another file 2020-10-07 22:54:31 -05:00
remotephone@gmail.com ff2ba5f876 double checking new line characters 2020-10-07 22:43:38 -05:00
remotephone@gmail.com 83ed39f95c adding UID, renaming 2020-10-07 22:25:54 -05:00
remotephone@gmail.com 4486c3ffc9 adding new line at end of file 2020-10-07 22:11:05 -05:00
remotephone@gmail.com cde0020d30 T1016 detection rules 2020-10-07 22:09:15 -05:00
Ömer Günal eac5ac9fc1 removed duplicate filter 2020-10-08 00:18:38 +03:00
Ömer Günal e6588c08f4 Create lnx_system_info_discovery.yml 2020-10-08 00:15:46 +03:00
Ömer Günal 2cea3800de Create lnx_password_policy_discovery.yml 2020-10-08 00:14:40 +03:00
Ömer Günal f00e79d123 Create lnx_file_deletion.yml 2020-10-07 22:28:37 +03:00
Ömer Günal 18821d2255 Create lnx_clear_logs.yml 2020-10-07 22:27:06 +03:00
Ömer Günal d44ef84b55 Update lnx_process_discovery.yml 2020-10-07 22:26:02 +03:00
Ömer Günal d328f92503 Update at_command.yml 2020-10-07 22:23:48 +03:00
Ömer Günal bdabb14483 Update at_command.yml 2020-10-07 22:22:31 +03:00
Ömer Günal 7b29e3a35f Update lnx_install_root_certificate.yml 2020-10-07 22:20:17 +03:00
Ömer Günal 8ea054ff0b Update at_command.yml 2020-10-07 00:07:30 +03:00
Ömer Günal b0b72de94d Create lnx_process_discovery.yml 2020-10-06 23:52:06 +03:00
Ömer Günal 7b39e76192 Create at_command.yml 2020-10-06 23:48:25 +03:00
Ömer Günal 759268108f rename filename 2020-10-06 09:04:36 +03:00
Ömer Günal 0e7eb32f62 update description 2020-10-05 20:22:43 +03:00