Commit Graph

379 Commits

Author SHA1 Message Date
yugoslavskiy aeb448cd4d Merge pull request #1171 from alejandroortuno/network-sniffing
[OSCD] MacOS Network Sniffing
2021-01-06 00:15:52 +03:00
yugoslavskiy ebc6451b86 Merge pull request #1170 from alejandroortuno/startup-items
[OSCD] MacOS Startup Items
2021-01-06 00:15:45 +03:00
yugoslavskiy ad739f7f29 Merge pull request #1169 from remotephone/oscd_t1113
[OSCD] - T1113 - macOS Screencapture via builtin screencapture utility
2021-01-06 00:15:37 +03:00
yugoslavskiy d50c081f3f Merge pull request #1168 from remotephone/oscd_t1056_002
[OSCD] macOS - T1056.002 - GUI Input capture
2021-01-06 00:15:30 +03:00
yugoslavskiy 635ac44949 Merge pull request #1132 from remotephone/oscd_t1070_002
[OSCD] Adding t1070_002 - Clear mac system logs
2021-01-05 23:16:57 +03:00
yugoslavskiy 793d271d37 Merge pull request #1131 from oscd-initiative/oscd_sigma_art_macos_task_63
[OSCD] macOS hidden user creation
2021-01-05 23:16:36 +03:00
yugoslavskiy a4101a6808 Merge pull request #1128 from alejandroortuno/local-group
[OSCD] Local System Groups Discovery
2021-01-05 23:14:47 +03:00
yugoslavskiy db66f8365e Merge pull request #1127 from alejandroortuno/account-creation
[OSCD]  MacOS local account creation
2021-01-05 23:14:28 +03:00
yugoslavskiy e492263a31 Merge pull request #1091 from alejandroortuno/sigma-local-account-rule
[OSCD] Local System Accounts Discovery
2021-01-05 23:10:09 +03:00
yugoslavskiy d9a0f6c41a Merge pull request #1090 from alejandroortuno/sigma-cron-rule
[OSCD] Scheduled Task/Job: Cron
2021-01-05 23:09:59 +03:00
yugoslavskiy c8da05fa5d Merge pull request #1086 from remotephone/oscd
[OSCD] T1016 - linux/macOS firewall enumeration
2021-01-05 23:09:15 +03:00
yugoslavskiy caf01c57bf Merge pull request #1083 from omergunal/patch-8
[OSCD] T1082: System Information Discovery - Linux
2021-01-05 23:08:19 +03:00
yugoslavskiy e002ffa404 Merge pull request #1079 from omergunal/patch-6
[OSCD] T1070.004: File Deletion - Linux
2021-01-05 23:06:12 +03:00
yugoslavskiy 1939b815d6 Merge pull request #1078 from omergunal/patch-5
[OSCD] T1070.002: Clear Linux or Mac System Logs - Linux
2021-01-05 23:06:02 +03:00
yugoslavskiy 75feffb016 Merge pull request #1082 from omergunal/patch-7
[OSCD] T1201: Password Policy Discovery - Linux
2021-01-05 23:02:06 +03:00
yugoslavskiy 3ef76437e4 Merge pull request #1055 from omergunal/patch-2
[OSCD] Scheduled Task/Job: At
2021-01-05 22:59:09 +03:00
yugoslavskiy f65e7100ec Merge pull request #1057 from omergunal/patch-4
[OSCD] T1057: Process Discovery
2021-01-05 22:58:35 +03:00
yugoslavskiy 57947fbd39 Merge pull request #1044 from omergunal/patch-1
[OSCD] Linux - Install Root Certificate
2021-01-05 22:56:18 +03:00
yugoslavskiy 733277d490 Merge pull request #1248 from oscd-initiative/oscd_art_macos_task_28_T1083
[OSCD] ART sync, test T1083: File and Directory Discovery (macOS)
2021-01-05 22:55:40 +03:00
yugoslavskiy f825003690 Merge pull request #1239 from alx1m1k/oscd-4
[OSCD] T1529: System Shutdown/Reboot - Lin/macOS
2021-01-05 22:55:14 +03:00
Thomas Patzke 9b4c1662b0 Merge pull request #1240 from alx1m1k/oscd-5
[OSCD] T1070.006: File Time Attribute Change - Lin/macOS
2020-12-30 23:00:54 +01:00
Thomas Patzke 1dcc56a0b0 Merge pull request #1241 from alx1m1k/oscd-6
[OSCD] T1552.001: Credentials In Files - Lin/macOS
2020-12-30 22:59:49 +01:00
Thomas Patzke e0f7dc125c Merge pull request #1244 from oscd-initiative/oscd_art_macos_task_3_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (macOS)
