Commit Graph

317 Commits

Author SHA1 Message Date
frack113 0f3eefdc9c Update title (#3746)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-02 18:10:43 +01:00
frack113 a674ee246b Update Title (#3739) 2022-11-30 11:44:15 +01:00
jstnk9 647f6dc2ef Update title (#3734) 2022-11-29 07:36:45 +01:00
Nasreddine Bencherchali b6dce4b6a5 feat: general fixes 2022-11-22 01:22:36 +01:00
Nasreddine Bencherchali 13fbab9a87 Update image_load_susp_python_image_load.yml 2022-11-08 17:33:45 +01:00
Nasreddine Bencherchali f312455db5 Update rules/windows/image_load/image_load_alternate_powershell_hosts_moduleload.yml 2022-11-08 17:26:24 +01:00
Nasreddine Bencherchali ae2c09f866 Update rules/windows/image_load/image_load_in_memory_powershell.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-11-08 17:25:53 +01:00
Nasreddine Bencherchali 024d76d5e5 Fix typo in conditions 2022-11-08 12:10:20 +01:00
Nasreddine Bencherchali 220e9c2c90 Fix FP 2022-11-08 12:05:38 +01:00
phantinuss 0165f9b05b Merge pull request #3664 from frack113/DeleteShadowCopies
Add image_load_susp_vss_dll_load
2022-11-01 12:32:04 +01:00
Nasreddine Bencherchali 4bdc286a02 Update rules/windows/image_load/image_load_susp_python_image_load.yml
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2022-11-01 11:10:07 +01:00
phantinuss b04f8c3db0 fix: description 2022-11-01 10:53:37 +01:00
Nasreddine Bencherchali 0aff47946d Fix FP 2022-11-01 01:05:42 +01:00
frack113 bb94f814af Update image_load_susp_vss_ps_load.yml 2022-10-31 20:24:22 +01:00
frack113 2469d525c1 Update image_load_susp_vss_dll_load.yml 2022-10-31 20:17:15 +01:00
frack113 5d3275aaca Merge branch 'master' into DeleteShadowCopies 2022-10-31 19:43:23 +01:00
frack113 a1fef566bd update filter image 2022-10-31 19:40:07 +01:00
frack113 f27ddc8a0f Update rules/windows/image_load/image_load_susp_vss_dll_load.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-31 19:33:13 +01:00
frack113 92ffbff5dc Add image_load_susp_vss_dll_load 2022-10-31 18:40:46 +01:00
phantinuss 2788fba40d fix: FPs found with Aurora 2022-10-31 11:31:30 +01:00
Nasreddine Bencherchali 9c10585a34 fix: fix fp in testing 2022-10-28 18:11:30 +02:00
Nasreddine Bencherchali bb84e503fa Merge branch 'master' into nasbench-rule-devel 2022-10-26 10:39:55 +02:00
frack113 a3eed2b760 Order yaml field 2022-10-26 09:42:26 +02:00
Nasreddine Bencherchali cd863c75b9 Update image_load_side_load_antivirus.yml 2022-10-25 23:52:15 +02:00
Nasreddine Bencherchali ef5f672a64 Update image_load_side_load_dbghelp_dll.yml 2022-10-25 12:48:52 +02:00
Nasreddine Bencherchali e14dedb3e3 Update image_load_side_load_dbghelp_dll.yml 2022-10-25 12:33:49 +02:00
Nasreddine Bencherchali 205cb7bc2e Update image_load_side_load_dbgcore_dll.yml 2022-10-25 12:30:35 +02:00
Nasreddine Bencherchali 062acaad6b Add more DLLs for Sideloading 2022-10-25 12:22:29 +02:00
Nasreddine Bencherchali 3c9dd2a959 Update image_load_uipromptforcreds_dlls.yml 2022-10-24 13:45:10 +02:00
phantinuss 5bf0c43984 fix: FPs in testing in connection to Aurora 2022-10-21 17:29:34 +02:00
phantinuss a5b08d5b9c fix: FPs on test machine 2022-10-18 16:39:04 +02:00
Florian Roth 0d5dba2d94 Merge pull request #3587 from nasbench/fix-false-positives
Fix False Positives
2022-10-14 10:22:24 +02:00
Nasreddine Bencherchali bf9bfa9a97 Add more FP filters 2022-10-13 12:36:25 +02:00
phantinuss ca58e92d52 fix: FP found in testing environment 2022-10-12 16:59:25 +02:00
Nasreddine Bencherchali 563a3d5646 Reduce level to medium 2022-10-11 14:04:14 +02:00
Nasreddine Bencherchali bf28e42f01 Fix FP Found In Testing 2022-10-10 17:33:14 +02:00
frack113 cf7a348028 Fix related 2022-10-09 17:28:05 +02:00
frack113 931fb30853 old experimental rule promotion 2022-10-09 16:54:04 +02:00
Florian Roth e2a172e257 Merge pull request #3569 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-10-07 22:52:24 +02:00
Florian Roth ee47f14dbe fix: more changes 2022-10-07 22:36:21 +02:00
Florian Roth c76b488941 fix: FPs during os upgrade 2022-10-07 22:31:13 +02:00
Florian Roth 4a298c56ce fix: FPs during Windows upgrade 2022-10-07 22:13:47 +02:00
Nasreddine Bencherchali adae180bc2 Update image_load_uipromptforcreds_dlls.yml 2022-10-07 16:49:02 +02:00
Nasreddine Bencherchali cdd9aff032 Fix FP 2022-09-29 11:20:08 +02:00
Nasreddine Bencherchali e3b3265240 Update image_load_side_load_from_non_system_location.yml 2022-09-28 10:48:30 +02:00
Florian Roth e6d7ba8224 Merge branch 'master' into aurora-false-positive-fixing 2022-09-27 00:20:07 +02:00
Florian Roth 0503e2b8f7 fix: FPs on Azure 2022-09-27 00:17:53 +02:00
phantinuss b7f20b884c fix: FPs from new evtx-baseline 2022-09-21 13:51:19 +02:00
Nasreddine Bencherchali 4a74129048 Fix after review 2022-09-21 13:12:21 +02:00
Nasreddine Bencherchali 59530f49d4 Fix more FP in testing 2022-09-21 11:53:39 +02:00