Mohamed Ashraf
5c4f599e3a
Merge PR #4982 from @X-Junior - Update scheduled task related rules
...
update: Suspicious Windows Service Tampering - Add additional services and PsService.EXE
update: Disable Important Scheduled Task - Add `\Windows\ExploitGuard\ExploitGuard MDM policy Refresh`
---------
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2024-08-26 10:20:57 +02:00
Nasreddine Bencherchali
598d29f811
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
...
chore: change tags, date, modified fields to comply with v2 of the Sigma spec.
chore: update the related type from `obsoletes` to `obsolete`.
chore: update local json schema to the latest version.
2024-08-12 12:02:50 +02:00
frack113
7d6f32d1be
Merge PR #4850 from @frack113 - Cleanup rule conditions to align with standard
...
chore: Cleanup conditions
update: Scheduled Task Creation From Potential Suspicious Parent Location - Add additional "temporary folder" locations.
---------
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2024-05-13 12:10:33 +02:00
frack113
020fc8061f
Merge PR #4479 From @frack113 - Upgrade Rules Status
...
chore: Upgrade status level from `experimental` to `test` for rules that have not changed in 300 days
---------
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2023-10-17 14:35:26 +02:00
Nasreddine Bencherchali
63888f7a53
feat: multiple fixes and updates
2023-02-21 22:15:30 +01:00