Jonhnathan
|
e26e5a1e7e
|
Update lnx_auditd_create_account.yml
|
2020-10-15 23:07:39 -03:00 |
|
Jonhnathan
|
8fd768aa66
|
Update lnx_susp_ssh.yml
|
2020-10-15 23:05:53 -03:00 |
|
Jonhnathan
|
d4284e60f9
|
Update lnx_susp_named.yml
|
2020-10-15 23:04:16 -03:00 |
|
Jonhnathan
|
83bad3de98
|
Update lnx_sudo_cve_2019_14287.yml
|
2020-10-15 23:03:40 -03:00 |
|
Jonhnathan
|
0ca17e88f6
|
Update lnx_setgid_setuid.yml
|
2020-10-15 22:55:41 -03:00 |
|
Jonhnathan
|
68ad66f390
|
Update lnx_proxy_connection.yml
|
2020-10-15 22:54:27 -03:00 |
|
Jonhnathan
|
41396636f9
|
Update lnx_file_copy.yml
|
2020-10-15 22:53:20 -03:00 |
|
Jonhnathan
|
6185640442
|
Update lnx_clamav.yml
|
2020-10-15 22:49:42 -03:00 |
|
Yugoslavskiy Daniil
|
d8a6048492
|
update /macos_create_hidden_account.yml
|
2020-10-16 02:05:22 +02:00 |
|
Alejandro Ortuno
|
2ef52dbfd8
|
Initial Sigma Rule
|
2020-10-14 10:24:59 +02:00 |
|
Alejandro Ortuno
|
bf8426d71b
|
Initial commit of sigma rule
|
2020-10-14 10:14:00 +02:00 |
|
Alejandro Ortuno
|
75a05db446
|
Add slash to bypass testing
|
2020-10-14 08:50:15 +02:00 |
|
remotephone@gmail.com
|
8e7fbbd147
|
fixing UUID and description
|
2020-10-14 00:54:51 -05:00 |
|
remotephone@gmail.com
|
ed22c8e0fe
|
adding macos screencapture rule
|
2020-10-14 00:51:55 -05:00 |
|
remotephone@gmail.com
|
8bbde90328
|
adding line at end of file
|
2020-10-14 00:05:28 -05:00 |
|
remotephone@gmail.com
|
3cddb86b70
|
updating tags
|
2020-10-14 00:01:30 -05:00 |
|
remotephone@gmail.com
|
7343936653
|
adding gui input capture, first iteration
|
2020-10-13 23:59:53 -05:00 |
|
remotephone@gmail.com
|
df20d2a5d2
|
adding new line at end of file
|
2020-10-13 22:44:02 -05:00 |
|
remotephone@gmail.com
|
7e002fcb5f
|
updating selections to make query more efficient and less prone to evasion
|
2020-10-13 22:17:26 -05:00 |
|
remotephone@gmail.com
|
56952ecdd4
|
updating to select commandline arguments correctly for macos rule, and cleaning up description across both rules
|
2020-10-13 22:09:37 -05:00 |
|
Alejandro Ortuno
|
c03a696762
|
additional modifications on commands and process names
|
2020-10-13 11:00:06 +02:00 |
|
Alejandro Ortuno
|
50fde8c13f
|
minor changes on command line
|
2020-10-13 10:55:29 +02:00 |
|
Alejandro Ortuno
|
30bd626d76
|
Split command line and do contains all.
|
2020-10-13 10:51:00 +02:00 |
|
Alejandro Ortuno
|
7459bcd08c
|
Use process_creation for the detection
|
2020-10-13 10:41:50 +02:00 |
|
remotephone@gmail.com
|
a85c19db17
|
updating files to cover broader network discovery logic, renaming alert, adding recommended changes
|
2020-10-13 00:39:53 -05:00 |
|
remotephone@gmail.com
|
7d49db3988
|
updating falsepositives documentation to remove line that's not applicable
|
2020-10-12 23:19:02 -05:00 |
|
remotephone@gmail.com
|
89c8a589a5
|
updating search syntax, splitting process name and cmdline and adding category
|
2020-10-12 22:49:19 -05:00 |
|
remotephone@gmail.com
|
476a3c04d9
|
Adding t1070_002
|
2020-10-12 00:01:10 -05:00 |
|
remotephone@gmail.com
|
781c7ce6dc
|
Cleaning up falsepositives section of both rules
|
2020-10-11 23:52:47 -05:00 |
|
remotephone@gmail.com
|
48edc674bd
|
updating keywords to CommandLine|contains and splitting rule into two
|
2020-10-11 22:43:28 -05:00 |
|
Yugoslavskiy Daniil
|
e52baddda2
|
improve descriptin
|
2020-10-11 22:11:03 +02:00 |
|
Yugoslavskiy Daniil
|
7dec19afca
|
add macos_create_hidden_account.yml; part of the oscd initiative task number 63 of the issue #1012
|
2020-10-11 22:01:05 +02:00 |
|
Alejandro Ortuno
|
d17faf8234
|
Local groups discovery sigma rules
|
2020-10-11 18:15:53 +02:00 |
|
Alejandro Ortuno
|
3358dd47ea
|
macos local account creation
|
2020-10-11 17:56:29 +02:00 |
|
Alejandro Ortuno
|
418a9d5a02
|
Use endswith with processname
|
2020-10-11 09:37:08 +02:00 |
|
Alejandro Ortuno
|
748dccc289
|
additional changes to split processname and commandline
|
2020-10-10 13:11:17 +02:00 |
|
Alejandro Ortuno
|
04f415c80b
|
Added the sigma rules per OS
|
2020-10-08 13:23:11 +02:00 |
|
Alejandro Ortuno
|
c5605ae8b6
|
Scheduled Cron Task/Job sigma rule
|
2020-10-08 13:15:02 +02:00 |
|
remotephone@gmail.com
|
e967cce211
|
change new lines to LF instead of CLRF
|
2020-10-07 23:02:03 -05:00 |
|
remotephone@gmail.com
|
9802704a2b
|
not sure why i'm failing the tests on a line I didn't change. copying format from another file
|
2020-10-07 22:54:31 -05:00 |
|
remotephone@gmail.com
|
ff2ba5f876
|
double checking new line characters
|
2020-10-07 22:43:38 -05:00 |
|
remotephone@gmail.com
|
83ed39f95c
|
adding UID, renaming
|
2020-10-07 22:25:54 -05:00 |
|
remotephone@gmail.com
|
4486c3ffc9
|
adding new line at end of file
|
2020-10-07 22:11:05 -05:00 |
|
remotephone@gmail.com
|
cde0020d30
|
T1016 detection rules
|
2020-10-07 22:09:15 -05:00 |
|
Ömer Günal
|
eac5ac9fc1
|
removed duplicate filter
|
2020-10-08 00:18:38 +03:00 |
|
Ömer Günal
|
e6588c08f4
|
Create lnx_system_info_discovery.yml
|
2020-10-08 00:15:46 +03:00 |
|
Ömer Günal
|
2cea3800de
|
Create lnx_password_policy_discovery.yml
|
2020-10-08 00:14:40 +03:00 |
|
Ömer Günal
|
f00e79d123
|
Create lnx_file_deletion.yml
|
2020-10-07 22:28:37 +03:00 |
|
Ömer Günal
|
18821d2255
|
Create lnx_clear_logs.yml
|
2020-10-07 22:27:06 +03:00 |
|
Ömer Günal
|
d44ef84b55
|
Update lnx_process_discovery.yml
|
2020-10-07 22:26:02 +03:00 |
|