Commit Graph

14333 Commits

Author SHA1 Message Date
Nasreddine Bencherchali cd303fa0a4 Merge pull request #3877 from redsand/fp_library_alias_and_use_of_alias
feat: add defender cmdlet alias option
2023-01-12 17:28:39 +01:00
Nasreddine Bencherchali a3fa8e8a90 Merge pull request #3914 from redsand/fp_citrix_receiver
FP: citrix receiver storefront
2023-01-12 17:25:08 +01:00
Tim Shelton 09b3e43afc Removing filter specification in condition 2023-01-12 16:21:58 +00:00
redsand (Tim Shelton) 3007d98844 Merge branch 'SigmaHQ:master' into fp_library_alias_and_use_of_alias 2023-01-12 10:19:47 -06:00
redsand (Tim Shelton) 88308b713c Update rules/windows/powershell/powershell_script/posh_ps_tamper_defender.yml
whatever you guys want, im good with. i like @neo23x0 suggestion

Co-authored-by: Florian Roth <venom14@gmail.com>
2023-01-12 10:14:14 -06:00
Tim Shelton ae51f1c472 FP: citrix receiver storefront 2023-01-12 16:09:36 +00:00
TheLawsOfChaos 52e40d10ef feat: updates multiple mitre tech/sub-tech/tactics (#3913) 2023-01-12 17:04:38 +01:00
Nasreddine Bencherchali 62cc2da296 Merge pull request #3912 from nasbench/nasbench-rule-devel
feat: more appx rules updates
2023-01-12 15:58:34 +01:00
Nasreddine Bencherchali a5df41cf39 fix: update title and description 2023-01-12 15:49:40 +01:00
Nasreddine Bencherchali 9a671e25d9 fix: add missing eid 400 2023-01-12 15:12:20 +01:00
Nasreddine Bencherchali 90c1e45d83 feat: add new reg variant of dev mode 2023-01-12 15:05:53 +01:00
Nasreddine Bencherchali c1e2fec93d Merge pull request #3911 from nasbench/nasbench-rule-devel
feat: test enhancements
2023-01-12 12:45:33 +01:00
Nasreddine Bencherchali 8b38e3ac2c fix: assertion logic 2023-01-12 12:36:33 +01:00
Nasreddine Bencherchali dca48fc125 fix: assert function in test 2023-01-12 12:29:38 +01:00
Nasreddine Bencherchali daee497c47 chore: break config for test 2023-01-12 12:22:28 +01:00
Nasreddine Bencherchali 30c658e2a4 fix: broken logic in test
- Fix ` test_duplicate_detections` test
- Add new test `test_broken_thor_logsource_config` to test for broken Windows eventlog sources
2023-01-12 12:21:58 +01:00
Nasreddine Bencherchali 0ccda79d4e Merge pull request #3908 from nasbench/nasbench-rule-devel
feat: new rules and updates
2023-01-12 11:03:33 +01:00
Nasreddine Bencherchali e7a2e1c169 fix: remove version from name
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-12 10:37:34 +01:00
Nasreddine Bencherchali 0470f45246 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-12 10:36:13 +01:00
Tim Brown 4b52acd2fe feat: add rules for BGP and LDP authentication failures 2023-01-12 01:59:16 +01:00
Nasreddine Bencherchali 67ea98a6db feat: more updates and fixes 2023-01-12 01:05:48 +01:00
Nasreddine Bencherchali dbd21096d7 Merge branch 'master' into nasbench-rule-devel 2023-01-12 00:12:58 +01:00
Nasreddine Bencherchali 79bc248b58 Merge pull request #3909 from nasbench/fix-thor-config-bug
fix: broken thor config
2023-01-12 00:09:49 +01:00
Nasreddine Bencherchali 2f479d1e8e fix: broken config 2023-01-12 00:03:57 +01:00
Nasreddine Bencherchali d0b2e2cbba fix: more fp and duplicate id 2023-01-11 23:47:12 +01:00
Nasreddine Bencherchali b6b1eba014 fix: fp and add related fields 2023-01-11 23:39:15 +01:00
Nasreddine Bencherchali debd658aac feat: new rules related to appx packages 2023-01-11 23:04:37 +01:00
Nasreddine Bencherchali acf4a404d5 feat: add Microsoft-Windows-AppXDeploymentServer/Operational 2023-01-11 22:23:52 +01:00
Nasreddine Bencherchali f4d4526d0f fix: fp found in testing 2023-01-11 20:05:55 +01:00
frack113 fbae1f3055 Merge pull request #3889 from frack113/iso_evtx
Add win_vhdmp_mount_iso.yml
2023-01-11 18:05:50 +01:00
frack113 b75c1de196 Delete win_vhdmp_mount_iso.yml 2023-01-11 17:59:10 +01:00
Nasreddine Bencherchali 80689b769b Merge pull request #3907 from pH-T/master
feat: updated rules for coverage of CVE-2015-2291
2023-01-11 16:42:34 +01:00
Nasreddine Bencherchali e0217640e8 fix: remove duplicate entries 2023-01-11 16:34:03 +01:00
Nasreddine Bencherchali 75b6b4fa59 fix: add missing modified date 2023-01-11 16:28:45 +01:00
Nasreddine Bencherchali 7edac96e63 fix: add modified 2023-01-11 16:27:49 +01:00
pH-T 5cc5f4db6d fix: syntax error 2023-01-11 16:27:17 +01:00
Paul Hager 69ffa7f51b feat: updated rules for coverage of CVE-2015-2291 2023-01-11 16:24:05 +01:00
Nasreddine Bencherchali 93f55874cd Merge pull request #3906 from nasbench/nasbench-rule-devel
feat: enhancements and fp fixes
2023-01-11 11:26:05 +01:00
Nasreddine Bencherchali 8dc2418ea9 fix: some issues 2023-01-11 11:18:54 +01:00
TheLawsOfChaos 8607588a13 11 Files with updates Tactics/techniques/sub-techs (#3904) 2023-01-11 06:30:46 +01:00
Nasreddine Bencherchali 28a3413aa7 feat: updates and enhancements 2023-01-11 01:03:52 +01:00
Nasreddine Bencherchali 5bd38f8ff0 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-11 01:03:08 +01:00
frack113 0f2a7128dd Merge pull request #3905 from frack113/logsource
Update logsource.json
2023-01-10 22:00:38 +01:00
frack113 5cff2d2b3f Update logsource.json 2023-01-10 21:53:35 +01:00
frack113 0c3ba418db Merge pull request #3898 from cyb3rjy0t/patch-2
New rule
2023-01-10 20:47:48 +01:00
frack113 8e7187e861 Rename azure_ad_risky_sign_ins_with_singlefactorauthencation_from_unknown_devices.yml to azure_ad_risky_sign_ins_with_singlefactorauth_from_unknown_devices.yml 2023-01-10 20:37:56 +01:00
Nasreddine Bencherchali 2820210945 fix: broken title 2023-01-10 19:43:19 +01:00
frack113 cb21d5d23e Merge pull request #3903 from frack113/mitre_url
Clean attack.mitre.org techniques ref
2023-01-10 19:32:51 +01:00
Nasreddine Bencherchali 15757c2b7d fix: remove tactic links 2023-01-10 19:20:31 +01:00
frack113 486ee8f435 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-10 19:13:38 +01:00