2020-12-30 22:58:26 +01:00
Thomas Patzke 810485993a Merge pull request #1245 from oscd-initiative/oscd_art_linux_task_4_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (Linux)
2020-12-30 22:57:59 +01:00
Thomas Patzke aa5396cb9f Merge pull request #1246 from oscd-initiative/oscd_art_macos_task_14_T1049
[OSCD] ART sync, test T1049: System Network Connections Discovery (macOS)
2020-12-30 22:57:29 +01:00
Thomas Patzke fb9698345b Merge pull request #1247 from oscd-initiative/oscd_art_linux_task_8__T1049
[OSCD] ART sync, test T1049: System Network Connections Discovery (Linux)
2020-12-30 22:57:11 +01:00
Thomas Patzke 6a7991ee96 Merge pull request #1250 from oscd-initiative/oscd_art_macos_task_41_T1518.001
[OSCD] ART sync, test T1518.001: Security Software Discovery (macOS)
2020-12-30 22:41:18 +01:00
Thomas Patzke a88c853237 Merge pull request #1251 from oscd-initiative/oscd_art_linux_task_26_T1518.001
[OSCD] ART sync, test T1518.001: Security Software Discovery (Linux)
2020-12-30 22:40:32 +01:00
Thomas Patzke 436fd37655 Merge pull request #1252 from oscd-initiative/oscd_art_macos_task_55_T1553.001
[OSCD] ART sync, test T1553.001: Gatekeeper Bypass (macOS)
2020-12-30 22:39:36 +01:00
Thomas Patzke 5de952d488 Merge pull request #1253 from oscd-initiative/oscd_art_macos_task_60_T1562.001
[OSCD] ART sync, test T1562.001: Disable or Modify Tools (macOS)
2020-12-30 22:39:15 +01:00
Thomas Patzke e223d34a6e Merge pull request #1257 from alejandroortuno/service-scanning
[OSCD] Network Service Scanning
2020-12-30 22:35:47 +01:00
Thomas Patzke 5c03c4d4ec Merge pull request #1258 from alejandroortuno/applescript
[OSCD] MacOS Applescript
2020-12-30 22:31:30 +01:00
Thomas Patzke 06c168d9b2 Merge pull request #1259 from alejandroortuno/firewall
[OSCD] Firewall Disable (Linux)
2020-12-30 22:30:41 +01:00
Florian Roth 7954684fbf Merge pull request #1260 from alejandroortuno/remote-system-discovery
[OSCD] Remote System Discovery
2020-12-21 18:32:08 +01:00
Florian Roth 64197d0dec Merge pull request #1261 from alejandroortuno/emond
[OSCD] MacOS Emond Launch Daemon
2020-12-21 18:30:56 +01:00
yugoslavskiy 378f663502 Update lnx_clear_logs.yml 2020-12-02 01:28:29 +01:00
yugoslavskiy 6ce08935bb Update lnx_file_deletion.yml 2020-12-02 01:27:35 +01:00
yugoslavskiy 1c4c5af99f Update lnx_clear_logs.yml 2020-12-02 01:24:59 +01:00
Ömer Günal 4ab522815b Update lnx_clear_logs.yml 2020-12-01 21:28:12 +03:00
Ömer Günal d0bb6e9e81 Update lnx_file_deletion.yml 2020-12-01 21:24:57 +03:00
Florian Roth c17c034cb5 Changed selections and condition
see manpage for security tool on macOS
https://gist.github.com/Capybara/6228955
2020-11-27 19:23:31 +01:00
Tim I 78d201ad15 Fix value modifier and add a slash 2020-11-24 23:06:21 +03:00
Alejandro Ortuno 000c038ede Retrigger tests 2020-11-20 09:30:43 +01:00
Alejandro Ortuno cfcda8d25f Trigger new test execution 2020-11-20 09:29:09 +01:00
Ömer Günal 1582c5230a Update lnx_process_discovery.yml 2020-11-18 23:25:15 +03:00
Thomas Patzke 199a897f75 Fix rule indent 2020-11-17 10:12:55 +01:00
yugoslavskiy 2939b33ab5 Update lnx_network_service_scanning.yml 2020-11-16 01:00:09 +01:00
Ömer Günal edc416a1d8 Update lnx_system_info_discovery.yml 2020-11-14 19:24:23 +03:00
Ömer Günal 821bdf8ab4 Update lnx_install_root_certificate.yml 2020-11-14 19:19:28 +03:00
Ömer Günal 19cad11a4a Update lnx_system_info_discovery.yml 2020-11-10 20:11:49 +03:00