Commit Graph

12938 Commits

Author SHA1 Message Date
Nasreddine Bencherchali b61d83beef Merge PR #5790 from @nasbench - Metadata Updates
chore: update metadata of many rules
update: AppX Located in Uncommon Directory Added to Deployment Pipeline - Enhance selection criteria

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-12-24 17:50:21 +01:00
Micah Babinski 2952d630a4 Merge PR #5774 from @mbabinski - Added rules related to ArcGIS Server Object Extension abuse
new: Suspicious File Created by ArcSOC.exe
new: Suspicious ArcSOC.exe Child Process

---------

Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com>
2025-12-21 18:07:30 +01:00
Swachchhanda Shrawan Poudel 685194383b Merge PR #5804 from @swachchhanda000 - enhance rules related with file download from file sharing websites
update: Suspicious Remote AppX Package Locations - add github.com
update: BITS Transfer Job Download From File Sharing Domains - add github.com
update: Suspicious File Download From File Sharing Websites - File Stream - add github.com
update: Unusual File Download From File Sharing Websites - File Stream - add github.com
update: Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder - add github.com
update: Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location - add github.com
update: Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE - add github.com
update: Suspicious File Download From File Sharing Domain Via Curl.EXE - add github.com
update: Suspicious File Download From File Sharing Domain Via Wget.EXE - add github.com
2025-12-12 08:04:27 +05:45
Swachchhanda Shrawan Poudel c5b881019a Merge PR #5777 from @swachchhanda000 - feat: more edrfreeze rules
new: WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze
new: Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
new: Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
new: Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
update: Hacktool - EDR-Freeze Execution - add more coverage
---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-12-10 15:29:38 +01:00
Toheeb Ajala Husain cce4545c10 Merge PR #5801 from @toheeb-orelope - add Invoke-DNSExfiltrator
update: Malicious PowerShell Scripts - FileCreation - add Invoke-DNSExfiltrator
update: Malicious PowerShell Scripts - PoshModule - add Invoke-DNSExfiltrator
update: Malicious PowerShell Commandlets - PoshModule - add Invoke-DNSExfiltrator
update: Malicious PowerShell Commandlets - ScriptBlock - add Invoke-DNSExfiltrator
update: Malicious PowerShell Commandlets - ProcessCreation - add Invoke-DNSExfiltrator

---------

Co-authored-by: nasbench <nasbench@users.noreply.github.com>
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-12-10 15:15:19 +01:00
Nasreddine Bencherchali cf3cbf8089 Merge PR #5799 from @nasbench - Update logic to use errorCode instead for better mapping and accuracy
update: Potential Malicious Usage of CloudTrail System Manager - Update logic to use errorCode instead for better mapping and accuracy
2025-12-09 10:17:50 +01:00
Swachchhanda Shrawan Poudel f05a8c4d94 Merge PR #5788 from @swachchhanda000 - Recon via RDP Logging Event
update: Potentially Suspicious EventLog Recon Activity Using Log Query Utilities - add more interesting event ids

---------

Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
2025-12-09 08:48:59 +05:45
Swachchhanda Shrawan Poudel f7f61a9f95 Merge PR #5789 from @swachchhanda000 - Add fps filter observed on ARM-based Windows updates
fix: Uncommon AppX Package Locations - filter out system32
fix: Unauthorized System Time Modification - filter out vmwaretools
fix: Files With System Process Name In Unsuspected Locations - filter windows temp
fix: Startup Folder File Write - filter out wuauclt.exe and C:$WinREAgent\Scratch\Mount\ directory
fix: Potentially Suspicious WDAC Policy File Creation - filter wuaucltcore.exe
fix: Creation of WerFault.exe/Wer.dll in Unusual Folder - filter C:\Windows\UUS\arm64\
fix: Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load - filter C:$WinREAgent\Scratch\
fix: Potential System DLL Sideloading From Non System Locations - filter legitimate ARM based locations
fix: Potential Defense Evasion Via Raw Disk Access By Uncommon Tools - filter legitimate ARM based locations

