frack113
|
a674ee246b
|
Update Title (#3739)
|
2022-11-30 11:44:15 +01:00 |
|
Nasreddine Bencherchali
|
4b9075e557
|
feat: new rules related to service creation
New service creation rules related to remote software tools
|
2022-11-28 12:09:00 +01:00 |
|
frack113
|
c820216541
|
Update Title (#3733)
|
2022-11-28 06:43:17 +01:00 |
|
frack113
|
cd4121d966
|
Update Title (#3731)
Co-authored-by: Florian Roth <venom14@gmail.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-11-27 19:19:27 +01:00 |
|
Qasim Qlf
|
ed54bf44a5
|
Minor Fix
|
2022-11-22 18:13:34 +05:00 |
|
Nasreddine Bencherchali
|
87b709a3e6
|
feat: add missing /r to cmd
|
2022-11-18 13:45:01 +01:00 |
|
Nasreddine Bencherchali
|
6603ca9202
|
fix: update rules to not use regex
|
2022-11-18 11:16:13 +01:00 |
|
Nasreddine Bencherchali
|
569d1d757a
|
fix: remove non existent eid and fix #2744
|
2022-11-15 22:58:19 +01:00 |
|
Florian Roth
|
187cb6b47e
|
Merge pull request #3694 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-11-15 09:35:45 +01:00 |
|
phantinuss
|
64d10f845a
|
fix: FPs in testing environment
|
2022-11-14 08:54:47 +01:00 |
|
Florian Roth
|
0fb1295157
|
fix: FPs noticed with Aurora
|
2022-11-13 20:26:03 +01:00 |
|
Nasreddine Bencherchali
|
04b7b92b64
|
fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
|
2022-11-11 10:03:24 +01:00 |
|
Nasreddine Bencherchali
|
0a51dcdf5c
|
fix: rename rule to reflect new title
|
2022-11-10 18:24:36 +01:00 |
|
Nasreddine Bencherchali
|
1ab9e9640e
|
fix: enhance description
|
2022-11-10 18:19:39 +01:00 |
|
Nasreddine Bencherchali
|
f09ea65ec4
|
fix: update code integrity rules
|
2022-11-10 17:43:22 +01:00 |
|
Nasreddine Bencherchali
|
30869e1b2b
|
fix: fp with defender def updates
|
2022-11-10 17:15:22 +01:00 |
|
Nasreddine Bencherchali
|
cd871bbc04
|
fix: update rules with more cases
|
2022-11-10 17:04:52 +01:00 |
|
Florian Roth
|
928f07c366
|
Merge pull request #3683 from SigmaHQ/rule-devel
rule: KDC RC4-HMAC downgrade CVE-2022-37966
|
2022-11-09 10:19:04 +01:00 |
|
Yamato Security
|
5de1fd6f2d
|
Rule add: windows access token abuse (#3675)
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-11-09 09:43:15 +01:00 |
|
Florian Roth
|
0de60f2b9f
|
revert: changes in krbrelay service rule
|
2022-11-09 09:33:37 +01:00 |
|
Florian Roth
|
f7b91b0f05
|
rule: kerberos rc4 rule
|
2022-11-09 09:31:31 +01:00 |
|
Florian Roth
|
869b0962b3
|
rule: KDC RC4-HMAC downgrade CVE-2022-37966
|
2022-11-09 09:08:22 +01:00 |
|
Nasreddine Bencherchali
|
fc8eeb7b1e
|
Fix FP
|
2022-11-07 12:11:30 +01:00 |
|
Florian Roth
|
5e9083261a
|
Merge pull request #3665 from nasbench/nasbench-rule-devel
Rule Dev
|
2022-11-01 18:57:31 +01:00 |
|
phantinuss
|
97d5255c2e
|
fix: new FPs found in testing environment
|
2022-11-01 16:19:14 +01:00 |
|
Nasreddine Bencherchali
|
96b7303a31
|
New Rules
|
2022-10-31 20:59:33 +01:00 |
|
Nasreddine Bencherchali
|
fb50c78531
|
Optimize selection
|
2022-10-31 20:57:48 +01:00 |
|
phantinuss
|
8c2b14a7ab
|
Merge pull request #3661 from phantinuss/master
FP fixes
|
2022-10-31 11:44:39 +01:00 |
|
phantinuss
|
91af76417b
|
fix: new code integrity offenders
|
2022-10-31 11:13:56 +01:00 |
|
Florian Roth
|
897580f294
|
Update win_codeintegrity_attempted_dll_load.yml
|
2022-10-29 09:52:36 +02:00 |
|
Florian Roth
|
07cf7ae5fa
|
fix: FP with Code Integrity Attempted DLL Load
|
2022-10-28 16:28:49 +02:00 |
|
phantinuss
|
f7319989e4
|
fix: new FP with Avast
|
2022-10-28 08:47:09 +02:00 |
|
frack113
|
625f05df3c
|
Merge pull request #3646 from nasbench/nasbench-rule-devel
Rule Dev
|
2022-10-28 06:34:48 +02:00 |
|
Nasreddine Bencherchali
|
aeefa4c022
|
Merge branch 'master' into fix-false-positives
|
2022-10-27 11:49:52 +02:00 |
|
phantinuss
|
07faf2b50a
|
fix: add missing \
|
2022-10-27 10:22:49 +02:00 |
|
phantinuss
|
152f22ba01
|
fix: FPs in testing environment
|
2022-10-27 09:46:05 +02:00 |
|
Nasreddine Bencherchali
|
2aff1acccd
|
Fix typo in selection
|
2022-10-27 00:12:58 +02:00 |
|
Nasreddine Bencherchali
|
4be6af3c08
|
Add/Update PAExec Rules
|
2022-10-26 23:27:17 +02:00 |
|
Nasreddine Bencherchali
|
efe0cf5871
|
Add/Update Exchange/Mailbox Rules
|
2022-10-26 23:17:54 +02:00 |
|
Nasreddine Bencherchali
|
6f4250e434
|
Rename Service Install Rules
|
2022-10-26 23:17:02 +02:00 |
|
Nasreddine Bencherchali
|
388624e279
|
Update PsExec Rules
|
2022-10-26 23:15:01 +02:00 |
|
Nasreddine Bencherchali
|
d88ae70256
|
Rename Rule
Renamed the rule to follow the folder convention
|
2022-10-26 18:25:12 +02:00 |
|
Nasreddine Bencherchali
|
8db7382bc9
|
Update win_codeintegrity_attempted_dll_load.yml
|
2022-10-26 11:15:18 +02:00 |
|
Nasreddine Bencherchali
|
bb84e503fa
|
Merge branch 'master' into nasbench-rule-devel
|
2022-10-26 10:39:55 +02:00 |
|
Nasreddine Bencherchali
|
9adbbf36c1
|
Rename Rule
|
2022-10-25 23:48:54 +02:00 |
|
Nasreddine Bencherchali
|
130e1af009
|
Change rule service
|
2022-10-25 20:03:11 +02:00 |
|
Nasreddine Bencherchali
|
9fdc08f17b
|
Add first sshd Rule
|
2022-10-25 19:15:31 +02:00 |
|
phantinuss
|
353e735caa
|
add FP filter for MS Office
|
2022-10-25 14:15:08 +02:00 |
|
Nasreddine Bencherchali
|
d85f085348
|
Update Code Integrity rule
|
2022-10-25 12:29:41 +02:00 |
|
Nasreddine Bencherchali
|
214ba4b2e2
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2022-10-25 12:27:43 +02:00 |
|