Commit Graph

8858 Commits

Author SHA1 Message Date
Nasreddine Bencherchali cd303fa0a4 Merge pull request #3877 from redsand/fp_library_alias_and_use_of_alias
feat: add defender cmdlet alias option
2023-01-12 17:28:39 +01:00
Nasreddine Bencherchali a3fa8e8a90 Merge pull request #3914 from redsand/fp_citrix_receiver
FP: citrix receiver storefront
2023-01-12 17:25:08 +01:00
Tim Shelton 09b3e43afc Removing filter specification in condition 2023-01-12 16:21:58 +00:00
redsand (Tim Shelton) 3007d98844 Merge branch 'SigmaHQ:master' into fp_library_alias_and_use_of_alias 2023-01-12 10:19:47 -06:00
redsand (Tim Shelton) 88308b713c Update rules/windows/powershell/powershell_script/posh_ps_tamper_defender.yml
whatever you guys want, im good with. i like @neo23x0 suggestion

Co-authored-by: Florian Roth <venom14@gmail.com>
2023-01-12 10:14:14 -06:00
Tim Shelton ae51f1c472 FP: citrix receiver storefront 2023-01-12 16:09:36 +00:00
Nasreddine Bencherchali a5df41cf39 fix: update title and description 2023-01-12 15:49:40 +01:00
Nasreddine Bencherchali 9a671e25d9 fix: add missing eid 400 2023-01-12 15:12:20 +01:00
Nasreddine Bencherchali 90c1e45d83 feat: add new reg variant of dev mode 2023-01-12 15:05:53 +01:00
Nasreddine Bencherchali e7a2e1c169 fix: remove version from name
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-12 10:37:34 +01:00
Nasreddine Bencherchali 0470f45246 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-12 10:36:13 +01:00
Nasreddine Bencherchali 67ea98a6db feat: more updates and fixes 2023-01-12 01:05:48 +01:00
Nasreddine Bencherchali d0b2e2cbba fix: more fp and duplicate id 2023-01-11 23:47:12 +01:00
Nasreddine Bencherchali b6b1eba014 fix: fp and add related fields 2023-01-11 23:39:15 +01:00
Nasreddine Bencherchali debd658aac feat: new rules related to appx packages 2023-01-11 23:04:37 +01:00
Nasreddine Bencherchali f4d4526d0f fix: fp found in testing 2023-01-11 20:05:55 +01:00
Nasreddine Bencherchali e0217640e8 fix: remove duplicate entries 2023-01-11 16:34:03 +01:00
Nasreddine Bencherchali 75b6b4fa59 fix: add missing modified date 2023-01-11 16:28:45 +01:00
Nasreddine Bencherchali 7edac96e63 fix: add modified 2023-01-11 16:27:49 +01:00
pH-T 5cc5f4db6d fix: syntax error 2023-01-11 16:27:17 +01:00
Paul Hager 69ffa7f51b feat: updated rules for coverage of CVE-2015-2291 2023-01-11 16:24:05 +01:00
Nasreddine Bencherchali 8dc2418ea9 fix: some issues 2023-01-11 11:18:54 +01:00
Nasreddine Bencherchali 28a3413aa7 feat: updates and enhancements 2023-01-11 01:03:52 +01:00
Nasreddine Bencherchali 5bd38f8ff0 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-11 01:03:08 +01:00
frack113 49d7eb244f Remove mitre url 2023-01-10 18:24:22 +01:00
frack113 4023bf2c83 Remove mitre url 2023-01-10 18:09:04 +01:00
Nasreddine Bencherchali 9d6a41edc6 fix: fp found in testing 2023-01-10 15:11:40 +01:00
frack113 c3fabfe2a8 Update image_load_side_load_non_existent_dlls.yml 2023-01-10 10:41:48 +01:00
Nasreddine Bencherchali b80b358427 fix: fp with defender 2023-01-10 00:44:52 +01:00
Nasreddine Bencherchali b0e3bb5d28 fix: broken condition 2023-01-10 00:33:38 +01:00
Nasreddine Bencherchali 81f75c1d2e feat: updates and enhancements 2023-01-10 00:13:37 +01:00
Nasreddine Bencherchali 17aaf7fdcd Merge pull request #3888 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
2023-01-09 10:39:54 +01:00
Florian Roth bcce3a85aa Merge branch 'master' into rule-devel 2023-01-09 09:56:21 +01:00
Florian Roth 0a9be5922c fix: shortened author list to make it fit in VARCHAR(255) DB fields 2023-01-09 09:47:26 +01:00
Florian Roth 7f45405867 fix: FPs noticed with Aurora 2023-01-09 09:46:16 +01:00
frack113 7f653db16c Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-08 14:45:39 +01:00
frack113 2cf8529657 Add posh_ps_susp_set_alias 2023-01-08 09:55:27 +01:00
Nasreddine Bencherchali 5ea2e76162 Merge pull request #3884 from frack113/UnhookingPatch
Add proc_access_win_invoke_patchingapi
2023-01-07 13:15:32 +01:00
frack113 f08f3706f7 Update proc_access_win_invoke_patchingapi.yml 2023-01-07 13:04:57 +01:00
Nasreddine Bencherchali 69dbdc2a34 fix: apply suggestions from code review 2023-01-07 13:03:21 +01:00
frack113 24264407d9 Update detection 2023-01-07 12:32:27 +01:00
frack113 4dbfebf65c Add proc_access_win_invoke_patchingapi 2023-01-07 10:35:28 +01:00
frack113 d6059d801b Filename normalisation 2023-01-07 08:52:11 +01:00
frack113 f015c940f8 Merge pull request #3880 from frack113/from_VT_screen
Add proc_creation_win_double_ext_parent
2023-01-06 18:31:47 +01:00
frack113 97ec1c4d54 Add related 2023-01-06 18:22:36 +01:00
frack113 3346a6d3e4 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-06 18:21:06 +01:00
frack113 679d1ee0ed Add more ext 2023-01-06 18:17:01 +01:00
Nasreddine Bencherchali 18a77e79e3 fix: multiple issues 2023-01-06 18:04:04 +01:00
Nasreddine Bencherchali 2e85903a59 fix: broken condition 2023-01-06 17:41:30 +01:00
Nasreddine Bencherchali df2c86f941 fix: separate selection and add missing modified 2023-01-06 17:41:01 +01:00