---------

Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
2025-12-09 08:29:51 +05:45
Swachchhanda Shrawan Poudel f58b44eb16 Merge #5798 from @swachchhanda000 - fix: aurora fps
fix: Rare Remote Thread Creation By Uncommon Source Image - filter provtool system
fix: Load Of RstrtMgr.DLL By An Uncommon Process - filter OneDriveStandaloneUpdater.exe
fix: Wow6432Node CurrentVersion Autorun Keys Modification - filter null Details

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-12-09 08:21:14 +05:45
Swachchhanda Shrawan Poudel 57c71b3b8a Merge PR #5778 from @swachchhanda000 - fix: add some filters or tune rules to reduce false positives
fix: Suspicious desktop.ini Action - filter onedrive
fix: CredUI.DLL Loaded By Uncommon Process - filter systemapps
update: Renamed Office Binary Execution - add olk.exe matching on Microsoft Outlook
2025-12-09 08:15:03 +05:45
Niicolaa ed2650a0eb Merge PR #5791 from @Niicolaa - fix: add correct osascript path
fix: GUI Input Capture - macOS - remove osascript wrong path

---------

Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-12-09 08:03:04 +05:45
Nasreddine Bencherchali 5656c48a97 Merge PR #5793 from @nasbench - Rename Auditd Folder Entries and update SYSCALL field
chore: rename auditd folders and others
update: Audio Capture - Updated syscall field to SYSCALL in order to make use of enriched logs
update: ASLR Disabled Via Sysctl or Direct Syscall - Linux - Updated syscall field to SYSCALL in order to make use of enriched logs
update: Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
update: System Info Discovery via Sysinfo Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
update: Special File Creation via Mknod Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
update: Webshell Remote Command Execution - Updated syscall field to SYSCALL in order to make use of enriched logs
2025-12-08 16:03:55 +01:00
Koifman 0aa29891df Merge PR #5782 from @Koifman - Add Github Self-Hosted Runner Execution
new: Github Self-Hosted Runner Execution

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com>
2025-12-04 00:55:53 +01:00
Álex d9c93074d4 Merge PR #5785 from @RiqTam - Update Certutil download rules
update: Suspicious Download Via Certutil.EXE - add URL flag related with GUI-based download
update: Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE - add URL flag related with GUI-based download
update: Suspicious File Downloaded From Direct IP Via Certutil.EXE - add URL flag related with GUI-based download

---------

Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-12-03 11:57:45 +05:45
suKTech24 3565dee3eb Merge PR #5536 from @suKTech24 - Add AWS GuardDuty Detector Deleted Or Updated
Goodlog Tests / check-baseline-win7 (push) Has been cancelled
Goodlog Tests / check-baseline-win10 (push) Has been cancelled
Goodlog Tests / check-baseline-win11 (push) Has been cancelled
Goodlog Tests / check-baseline-win11-2023 (push) Has been cancelled
Goodlog Tests / check-baseline-win2022 (push) Has been cancelled
Goodlog Tests / check-baseline-win2022-domain-controller (push) Has been cancelled
Goodlog Tests / check-baseline-win2022-0-20348-azure (push) Has been cancelled
Regression Tests / true-positive-tests (push) Has been cancelled
Create Release / Create Release (push) Has been cancelled
Sigma Rule Tests / yamllint (push) Has been cancelled
Validate Sigma rules / sigma-rules-validator (push) Has been cancelled
Sigma Rule Tests / test-sigma-logsource (push) Has been cancelled
Sigma Rule Tests / test-sigma-legacy (push) Has been cancelled
Sigma Rule Tests / sigma-check (push) Has been cancelled
Sigma Rule Tests / duplicate-id-check (push) Has been cancelled
new: AWS GuardDuty Detector Deleted Or Updated

