frack113
|
4acc692633
|
Update proc_creation_win_susp_certutil_command.yml
|
2022-10-12 06:28:34 +02:00 |
|
frack113
|
d5b6451f90
|
Fix modified
|
2022-10-11 20:30:31 +02:00 |
|
Gude5
|
2a1233c965
|
Updated some rules after review
|
2022-10-11 16:31:56 +02:00 |
|
phantinuss
|
af9d04aa9c
|
fix: FPs occurring when using winget upgrade
|
2022-10-11 16:25:03 +02:00 |
|
Nasreddine Bencherchali
|
0e40a65bef
|
Fix FP caused by short atoms
Added spaces to avoid fp
|
2022-10-11 14:37:34 +02:00 |
|
Nasreddine Bencherchali
|
563a3d5646
|
Reduce level to medium
|
2022-10-11 14:04:14 +02:00 |
|
Tim Rauch
|
cd6ee66a38
|
Updated some rules
|
2022-10-11 13:48:42 +02:00 |
|
Tim Rauch
|
d84e281e96
|
Updated cbb9e3d1-2386-4e59-912e-62f1484f7a89
|
2022-10-11 13:42:24 +02:00 |
|
Tim Rauch
|
c4fec44e5b
|
Updated some rules
|
2022-10-11 13:28:59 +02:00 |
|
Tim Rauch
|
4ab6fe537a
|
Updated some rules
|
2022-10-11 12:38:23 +02:00 |
|
Florian Roth
|
8d9c11b26e
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2022-10-11 11:40:07 +02:00 |
|
Florian Roth
|
5ad51c4dea
|
refactor: additional Rubeus indicators
|
2022-10-11 11:40:03 +02:00 |
|
Tim Rauch
|
3454738439
|
Merge branch 'master'
|
2022-10-11 11:32:20 +02:00 |
|
Gude5
|
2d5939e33b
|
Merge branch 'SigmaHQ:master' into master
|
2022-10-11 11:29:48 +02:00 |
|
Tim Rauch
|
b992a0e340
|
fix: updated rules after review
|
2022-10-11 11:29:08 +02:00 |
|
Florian Roth
|
a55cea92e0
|
Merge pull request #3572 from nasbench/nasbench-rule-devel
Rule Dev - Small Updates
|
2022-10-11 00:40:35 +02:00 |
|
Florian Roth
|
41d2ece9f4
|
Merge pull request #3573 from SigmaHQ/rule-devel
rule: Process Hacker, PCHunter; ZINC APT UA
|
2022-10-11 00:40:21 +02:00 |
|
Florian Roth
|
0df87d76f2
|
fix: duplicate, list with one entry
|
2022-10-10 22:49:34 +02:00 |
|
Nasreddine Bencherchali
|
bf28e42f01
|
Fix FP Found In Testing
|
2022-10-10 17:33:14 +02:00 |
|
Florian Roth
|
b2c012146e
|
rules: pchunter, process hacker
|
2022-10-10 17:21:17 +02:00 |
|
Gude5
|
4a2a6037de
|
Update rules/windows/process_creation/proc_creation_win_unusual_child_process_of_dns_exe.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:05:10 +02:00 |
|
Gude5
|
5275ade621
|
Update rules/windows/process_creation/proc_creation_win_susp_cmd_exectution_via_wmi.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:05:01 +02:00 |
|
Gude5
|
eb65a3f5c5
|
Update rules/windows/process_creation/proc_creation_win_remote_desktop_tunneling.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:04:38 +02:00 |
|
Gude5
|
a8501da311
|
Update rules/windows/process_creation/proc_creation_win_firewall_disabled_via_powershell.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:03:54 +02:00 |
|
Gude5
|
e70bced56e
|
