Commit Graph

1379 Commits

Author SHA1 Message Date
frack113 a674ee246b Update Title (#3739) 2022-11-30 11:44:15 +01:00
Nasreddine Bencherchali 4b9075e557 feat: new rules related to service creation
New service creation rules related to remote software tools
2022-11-28 12:09:00 +01:00
frack113 c820216541 Update Title (#3733) 2022-11-28 06:43:17 +01:00
frack113 cd4121d966 Update Title (#3731)
Co-authored-by: Florian Roth <venom14@gmail.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-11-27 19:19:27 +01:00
Qasim Qlf ed54bf44a5 Minor Fix 2022-11-22 18:13:34 +05:00
Nasreddine Bencherchali 87b709a3e6 feat: add missing /r to cmd 2022-11-18 13:45:01 +01:00
Nasreddine Bencherchali 6603ca9202 fix: update rules to not use regex 2022-11-18 11:16:13 +01:00
Nasreddine Bencherchali 569d1d757a fix: remove non existent eid and fix #2744 2022-11-15 22:58:19 +01:00
Florian Roth 187cb6b47e Merge pull request #3694 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-11-15 09:35:45 +01:00
phantinuss 64d10f845a fix: FPs in testing environment 2022-11-14 08:54:47 +01:00
Florian Roth 0fb1295157 fix: FPs noticed with Aurora 2022-11-13 20:26:03 +01:00
Nasreddine Bencherchali 04b7b92b64 fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2022-11-11 10:03:24 +01:00
Nasreddine Bencherchali 0a51dcdf5c fix: rename rule to reflect new title 2022-11-10 18:24:36 +01:00
Nasreddine Bencherchali 1ab9e9640e fix: enhance description 2022-11-10 18:19:39 +01:00
Nasreddine Bencherchali f09ea65ec4 fix: update code integrity rules 2022-11-10 17:43:22 +01:00
Nasreddine Bencherchali 30869e1b2b fix: fp with defender def updates 2022-11-10 17:15:22 +01:00
Nasreddine Bencherchali cd871bbc04 fix: update rules with more cases 2022-11-10 17:04:52 +01:00
Florian Roth 928f07c366 Merge pull request #3683 from SigmaHQ/rule-devel
rule: KDC RC4-HMAC downgrade CVE-2022-37966
2022-11-09 10:19:04 +01:00
Yamato Security 5de1fd6f2d Rule add: windows access token abuse (#3675)
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-11-09 09:43:15 +01:00
Florian Roth 0de60f2b9f revert: changes in krbrelay service rule 2022-11-09 09:33:37 +01:00
Florian Roth f7b91b0f05 rule: kerberos rc4 rule 2022-11-09 09:31:31 +01:00
Florian Roth 869b0962b3 rule: KDC RC4-HMAC downgrade CVE-2022-37966 2022-11-09 09:08:22 +01:00
Nasreddine Bencherchali fc8eeb7b1e Fix FP 2022-11-07 12:11:30 +01:00
Florian Roth 5e9083261a Merge pull request #3665 from nasbench/nasbench-rule-devel
Rule Dev
2022-11-01 18:57:31 +01:00
phantinuss 97d5255c2e fix: new FPs found in testing environment 2022-11-01 16:19:14 +01:00
Nasreddine Bencherchali 96b7303a31 New Rules 2022-10-31 20:59:33 +01:00
Nasreddine Bencherchali fb50c78531 Optimize selection 2022-10-31 20:57:48 +01:00
phantinuss 8c2b14a7ab Merge pull request #3661 from phantinuss/master
FP fixes
2022-10-31 11:44:39 +01:00
phantinuss 91af76417b fix: new code integrity offenders 2022-10-31 11:13:56 +01:00
Florian Roth 897580f294 Update win_codeintegrity_attempted_dll_load.yml 2022-10-29 09:52:36 +02:00
Florian Roth 07cf7ae5fa fix: FP with Code Integrity Attempted DLL Load 2022-10-28 16:28:49 +02:00
phantinuss f7319989e4 fix: new FP with Avast 2022-10-28 08:47:09 +02:00
frack113 625f05df3c Merge pull request #3646 from nasbench/nasbench-rule-devel
Rule Dev
2022-10-28 06:34:48 +02:00
Nasreddine Bencherchali aeefa4c022 Merge branch 'master' into fix-false-positives 2022-10-27 11:49:52 +02:00
phantinuss 07faf2b50a fix: add missing \ 2022-10-27 10:22:49 +02:00
phantinuss 152f22ba01 fix: FPs in testing environment 2022-10-27 09:46:05 +02:00
Nasreddine Bencherchali 2aff1acccd Fix typo in selection 2022-10-27 00:12:58 +02:00
Nasreddine Bencherchali 4be6af3c08 Add/Update PAExec Rules 2022-10-26 23:27:17 +02:00
Nasreddine Bencherchali efe0cf5871 Add/Update Exchange/Mailbox Rules 2022-10-26 23:17:54 +02:00
Nasreddine Bencherchali 6f4250e434 Rename Service Install Rules 2022-10-26 23:17:02 +02:00
Nasreddine Bencherchali 388624e279 Update PsExec Rules 2022-10-26 23:15:01 +02:00
Nasreddine Bencherchali d88ae70256 Rename Rule
Renamed the rule to follow the folder convention
2022-10-26 18:25:12 +02:00
Nasreddine Bencherchali 8db7382bc9 Update win_codeintegrity_attempted_dll_load.yml 2022-10-26 11:15:18 +02:00
Nasreddine Bencherchali bb84e503fa Merge branch 'master' into nasbench-rule-devel 2022-10-26 10:39:55 +02:00
Nasreddine Bencherchali 9adbbf36c1 Rename Rule 2022-10-25 23:48:54 +02:00
Nasreddine Bencherchali 130e1af009 Change rule service 2022-10-25 20:03:11 +02:00
Nasreddine Bencherchali 9fdc08f17b Add first sshd Rule 2022-10-25 19:15:31 +02:00
phantinuss 353e735caa add FP filter for MS Office 2022-10-25 14:15:08 +02:00
Nasreddine Bencherchali d85f085348 Update Code Integrity rule 2022-10-25 12:29:41 +02:00
Nasreddine Bencherchali 214ba4b2e2 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-10-25 12:27:43 +02:00