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-11-28 10:33:03 +01:00
Swachchhanda Shrawan Poudel 0a6d929974 Merge PR #5482 from @swachchhanda000 - Update Suspicious Copy From or To System Directory
update: Suspicious Copy From or To System Directory - Update selection to use regex for better accuracy
update: LOL-Binary Copied From System Directory - Add ie4uinit.exe

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2025-11-27 23:44:35 +01:00
Swachchhanda Shrawan Poudel 1821bcbb00 Merge PR #5475 from @swachchhanda000 - Add Renamed Schtasks Execution
new: Renamed Schtasks Execution
---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2025-11-27 23:19:13 +01:00
Swachchhanda Shrawan Poudel 3e9318e23f Merge PR #5763 from @swachchhanda000 - Update ClickFix/FileFix related rules
removed: FileFix - Suspicious Child Process from Browser File Upload Abuse - Deprecated in favor of b5b29e4e-31fa-4fdf-b058-296e7a1aa0c2
new: DNS Query by Finger Utility
new: Network Connection Initiated via Finger.EXE
fix: Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix - Fix selection to use ParentImage instead of Image field
new: Suspicious FileFix Execution Pattern
update: FileFix - Command Evidence in TypedPaths - Added more markers
update: Potential ClickFix Execution Pattern - Registry - Add 2 new strings, "finger" and "identification"
chore: Update "test_rules.py" filename test with better output formatting

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: nasbench <monsteroffire2@gmail.com>
2025-11-27 23:00:25 +01:00
Chris b09cbc3083 Merge PR #5724 from @darses - update DNS Query to External Service Interaction Domains
update: DNS Query to External Service Interaction Domains - add additional domains and filters

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2025-11-26 11:52:21 +01:00
Swachchhanda Shrawan Poudel c141859b83 Merge PR #5775 from @swachchhanda000 - Restructure regression testing data directory
chore: restructure regression testing data directory
2025-11-26 11:08:11 +01:00
Seth Hanford 5f57f9e816 Merge PR #5766 from @SethHanford - Update Potential Container Discovery Via Inodes Listing
update: Potential Container Discovery Via Inodes Listing - replace contains globbing with more correct patterns using regex

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com>
2025-11-25 16:29:32 +01:00
EzLucky 66e091c08c Merge PR #5770 from @EzLucky - Update MITRE Attack mapping for Linux Capabilities Discovery
chore: update mitre att&ck tag

---------

Co-authored-by: nasbench <monsteroffire2@gmail.com>
2025-11-25 16:23:51 +01:00
Nasreddine Bencherchali 2cb7375c6b Merge PR #5719 from @nasbench - Add regression test CI, data and simulation links
update: Cred Dump Tools Dropped Files - Add procdump.exe and procdump64a.exe
update: File Download From Browser Process Via Inline URL - Enhance selection by splitting CLI markers for better matching
update: Tor Client/Browser Execution - Add additional PE metadata markers
update: System Information Discovery via Registry Queries - Enhance registry markers
update: PUA - AdFind Suspicious Execution - Add -sc to dclist string for more accurate coverage.
fix: Removal Of Index Value to Hide Schedule Task - Registry - Remove EventType condition that broke the rule.
fix: Removal Of SD Value to Hide Schedule Task - Registry - Remove EventType condition that broke the rule.
fix: Creation of a Local Hidden User Account by Registry - Fix the TargetObject value
fix: Potential Persistence Via New AMSI Providers - Registry - Change logsource and fix the rule logic
fix: Potential COM Object Hijacking Via TreatAs Subkey - Registry - Change logsource and fix the rule logic
fix: Potential Persistence Via Logon Scripts - Registry - Fix incorrect logsource
fix: PUA - Sysinternal Tool Execution - Registry - Fix incorrect logsource
fix: Suspicious Execution Of Renamed Sysinternals Tools - Registry - Fix incorrect logsource
fix: PUA - Sysinternals Tools Execution - Registry - Fix incorrect logsource
chore: add CI script for regression
chore: add regression data

