Commit Graph

9 Commits

Author SHA1 Message Date
david-syk 95b6dd8573 Merge PR #5381 from @david-syk - Update MITRE ATT&CK tags
chore: update multiple mitre att&ck tags
2025-04-25 20:55:51 +02:00
Nasreddine Bencherchali 598d29f811 Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
chore: change tags, date, modified fields to comply with v2 of the Sigma spec.
chore: update the related type from `obsoletes` to `obsolete`.
chore: update local json schema to the latest version.
2024-08-12 12:02:50 +02:00
Nasreddine Bencherchali c13b568bd3 Merge PR #4555 from @nasbench - New ET Rules Related To Lace Tempest / SysAid CVE-2023-47246 Exploitation
new: Lace Tempest File Indicators
new: Lace Tempest PowerShell Evidence Eraser
new: Lace Tempest PowerShell Launcher
new: Lace Tempest Cobalt Strike Download
new: Lace Tempest Malware Loader Execution
update: Suspicious Processes Spawned by Java.EXE - Enhance process coverage by adding new processes and removing unrelated ones
update: Webshell Detection With Command Line Keywords - Enhance process coverage by adding new processes and removing unrelated ones
update: Suspicious Process By Web Server Process - Enhance process coverage by adding new processes and removing unrelated ones

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-11-10 12:00:08 +01:00
frack113 020fc8061f Merge PR #4479 From @frack113 - Upgrade Rules Status
chore: Upgrade status level from `experimental` to `test` for rules that have not changed in 300 days

---------

Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2023-10-17 14:35:26 +02:00
Nasreddine Bencherchali 7c38a5c496 chore: add nextron authors tag 2023-02-01 11:14:59 +01:00
frack113 1f8e37351e order yaml 2022-10-28 15:06:36 +02:00
Nasreddine Bencherchali fe2e279cfa Add more comsvcs variations
Based on this https://twitter.com/Wietze/status/1542107456507203586
2022-08-04 16:18:51 +01:00
phantinuss f1dcaa02f4 fix: single list element 2022-03-21 12:33:55 +01:00
Florian Roth 33617fd8b4 rule: new webshell detection rule 2022-03-17 18:31:11 +01:00