frack113
|
0f3eefdc9c
|
Update title (#3746)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-02 18:10:43 +01:00 |
|
frack113
|
a674ee246b
|
Update Title (#3739)
|
2022-11-30 11:44:15 +01:00 |
|
jstnk9
|
647f6dc2ef
|
Update title (#3734)
|
2022-11-29 07:36:45 +01:00 |
|
Nasreddine Bencherchali
|
b6dce4b6a5
|
feat: general fixes
|
2022-11-22 01:22:36 +01:00 |
|
Nasreddine Bencherchali
|
13fbab9a87
|
Update image_load_susp_python_image_load.yml
|
2022-11-08 17:33:45 +01:00 |
|
Nasreddine Bencherchali
|
f312455db5
|
Update rules/windows/image_load/image_load_alternate_powershell_hosts_moduleload.yml
|
2022-11-08 17:26:24 +01:00 |
|
Nasreddine Bencherchali
|
ae2c09f866
|
Update rules/windows/image_load/image_load_in_memory_powershell.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-11-08 17:25:53 +01:00 |
|
Nasreddine Bencherchali
|
024d76d5e5
|
Fix typo in conditions
|
2022-11-08 12:10:20 +01:00 |
|
Nasreddine Bencherchali
|
220e9c2c90
|
Fix FP
|
2022-11-08 12:05:38 +01:00 |
|
phantinuss
|
0165f9b05b
|
Merge pull request #3664 from frack113/DeleteShadowCopies
Add image_load_susp_vss_dll_load
|
2022-11-01 12:32:04 +01:00 |
|
Nasreddine Bencherchali
|
4bdc286a02
|
Update rules/windows/image_load/image_load_susp_python_image_load.yml
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
|
2022-11-01 11:10:07 +01:00 |
|
phantinuss
|
b04f8c3db0
|
fix: description
|
2022-11-01 10:53:37 +01:00 |
|
Nasreddine Bencherchali
|
0aff47946d
|
Fix FP
|
2022-11-01 01:05:42 +01:00 |
|
frack113
|
bb94f814af
|
Update image_load_susp_vss_ps_load.yml
|
2022-10-31 20:24:22 +01:00 |
|
frack113
|
2469d525c1
|
Update image_load_susp_vss_dll_load.yml
|
2022-10-31 20:17:15 +01:00 |
|
frack113
|
5d3275aaca
|
Merge branch 'master' into DeleteShadowCopies
|
2022-10-31 19:43:23 +01:00 |
|
frack113
|
a1fef566bd
|
update filter image
|
2022-10-31 19:40:07 +01:00 |
|
frack113
|
f27ddc8a0f
|
Update rules/windows/image_load/image_load_susp_vss_dll_load.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-31 19:33:13 +01:00 |
|
frack113
|
92ffbff5dc
|
Add image_load_susp_vss_dll_load
|
2022-10-31 18:40:46 +01:00 |
|
phantinuss
|
2788fba40d
|
fix: FPs found with Aurora
|
2022-10-31 11:31:30 +01:00 |
|
Nasreddine Bencherchali
|
9c10585a34
|
fix: fix fp in testing
|
2022-10-28 18:11:30 +02:00 |
|
Nasreddine Bencherchali
|
bb84e503fa
|
Merge branch 'master' into nasbench-rule-devel
|
2022-10-26 10:39:55 +02:00 |
|
frack113
|
a3eed2b760
|
Order yaml field
|
2022-10-26 09:42:26 +02:00 |
|
Nasreddine Bencherchali
|
cd863c75b9
|
Update image_load_side_load_antivirus.yml
|
2022-10-25 23:52:15 +02:00 |
|
Nasreddine Bencherchali
|
ef5f672a64
|
Update image_load_side_load_dbghelp_dll.yml
|
2022-10-25 12:48:52 +02:00 |
|
Nasreddine Bencherchali
|
e14dedb3e3
|
Update image_load_side_load_dbghelp_dll.yml
|
2022-10-25 12:33:49 +02:00 |
|
Nasreddine Bencherchali
|
205cb7bc2e
|
Update image_load_side_load_dbgcore_dll.yml
|
2022-10-25 12:30:35 +02:00 |
|
Nasreddine Bencherchali
|
062acaad6b
|
Add more DLLs for Sideloading
|
2022-10-25 12:22:29 +02:00 |
|
Nasreddine Bencherchali
|
3c9dd2a959
|
Update image_load_uipromptforcreds_dlls.yml
|
2022-10-24 13:45:10 +02:00 |
|
phantinuss
|
5bf0c43984
|
fix: FPs in testing in connection to Aurora
|
2022-10-21 17:29:34 +02:00 |
|
phantinuss
|
a5b08d5b9c
|
fix: FPs on test machine
|
2022-10-18 16:39:04 +02:00 |
|
Florian Roth
|
0d5dba2d94
|
Merge pull request #3587 from nasbench/fix-false-positives
Fix False Positives
|
2022-10-14 10:22:24 +02:00 |
|
Nasreddine Bencherchali
|
bf9bfa9a97
|
Add more FP filters
|
2022-10-13 12:36:25 +02:00 |
|
phantinuss
|
ca58e92d52
|
fix: FP found in testing environment
|
2022-10-12 16:59:25 +02:00 |
|
Nasreddine Bencherchali
|
563a3d5646
|
Reduce level to medium
|
2022-10-11 14:04:14 +02:00 |
|
Nasreddine Bencherchali
|
bf28e42f01
|
Fix FP Found In Testing
|
2022-10-10 17:33:14 +02:00 |
|
frack113
|
cf7a348028
|
Fix related
|
2022-10-09 17:28:05 +02:00 |
|
frack113
|
931fb30853
|
old experimental rule promotion
|
2022-10-09 16:54:04 +02:00 |
|
Florian Roth
|
e2a172e257
|
Merge pull request #3569 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-10-07 22:52:24 +02:00 |
|
Florian Roth
|
ee47f14dbe
|
fix: more changes
|
2022-10-07 22:36:21 +02:00 |
|
Florian Roth
|
c76b488941
|
fix: FPs during os upgrade
|
2022-10-07 22:31:13 +02:00 |
|
Florian Roth
|
4a298c56ce
|
fix: FPs during Windows upgrade
|
2022-10-07 22:13:47 +02:00 |
|
Nasreddine Bencherchali
|
adae180bc2
|
Update image_load_uipromptforcreds_dlls.yml
|
2022-10-07 16:49:02 +02:00 |
|
Nasreddine Bencherchali
|
cdd9aff032
|
Fix FP
|
2022-09-29 11:20:08 +02:00 |
|
Nasreddine Bencherchali
|
e3b3265240
|
Update image_load_side_load_from_non_system_location.yml
|
2022-09-28 10:48:30 +02:00 |
|
Florian Roth
|
e6d7ba8224
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-09-27 00:20:07 +02:00 |
|
Florian Roth
|
0503e2b8f7
|
fix: FPs on Azure
|
2022-09-27 00:17:53 +02:00 |
|
phantinuss
|
b7f20b884c
|
fix: FPs from new evtx-baseline
|
2022-09-21 13:51:19 +02:00 |
|
Nasreddine Bencherchali
|
4a74129048
|
Fix after review
|
2022-09-21 13:12:21 +02:00 |
|
Nasreddine Bencherchali
|
59530f49d4
|
Fix more FP in testing
|
2022-09-21 11:53:39 +02:00 |
|