---------

Co-authored-by: swachchhanda000 <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-11-25 16:00:53 +01:00
Jonathan Beierle 23a375bfa6 Merge PR #5762 from @HullaBrian - Unsigned .node File Load
new: Unsigned .node File Loaded

---------
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-11-25 17:48:05 +05:45
Kostas 5a2885c310 Merge PR #5627 from @tsale - Filename with Embedded Base64 Commands
new: Suspicious Filename with Embedded Base64 Commands
new: Potentially Suspicious Long Filename Pattern - Linux

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: swachchhanda000 <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2025-11-24 15:33:42 +01:00
Nasreddine Bencherchali 9d58e38bbc Merge PR #5769 from @nasbench - fix keywords rule and remove the fields field
remove: Space After Filename - Logic was incorrect and untested
update: Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - Update selection
update: JexBoss Command Sequence - Update the selection to use the |all modifier.
chore: remove any usage of the fields field to prepare for deprecation in the spec.
2025-11-24 09:54:29 +01:00
Swachchhanda Shrawan Poudel 37024247ae Merge PR #5761 from @swachchhanda000 - feat: Suspicious Kerberos ticket request via CLI
update: Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock - Add the "GetRequest()" string
new: Suspicious Kerberos Ticket Request via CLI
---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
2025-11-23 21:12:40 +05:45
IntelScott 0d7658fb3a Merge PR #5717 from @tropChaud - Add and Enhance Windows Default Domain GPO & RDP Tampering Rules
new: Windows Default Domain GPO Modification
new: Windows Default Domain GPO Modification via GPME
update: Potential Tampering With RDP Related Registry Keys Via Reg.EXE - Add coverage for SecurityLayer value
update: RDP Sensitive Settings Changed - Add coverage for SecurityLayer value
---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2025-11-23 20:36:08 +05:45
Swachchhanda Shrawan Poudel 5121401b01 Merge PR #5652 from @swachchhanda000 - Abuse of WerFaultSecure for PPL Tampering
new: HackTool - WSASS Execution
update: System File Execution Location Anomaly - add Windows error reporting binaries
update: PPL Tampering Via WerFaultSecure - Rename and update metadata

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
2025-11-23 20:00:17 +05:45
Javier Bruno 8c50909141 Merge PR #5746 from @deftoner - improve logsource format
chore: DNS Query To Visual Studio Code Tunnels Domain - improve logsource format
2025-11-21 12:13:42 +01:00
Swachchhanda Shrawan Poudel f448a13ce7 Merge PR #5591 from @swachchhanda000 - Registry Modifications through VBScripts
new: Registry Modification Attempt Via VBScript - PowerShell
new: Registry Modification Attempt Via VBScript
new: Registry Tampering by Potentially Suspicious Processes
---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-11-21 11:54:19 +01:00
Koifman 1da888c779 Merge PR #5725 from @Koifman - RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
new: RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
---------

Co-authored-by: nasbench <nasbench@users.noreply.github.com>
Co-authored-by: swachchhanda000 <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-11-21 10:26:45 +01:00
montysecurity 4ac67452f1 Merge PR #5218 from @montysecurity - Suspicious ClickFix/FileFix Execution Pattern
new: Suspicious ClickFix/FileFix Execution Pattern

---------

Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
Co-authored-by: swachchhanda000 <87493836+swachchhanda000@users.noreply.github.com>
2025-11-21 13:53:59 +05:45
Liran Ravich e0bb355b3f Merge PR #5550 from @Liran017 - Unusual svchost Command Line Parameter
new: Uncommon Svchost Command Line Parameter

---------

Co-authored-by: Nasreddine Bencherchali <nasbench@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-11-21 13:00:47 +05:45
jstnk9 55e61044ff Merge PR #5519 from @jstnk9 - Suspicious Use of for Loop with Directory Search in CMD
new: Suspicious Usage of For Loop with Recursive Directory Search in CMD

