frack113
|
a6149462d8
|
Merge pull request #1931 from phantinuss/master
More malleable CobaltStrike C2 profiles from new source/reference
|
2021-08-26 17:18:19 +02:00 |
|
frack113
|
59000b993d
|
Merge pull request #1932 from mlp1515/french_user
Add French user
|
2021-08-26 17:12:39 +02:00 |
|
phantinuss
|
e59b8e1e3e
|
add applicable pipe names from regex rule
|
2021-08-26 14:53:20 +02:00 |
|
mlp1515
|
cce7cfc79a
|
Update win_tool_psexec.yml
French language settings
|
2021-08-26 12:51:45 +00:00 |
|
mlp1515
|
e1aa82b412
|
Update win_susp_tscon_localsystem.yml
French language settings
|
2021-08-26 12:50:24 +00:00 |
|
mlp1515
|
e9ed5f592c
|
Update sysmon_always_install_elevated_windows_installer.yml
French language settings
|
2021-08-26 12:48:59 +00:00 |
|
mlp1515
|
4f49f03460
|
Update sysmon_abusing_debug_privilege.yml
French language settings
|
2021-08-26 12:46:15 +00:00 |
|
mlp1515
|
a31422db74
|
Update win_susp_schtask_creation.yml
French language settings
|
2021-08-26 12:45:24 +00:00 |
|
mlp1515
|
5f419d6f35
|
Update win_susp_taskmgr_localsystem.yml
French language settings
|
2021-08-26 12:44:35 +00:00 |
|
mlp1515
|
5545403a9b
|
Update win_whoami_as_system.yml
French language settings
|
2021-08-26 12:43:33 +00:00 |
|
mlp1515
|
7ad927f28e
|
Update win_wmiprvse_spawning_process.yml
French language settings
|
2021-08-26 12:42:47 +00:00 |
|
mlp1515
|
644397e65c
|
Update win_exploit_cve_2019_1388.yml
French language settings
|
2021-08-26 12:41:36 +00:00 |
|
phantinuss
|
dc19268583
|
remove becasue of possible conflict
with a legitimate tool (https://labs.nettitude.com/blog/cve-2017-16245-cve-2017-16246-avecto-defendpoint-multiple-vulnerabilities/)
|
2021-08-26 14:25:12 +02:00 |
|
Florian Roth
|
6c7d355ef5
|
Try to add more pipe names to this non-regex rule
|
2021-08-26 14:00:57 +02:00 |
|
Florian Roth
|
2d36d62e88
|
Merge pull request #1928 from frack113/fix_name_case
fix file name case
|
2021-08-26 13:55:12 +02:00 |
|
Florian Roth
|
54997553ba
|
Merge pull request #1929 from SigmaHQ/rule-devel
refactor: Mimikatz keyword rule refactoring
|
2021-08-26 13:33:02 +02:00 |
|
phantinuss
|
217dbc768a
|
More malleable CobaltStrike C2 profiles from new source/reference
|
2021-08-26 12:53:43 +02:00 |
|
Florian Roth
|
8b318b9273
|
refactor: Mimikatz keyword rule refactoring
|
2021-08-26 12:51:45 +02:00 |
|
f.hubaut
|
e66007a43d
|
fix file name case
|
2021-08-26 11:15:33 +02:00 |
|
frack113
|
a4021842de
|
Fix invalid tags
|
2021-08-25 09:15:57 +02:00 |
|
frack113
|
e849af9df0
|
Merge pull request #1915 from frack113/tags_cve
fix tags
|
2021-08-25 06:29:48 +02:00 |
|
Florian Roth
|
9f69cead8a
|
Merge pull request #1916 from SigmaHQ/rule-devel
refactor: changed level of rule, refactored RazerInstaller rule
|
2021-08-24 15:42:26 +02:00 |
|
Florian Roth
|
46e312ff0d
|
fix: error in modifier
|
2021-08-24 15:03:23 +02:00 |
|
Florian Roth
|
cc519552aa
|
refactor: RazorInstaller integrity level system
|
2021-08-24 14:54:07 +02:00 |
|
frack113
|
7753f8c22e
|
fix tags
|
2021-08-24 12:36:31 +02:00 |
|
Florian Roth
|
6ca30619ac
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-08-24 12:30:42 +02:00 |
|
Florian Roth
|
3cdb88ad55
|
refactor: level of suspicious parent for powershell rule
|
2021-08-24 12:30:40 +02:00 |
|
frack113
|
5b869a3f42
|
Update cve tags
|
2021-08-24 10:50:01 +02:00 |
|
frack113
|
ace46c17be
|
Update cve tags
|
2021-08-24 10:27:27 +02:00 |
|
frack113
|
c2302a15da
|
fix cve tags
|
2021-08-24 10:10:45 +02:00 |
|
Florian Roth
|
0c69fd9c41
|
Merge pull request #1898 from SigmaHQ/rule-devel
rule: EfsPotato Named Pipe, splwow64, RazerInstaller
|
2021-08-24 09:20:54 +02:00 |
|
Florian Roth
|
272625a005
|
Update win_susp_splwow64.yml
|
2021-08-24 08:34:08 +02:00 |
|
frack113
|
a04fbe2a99
|
Merge pull request #1901 from frack113/redcanary
Redcanary Powershell Suspicious Win32_PnPEntity T1120
|
2021-08-23 19:44:16 +02:00 |
|
Florian Roth
|
998ebbe1f3
|
fix: typo in name
|
2021-08-23 18:46:05 +02:00 |
|
Florian Roth
|
6b86dacc9e
|
rule: razor installer
|
2021-08-23 18:44:15 +02:00 |
|
frack113
|
be316db84d
|
Merge pull request #1899 from secDre4mer/master
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 17:26:16 +02:00 |
|
SomeOne
|
037f33b5e2
|
Replace by default windows fieldnames
|
2021-08-23 15:24:48 +02:00 |
|
Florian Roth
|
91b42f9077
|
fix: indentation
|
2021-08-23 15:03:59 +02:00 |
|
SomeOne
|
45f30cb2b4
|
Add fields to event log cleared
|
2021-08-23 15:00:07 +02:00 |
|
frack113
|
25072e37b3
|
update references
|
2021-08-23 13:30:46 +02:00 |
|
frack113
|
33c6ff6b5f
|
add powershell_suspicious_win32_pnpentity
|
2021-08-23 13:17:35 +02:00 |
|
Max Altgelt
|
82dde594d1
|
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 11:20:30 +02:00 |
|
Florian Roth
|
a0f72e5f6f
|
rule: suspicious splwow64 process starts
|
2021-08-23 10:41:42 +02:00 |
|
Florian Roth
|
dc3ed771b5
|
rule: EfsPotato Named Pipe
|
2021-08-23 08:32:50 +02:00 |
|
frack113
|
fc9666fb4e
|
Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
|
2021-08-22 18:56:08 +02:00 |
|
frack113
|
0a410010a2
|
Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
|
2021-08-22 18:50:58 +02:00 |
|
SomeOne
|
295054dcbe
|
Replace old mitre techniques by new one
|
2021-08-22 13:57:56 +02:00 |
|
frack113
|
064c65cb1f
|
Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
|
2021-08-21 18:04:52 +02:00 |
|
frack113
|
07a87aa7f8
|
Merge pull request #1858 from frack113/fix_pr718
Replace pr718
|
2021-08-21 18:02:30 +02:00 |
|
frack113
|
a44206bfa0
|
Some cleanup
|
2021-08-21 17:33:39 +02:00 |
|