Commit Graph

4601 Commits

Author SHA1 Message Date
frack113 4acc692633 Update proc_creation_win_susp_certutil_command.yml 2022-10-12 06:28:34 +02:00
frack113 d5b6451f90 Fix modified 2022-10-11 20:30:31 +02:00
Gude5 2a1233c965 Updated some rules after review 2022-10-11 16:31:56 +02:00
phantinuss af9d04aa9c fix: FPs occurring when using winget upgrade 2022-10-11 16:25:03 +02:00
Nasreddine Bencherchali 0e40a65bef Fix FP caused by short atoms
Added spaces to avoid fp
2022-10-11 14:37:34 +02:00
Nasreddine Bencherchali 563a3d5646 Reduce level to medium 2022-10-11 14:04:14 +02:00
Tim Rauch cd6ee66a38 Updated some rules 2022-10-11 13:48:42 +02:00
Tim Rauch d84e281e96 Updated cbb9e3d1-2386-4e59-912e-62f1484f7a89 2022-10-11 13:42:24 +02:00
Tim Rauch c4fec44e5b Updated some rules 2022-10-11 13:28:59 +02:00
Tim Rauch 4ab6fe537a Updated some rules 2022-10-11 12:38:23 +02:00
Florian Roth 8d9c11b26e Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2022-10-11 11:40:07 +02:00
Florian Roth 5ad51c4dea refactor: additional Rubeus indicators 2022-10-11 11:40:03 +02:00
Tim Rauch 3454738439 Merge branch 'master' 2022-10-11 11:32:20 +02:00
Gude5 2d5939e33b Merge branch 'SigmaHQ:master' into master 2022-10-11 11:29:48 +02:00
Tim Rauch b992a0e340 fix: updated rules after review 2022-10-11 11:29:08 +02:00
Florian Roth a55cea92e0 Merge pull request #3572 from nasbench/nasbench-rule-devel
Rule Dev - Small Updates
2022-10-11 00:40:35 +02:00
Florian Roth 41d2ece9f4 Merge pull request #3573 from SigmaHQ/rule-devel
rule: Process Hacker, PCHunter; ZINC APT UA
2022-10-11 00:40:21 +02:00
Florian Roth 0df87d76f2 fix: duplicate, list with one entry 2022-10-10 22:49:34 +02:00
Nasreddine Bencherchali bf28e42f01 Fix FP Found In Testing 2022-10-10 17:33:14 +02:00
Florian Roth b2c012146e rules: pchunter, process hacker 2022-10-10 17:21:17 +02:00
Gude5 4a2a6037de Update rules/windows/process_creation/proc_creation_win_unusual_child_process_of_dns_exe.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:05:10 +02:00
Gude5 5275ade621 Update rules/windows/process_creation/proc_creation_win_susp_cmd_exectution_via_wmi.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:05:01 +02:00
Gude5 eb65a3f5c5 Update rules/windows/process_creation/proc_creation_win_remote_desktop_tunneling.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:04:38 +02:00
Gude5 a8501da311 Update rules/windows/process_creation/proc_creation_win_firewall_disabled_via_powershell.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:03:54 +02:00
Gude5 e70bced56e Update rules/windows/process_creation/proc_creation_win_credential_acquisition_registry_hive_dumping.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:03:34 +02:00
Gude5 31717609cd Update rules/windows/process_creation/proc_creation_win_credential_acquisition_registry_hive_dumping.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:02:54 +02:00
Florian Roth 6879484928 Update proc_creation_win_susp_lolbin_non_c_drive.yml 2022-10-10 10:27:15 +02:00
Nasreddine Bencherchali be0a3ad863 Add missing definition section for EID 4697 2022-10-10 10:22:46 +02:00
Florian Roth 3f25f62d94 Update proc_creation_win_susp_lolbin_non_c_drive.yml 2022-10-10 10:20:47 +02:00
Florian Roth 83f93bc32c Merge branch 'master' into master 2022-10-10 00:27:48 +02:00
Florian Roth cb73e9725a Merge pull request #3570 from SigmaHQ/rule-devel
IOX and NPS tunneling tools
2022-10-10 00:26:48 +02:00
frack113 cf7a348028 Fix related 2022-10-09 17:28:05 +02:00
frack113 931fb30853 old experimental rule promotion 2022-10-09 16:54:04 +02:00
Florian Roth e009ba937e rule: NPS tunneling tool 2022-10-08 09:49:51 +02:00
Florian Roth deb5540816 rules: refactored FRP, new IOX 2022-10-08 09:32:36 +02:00
AaronHerman 7a0e117b48 updating with vbs/vbe and falsepositives recommendations 2022-10-07 20:36:22 -05:00
AaronHerman 3d225b3862 updating with vbs/vbe and falsepositives recommendations 2022-10-07 20:35:57 -05:00
Florian Roth d8890295fe Merge branch 'master' into master 2022-10-07 16:24:30 +02:00
Nasreddine Bencherchali 8dbd03ff32 Fix FP In Testing 2022-10-07 13:26:33 +02:00
Florian Roth 6623778a61 fix: wrong log source 2022-10-07 10:44:35 +02:00
Florian Roth c073388472 rule: lpe - tabtip indicator 2022-10-07 10:41:04 +02:00
Florian Roth b634e1a3f9 Merge pull request #3562 from nasbench/pysigma-fix
PySigma Issues Fix
2022-10-07 09:21:15 +02:00
frack113 7539d29e8b Merge pull request #3559 from nasbench/nasbench-rule-devel
Rule Dev
2022-10-07 06:07:43 +02:00
Florian Roth d5e2991a4c Merge pull request #3551 from frack113/redcannary_20221002
Redcannary rules
2022-10-06 13:02:46 +02:00
Florian Roth 8a0cf2e7e6 Update proc_creation_win_hh_chm_http.yml 2022-10-06 09:28:17 +02:00
Florian Roth c0ff746d99 change: make uppercase in Sysmon version 2022-10-06 09:27:26 +02:00
Florian Roth f0196039ba Update proc_creation_win_susp_logoff.yml 2022-10-06 09:24:15 +02:00
Florian Roth f1435ea16b Update proc_creation_win_susp_logoff.yml 2022-10-06 09:23:37 +02:00
Florian Roth 881dd0c6d0 Update proc_creation_win_pdq_deploy.yml 2022-10-06 09:22:44 +02:00
Florian Roth 15232621b1 refactor: another JuicyPotatoNG pattern 2022-10-06 08:47:23 +02:00