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2025-11-21 12:26:45 +05:45
Nasreddine Bencherchali ddcccfe4d3 Merge PR #5757 from @nasbench - Clone #5504
update: Potentially Suspicious NTFS Symlink Behavior Modification - Tighten logic to focus on proxy process such as cmd or powershell

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-11-17 12:23:57 +05:45
phantinuss c2f1eb41bc Merge PR #5756 from @phantinuss - add a check for duplicate IDs over all rules that ever existed
chore: ci: add a check for duplicate ids over all rules that ever existed
chore: change duplicate IDs in obsoleted rules
---------

Co-authored-by: nasbench <nasbench@users.noreply.github.com>
2025-11-13 14:22:02 +01:00
Swachchhanda Shrawan Poudel 3d59e82504 Merge PR #5748 from @swachchhanda000 - feat: add new CLSID for COM Hijacking detection
update: COM Object Hijacking Via Modification Of Default System CLSID Default Value - add clsid of twinapi.dll
2025-11-13 10:03:01 +05:45
Swachchhanda Shrawan Poudel 47171af68a Merge PR #5601 from @swachchhanda000 - fix: add filters on registry rules
fix: Potential Ursnif Malware Activity - Registry - add specific registry key
fix: Common Autorun Keys Modification - filter null
fix: CurrentVersion NT Autorun Keys Modification - filter null and poqexec.exe
fix: Wow6432Node Windows NT CurrentVersion Autorun Keys Modification - filter null
2025-11-13 09:55:26 +05:45
Swachchhanda Shrawan Poudel 4355ece230 Merge PR #5598 from @swachchhanda000 - filter FPs on multiple rules
remove: Active Directory Kerberos DLL Loaded Via Office Application - deprecated as it triggers on normal activity
fix: Scheduled Task Creation Via Schtasks.EXE - add for for msoffice application
fix: Use Short Name Path in Command Line - add filter for dotnet csc.exe
fix: Potential Product Reconnaissance Via Wmic.EXE - add filter for some product related operation through wmic
fix: WMIC Remote Command Execution - fix broken FP filter
fix: Classes Autorun Keys Modification - filter null details
fix: CurrentVersion Autorun Keys Modification - filter null details
fix: Modification of IE Registry Settings - filter null details
fix: Potential Persistence Via Shim Database Modification - filter null details
fix: Scheduled TaskCache Change by Uncommon Program - filter null details
update: Copy From Or To Admin Share Or Sysvol Folder - some logic change

---------

Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2025-11-10 13:52:54 +01:00
Nasreddine Bencherchali f61f66e745 Merge PR #5733 from @nasbench - fix windash issues and some renames
fix: Office Macro File Download - Reduce level to low due to FPs spotted via VT.
fix: Suspicious CustomShellHost Execution - Increased level to high due to low FP rate spotted via VT.
fix: Explorer Process Tree Break - Fix incorrect usage of windash with the all modifier, that broke the logic.
fix: MSDT Execution Via Answer File - Rename rule as well as introduce usage of windash for increased coverage.
fix: Capture Credentials with Rpcping.exe - Fix incorrect usage of windash with the all modifier, that broke the logic.
fix: Wlrmdr.EXE Uncommon Argument Or Child Process - Fix incorrect usage of windash with the all modifier, that broke the logic.

