Commit Graph

6 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 598d29f811 Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
chore: change tags, date, modified fields to comply with v2 of the Sigma spec.
chore: update the related type from `obsoletes` to `obsolete`.
chore: update local json schema to the latest version.
2024-08-12 12:02:50 +02:00
Nasreddine Bencherchali 779111a0dd Merge PR #4928 from @nasbench - Fix FPs and issues found in testing
fix: Potential DLL Sideloading Of DbgModel.DLL - Update selection name to match the condition
fix: NTLM Logon - Remove unnecessary field
fix: Potential Commandline Obfuscation Using Unicode Characters - Remove legitimate currency characters as they could be used in document names
fix: Suspicious SYSTEM User Process Creation - Update `ping` filter to account for other FP variants found in the wild.
2024-07-24 09:22:49 +02:00
Gameel Ali 1b0eb51f19 Merge PR #4721 from @MalGamy - Add UA used by RedCurl APT
update: APT User Agent - Add UA used by RedCurl APT 
---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2024-02-15 11:27:43 +01:00
Luca 099d435adc Merge PR #4565 from @CrimpSec - Add UA related to PlugX backdoor
update: APT User Agent - adding user agent associated with PlugX backdoor.

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2023-11-13 11:43:55 +01:00
Nasreddine Bencherchali 7c38a5c496 chore: add nextron authors tag 2023-02-01 11:14:59 +01:00
frack113 8b321ba0b2 Order root rules folder 2023-01-31 14:05:08 +01:00