Commit Graph

4270 Commits

Author SHA1 Message Date
frack113 f015c940f8 Merge pull request #3880 from frack113/from_VT_screen
Add proc_creation_win_double_ext_parent
2023-01-06 18:31:47 +01:00
frack113 97ec1c4d54 Add related 2023-01-06 18:22:36 +01:00
frack113 3346a6d3e4 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-06 18:21:06 +01:00
frack113 679d1ee0ed Add more ext 2023-01-06 18:17:01 +01:00
Nasreddine Bencherchali 18a77e79e3 fix: multiple issues 2023-01-06 18:04:04 +01:00
frack113 4adbb3fbd2 Add proc_creation_win_double_ext_parent 2023-01-06 17:18:50 +01:00
Nasreddine Bencherchali e56d3763b5 fix: unused selection 2023-01-06 17:16:20 +01:00
Nasreddine Bencherchali 7e73028c5e feat: updates and enhancements 2023-01-06 16:35:34 +01:00
frack113 65eb06e231 Merge pull request #3876 from frack113/fix_fp_gfx
Update proc_creation_win_susp_file_download_via_gfxdownloadwrapper.yml
2023-01-06 13:48:31 +01:00
frack113 31530e50b7 Update FP 2023-01-06 13:28:57 +01:00
Nasreddine Bencherchali fb1f72a634 fix: add missing modified field 2023-01-05 23:08:36 +01:00
Veramine 325d532239 Update proc_creation_win_susp_3proxy_usage.yml
Fix condition
2023-01-05 13:30:45 -08:00
Nasreddine Bencherchali be4d99d6dd Merge pull request #3868 from nasbench/nasbench-rule-devel
feat: updates and enhancements
2023-01-04 19:29:12 +01:00
Nasreddine Bencherchali 679f3d015b fix: remove unnecessary space 2023-01-04 19:11:33 +01:00
Nasreddine Bencherchali 46f01f2f88 fix: typo in unknown 2023-01-04 18:46:34 +01:00
Tim Shelton 903ebb1176 FP: tenable nessus client calls cmd during scanning. 2023-01-04 17:42:16 +00:00
Nasreddine Bencherchali 219b24be0b fix: broken selection 2023-01-04 18:04:14 +01:00
Nasreddine Bencherchali 711ba956e3 feat: updates and enhancements 2023-01-04 17:49:32 +01:00
Nasreddine Bencherchali 0fe4f16dfb fix: update filter based on ##3865 and #3866 2023-01-04 10:28:50 +01:00
Nasreddine Bencherchali a737737d92 fix: enhance filter 2023-01-04 00:46:54 +01:00
Tim Shelton 0c520dc930 FP: manage engine admanager postgres calling archive.bat 2023-01-03 22:04:52 +00:00
Nasreddine Bencherchali 343e3f0934 Merge pull request #3859 from D3F7A5105/master
Change Evtx Location Used Wevtutil
2023-01-03 13:23:57 +01:00
Vadim eabad66768 Delete proc_creation_win_change_evtx_location.yml 2023-01-03 15:15:52 +03:00
Vadim 4329b9ad49 Update proc_creation_win_susp_eventlog_clear.yml 2023-01-03 15:11:33 +03:00
Vadim 5dc77bad7a Update rule for detects change location evtx 2023-01-03 15:10:54 +03:00
Vadim 052cd2e967 Update proc_creation_win_change_evtx_location.yml 2023-01-03 12:11:13 +03:00
Vadim 2075962596 Update proc_creation_win_change_evtx_location.yml 2023-01-03 11:54:30 +03:00
vadim e620fcbc0b Detects change location evtx used wecutil 2023-01-03 11:36:54 +03:00
Florian Roth 2b04ae2e35 Merge branch 'master' into aurora-false-positive-fixing 2023-01-03 00:17:11 +01:00
Florian Roth fefaa57d3c fix: FPs noticed in CI testing 2023-01-03 00:16:32 +01:00
Nasreddine Bencherchali 579b450d17 fix: add missing date 2023-01-02 15:26:41 +01:00
Nasreddine Bencherchali 083d30c19d fix: title and add python filter 2023-01-02 15:02:28 +01:00
Nasreddine Bencherchali e23a63a60e fix: typo in field name 2023-01-02 14:52:35 +01:00
Nasreddine Bencherchali 3749416a30 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-02 14:50:27 +01:00
Nasreddine Bencherchali a99b5082e1 feat: updates and enhancements 2023-01-02 14:49:45 +01:00
frack113 0aad498425 Last lolbin (#3845)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-31 19:53:44 +01:00
Nasreddine Bencherchali f67cd766d0 Merge pull request #3846 from fukusuket/fix-invalid-regex-escape
fix: remove incorrect backslash escape(in `|re` block)
2022-12-31 18:35:36 +01:00
fukusuket 04ecbbded9 fix: typo modified 2022-12-31 21:57:05 +09:00
fukusuket 9298295c15 fix: remove invalid backslash escape 2022-12-31 21:35:07 +09:00
signalblur 73f56c2f0e Hidden Linux Binary Execution (#3108)
Co-authored-by: Florian Roth <venom14@gmail.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-31 08:27:32 +01:00
Nasreddine Bencherchali 7dab38b19f fix: add missing modified date 2022-12-30 20:56:21 +01:00
fukusuket bd6243be7d fix: remove unneeded backslash escape in character class. 2022-12-31 00:33:00 +09:00
Nasreddine Bencherchali 261bb8758a Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-30 11:49:08 +01:00
frack113 aee5ca7afc Fix invalid field cast or name (#3841) 2022-12-30 11:46:21 +01:00
Nasreddine Bencherchali d4b9df608b fix: broken selection 2022-12-30 10:30:15 +01:00
Nasreddine Bencherchali 58f47b9875 fix: add known children appvlp 2022-12-30 10:24:25 +01:00
frack113 995b5918f2 Update rules/windows/process_creation/proc_creation_win_susp_shellexec_rundll_usage.yml 2022-12-30 10:21:54 +01:00
frack113 f083c5f83f Merge branch 'master' into patch-1 2022-12-30 10:12:25 +01:00
frack113 d10ecf5527 Merge pull request #3838 from redsand/fp_sysmon_werfault_child
FP when sysmon crashes and werfault gets launched
2022-12-30 10:08:09 +01:00
zydyka d7bc30587f Update proc_creation_win_sysmon_exploitation.yml 2022-12-30 09:00:57 +05:00