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2025-11-10 12:12:34 +01:00
Swachchhanda Shrawan Poudel c6fcff5cff Merge PR #5740 from @swachchhanda000 - chore: reorganize threat specific rules into rules-emerging-threats directory
chore: reorganize threat specific rules into rules-emerging-threats directory

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-11-10 12:00:08 +01:00
Álex 43b6fae2a0 Merge PR #5727 from @RiqTam - Fix rule to detect downloads via CertReq
fix: Suspicious Certreq Command to Download - remove spaces and specific path from detection
---------

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2025-11-06 10:31:11 +05:45
Swachchhanda Shrawan Poudel 251be1edd8 Merge PR #5743 from @swachchhanda000 - new: clickfix/filefix space character padding
new: Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
new: Suspicious Space Characters in RunMRU Registry Path - ClickFix
new: Suspicious Space Characters in TypedPaths Registry Path - FileFix

---------

Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-11-05 11:11:32 +01:00
Nasreddine Bencherchali 3a20687cad Merge PR #5738 from @nasbench - rename folders and update readme
chore: rename folders and update readme
2025-11-03 10:35:44 +01:00
InTheCyber 4dfbd6b713 Merge PR #5197 from @inthecyber - Add new Fortinet Fortigate rules
new: FortiGate - New Administrator Account Created
new: FortiGate - Firewall Address Object Added
new: FortiGate - New Firewall Policy Added
new: FortiGate - New Local User Created
new: FortiGate - New VPN SSL Web Portal Added
new: FortiGate - User Group Modified
new: FortiGate - VPN SSL Settings Modified

---------

Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
Co-authored-by: Tommaso Tosi <tommaso.tosi@inthecyber.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2025-11-02 00:06:27 +01:00
Nasreddine Bencherchali a77d3bae4b Merge PR #5708 from @nasbench - Multiple updates and issue fixes
Goodlog Tests / check-baseline-win7 (push) Has been cancelled
Goodlog Tests / check-baseline-win10 (push) Has been cancelled
Goodlog Tests / check-baseline-win11 (push) Has been cancelled
Goodlog Tests / check-baseline-win11-2023 (push) Has been cancelled
Goodlog Tests / check-baseline-win2022 (push) Has been cancelled
Goodlog Tests / check-baseline-win2022-domain-controller (push) Has been cancelled
Goodlog Tests / check-baseline-win2022-0-20348-azure (push) Has been cancelled
Create Release / Create Release (push) Has been cancelled
Sigma Rule Tests / yamllint (push) Has been cancelled
Validate Sigma rules / sigma-rules-validator (push) Has been cancelled
Sigma Rule Tests / test-sigma-logsource (push) Has been cancelled
Sigma Rule Tests / test-sigma-legacy (push) Has been cancelled
Sigma Rule Tests / sigma-check (push) Has been cancelled
fix: Turla Group Commands May 2020 - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Dtrack RAT Activity - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Data Exfiltration Activity Via CommandLine Tools - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Suspicious Network Command - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Suspicious SYSTEM User Process Creation - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Snatch Ransomware Activity - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Potential Devil Bait Malware Reconnaissance - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Mint Sandstorm - AsperaFaspex Suspicious Process Execution - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
fix: Mint Sandstorm - ManageEngine Suspicious Process Execution - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
update: Powershell Token Obfuscation - Powershell - Move to the TH folder in order to set the right FP expectations.
fix: Kerberoasting Activity - Initial Query - Fix issue with filter names and logic
chore: add sorting to the rule archiver script


---------

Thanks: KingKDot
Thanks: zambomarcell
Thanks: Koifman
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-10-29 11:45:19 +01:00
Nasreddine Bencherchali 02f7843bcf Merge PR #5720 from @nasbench - Add Suspicious Speech Runtime Binary Child Process
Thanks: BIitzkrieg
2025-10-29 11:41:51 +01:00
Swachchhanda Shrawan Poudel 6560a6cc20 Merge PR #5711 from @swachchhanda000 - Add PUA - AWS TruffleHog Execution
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-29 11:40:20 +01:00
Swachchhanda Shrawan Poudel 24f411b879 Merge PR #5706 from @swachchhanda000 - update PFX File Creation
update: PFX File Creation - Enhance filters, metadata and logic

---------

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2025-10-29 09:52:39 +01:00