Update rules/windows/process_creation/proc_creation_win_credential_acquisition_registry_hive_dumping.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:03:34 +02:00 |
|
Gude5
|
31717609cd
|
Update rules/windows/process_creation/proc_creation_win_credential_acquisition_registry_hive_dumping.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:02:54 +02:00 |
|
Florian Roth
|
6879484928
|
Update proc_creation_win_susp_lolbin_non_c_drive.yml
|
2022-10-10 10:27:15 +02:00 |
|
Nasreddine Bencherchali
|
be0a3ad863
|
Add missing definition section for EID 4697
|
2022-10-10 10:22:46 +02:00 |
|
Florian Roth
|
3f25f62d94
|
Update proc_creation_win_susp_lolbin_non_c_drive.yml
|
2022-10-10 10:20:47 +02:00 |
|
Florian Roth
|
83f93bc32c
|
Merge branch 'master' into master
|
2022-10-10 00:27:48 +02:00 |
|
Florian Roth
|
cb73e9725a
|
Merge pull request #3570 from SigmaHQ/rule-devel
IOX and NPS tunneling tools
|
2022-10-10 00:26:48 +02:00 |
|
frack113
|
cf7a348028
|
Fix related
|
2022-10-09 17:28:05 +02:00 |
|
frack113
|
931fb30853
|
old experimental rule promotion
|
2022-10-09 16:54:04 +02:00 |
|
Florian Roth
|
e009ba937e
|
rule: NPS tunneling tool
|
2022-10-08 09:49:51 +02:00 |
|
Florian Roth
|
deb5540816
|
rules: refactored FRP, new IOX
|
2022-10-08 09:32:36 +02:00 |
|
AaronHerman
|
7a0e117b48
|
updating with vbs/vbe and falsepositives recommendations
|
2022-10-07 20:36:22 -05:00 |
|
AaronHerman
|
3d225b3862
|
updating with vbs/vbe and falsepositives recommendations
|
2022-10-07 20:35:57 -05:00 |
|
Florian Roth
|
d8890295fe
|
Merge branch 'master' into master
|
2022-10-07 16:24:30 +02:00 |
|
Nasreddine Bencherchali
|
8dbd03ff32
|
Fix FP In Testing
|
2022-10-07 13:26:33 +02:00 |
|
Florian Roth
|
6623778a61
|
fix: wrong log source
|
2022-10-07 10:44:35 +02:00 |
|
Florian Roth
|
c073388472
|
rule: lpe - tabtip indicator
|
2022-10-07 10:41:04 +02:00 |
|
Florian Roth
|
b634e1a3f9
|
Merge pull request #3562 from nasbench/pysigma-fix
PySigma Issues Fix
|
2022-10-07 09:21:15 +02:00 |
|
frack113
|
7539d29e8b
|
Merge pull request #3559 from nasbench/nasbench-rule-devel
Rule Dev
|
2022-10-07 06:07:43 +02:00 |
|
Florian Roth
|
d5e2991a4c
|
Merge pull request #3551 from frack113/redcannary_20221002
Redcannary rules
|
2022-10-06 13:02:46 +02:00 |
|
Florian Roth
|
8a0cf2e7e6
|
Update proc_creation_win_hh_chm_http.yml
|
2022-10-06 09:28:17 +02:00 |
|
Florian Roth
|
c0ff746d99
|
change: make uppercase in Sysmon version
|
2022-10-06 09:27:26 +02:00 |
|
Florian Roth
|
f0196039ba
|
Update proc_creation_win_susp_logoff.yml
|
2022-10-06 09:24:15 +02:00 |
|
Florian Roth
|
f1435ea16b
|
Update proc_creation_win_susp_logoff.yml
|
2022-10-06 09:23:37 +02:00 |
|
Florian Roth
|
881dd0c6d0
|
Update proc_creation_win_pdq_deploy.yml
|
2022-10-06 09:22:44 +02:00 |
|
Florian Roth
|
15232621b1
|
refactor: another JuicyPotatoNG pattern
|
2022-10-06 08:47:23 +02:00 |
|