Florian Roth
|
b6270dfcf0
|
Merge branch 'master' into rule-devel
|
2022-10-06 08:43:02 +02:00 |
|
Florian Roth
|
e92f2475b6
|
refactor: JuicyPotatoNG imphashes
|
2022-10-06 08:30:48 +02:00 |
|
frack113
|
32406c1915
|
Issue 3552
|
2022-10-06 06:50:54 +02:00 |
|
frack113
|
b1b7428a30
|
Merge pull request #3560 from redsand/fp_ec2_windows
FP: ignore amazon aws ec2 scripts
|
2022-10-06 06:41:22 +02:00 |
|
Nasreddine Bencherchali
|
dadec8b9f0
|
Update incorrect mitre tags
|
2022-10-06 00:35:40 +02:00 |
|
Florian Roth
|
adfb7d58e8
|
Merge pull request #3563 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG pattern
|
2022-10-06 00:10:32 +02:00 |
|
Florian Roth
|
d2777f4d02
|
refactor: JuicyPotatoNG pattern
|
2022-10-06 00:00:46 +02:00 |
|
Nasreddine Bencherchali
|
2c26614ce4
|
Update Wildcard + Int to Str fields
|
2022-10-05 23:15:20 +02:00 |
|
Tim Shelton
|
f65e795e22
|
FP: ignore amazon aws ec2 scripts
|
2022-10-05 19:40:37 +00:00 |
|
Nasreddine Bencherchali
|
68937161a0
|
Add GMER + PCHunter
|
2022-10-05 12:04:11 +02:00 |
|
Nasreddine Bencherchali
|
40dcb9a4c9
|
Update + Rename
|
2022-10-05 10:42:29 +02:00 |
|
Nasreddine Bencherchali
|
2ecf9ec7e1
|
Updates
|
2022-10-04 20:57:11 +02:00 |
|
Florian Roth
|
ef0e5c76a5
|
Merge pull request #3557 from SigmaHQ/rule-devel
fix: wrong condition in whoami rule
|
2022-10-04 16:23:04 +02:00 |
|
Florian Roth
|
eee1d2c1cb
|
fix: wrong condition in whoami rule
https://github.com/SigmaHQ/sigma/issues/3556
|
2022-10-04 16:11:03 +02:00 |
|
Tim Rauch
|
f61c82e7a1
|
fix: fixed FPs after failed Sigma Rule Test
|
2022-10-04 11:30:13 +02:00 |
|
Tim Rauch
|
b6046803a0
|
fix: fixed rules after review
|
2022-10-04 10:06:15 +02:00 |
|
Gude5
|
f692271c0a
|
Merge branch 'SigmaHQ:master' into master
|
2022-10-04 09:33:51 +02:00 |
|
Florian Roth
|
029900c284
|
Merge pull request #3548 from aaronherman/patch-1
Update description typo on "Phishing Pattern ISO in Archive"
|
2022-10-03 19:55:13 +02:00 |
|
securepeacock
|
161c8e6c2c
|
Update proc_creation_win_lolbins_by_office_applications.yml
Adding msidb.exe references are below.
https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
|
2022-10-03 11:56:06 -04:00 |
|
frack113
|
5bd9dd76aa
|
Redcannary rules
|
2022-10-02 11:34:33 +02:00 |
|
Florian Roth
|
41a7bdb250
|
Update proc_creation_win_susp_lolbin_non_c_drive.yml
|
2022-10-02 10:23:36 +02:00 |
|
Florian Roth
|
6af0e0c24f
|
Apply suggestions from code review
|
2022-10-02 10:23:01 +02:00 |
|
Florian Roth
|
93004a3fd5
|
Update proc_creation_win_archiver_iso_phishing.yml
|
2022-10-02 10:21:04 +02:00 |
|
AaronHerman
|
47cd3d4e7b
|
update for Image instead of CommandLine
|
2022-10-01 19:13:31 -05:00 |
|
AaronHerman
|
0710acf9e7
|
include any.run sample, add leading \ and filter env vars
|
2022-10-01 17:19:28 -05:00 |
|
AaronHerman
|
e8404ed146
|
updating title to conform with CICD
|
2022-10-01 12:05:22 -05:00 |
|
AaronHerman
|
ca5bad2c49
|
update description, removing regsvr since uses relative path
|
2022-10-01 11:53:52 -05:00 |
|
AaronHerman
|
42cc5d90f4
|
uppdate date
|
2022-10-01 11:50:53 -05:00 |
|
AaronHerman
|
5983bbfa50
|
Add rule for suspicious lolbin executing in non-c drive
|
2022-10-01 11:50:13 -05:00 |
|
Aaron Herman
|
580360b540
|
Update description typo
|
2022-10-01 10:52:35 -05:00 |
|
Florian Roth
|
65f531fb30
|
rule: Exchange Exploitation
|
2022-10-01 16:08:27 +02:00 |
|
Nasreddine Bencherchali
|
7880e3a2b6
|
Fix FP
Make the FP fix more broad to cover more future cases
|
2022-09-29 22:29:47 +02:00 |
|
Nasreddine Bencherchali
|
bfc1d6a5b7
|
Create proc_creation_win_hh_chm_http.yml
|
2022-09-29 22:06:11 +02:00 |
|
Nasreddine Bencherchali
|
47dbe6081d
|
Update proc_creation_win_susp_conhost.yml
|
2022-09-29 12:15:10 +02:00 |
|
Tim Rauch
|
119c9f5275
|
fix: fixed rules after failed Sigma Rule Tests
|
2022-09-29 11:30:45 +02:00 |
|
Florian Roth
|
a888ecb8b8
|
Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
|
2022-09-29 11:01:29 +02:00 |
|
Tim Rauch
|
58e5b9f419
|
fix: removed ' from references
|
2022-09-29 10:21:01 +02:00 |
|
Tim Rauch
|
81a112e35b
|
Fixed merge conflicts
|
2022-09-29 10:05:49 +02:00 |
|
Tim Rauch
|
d35ea51136
|
Merge branch 'master' of https://github.com/Gude5/sigma
|
2022-09-29 09:57:29 +02:00 |
|
Florian Roth
|
428cb6ab74
|
Merge pull request #3538 from SigmaHQ/rule-devel
fix: filter definition in userinit rule
|
2022-09-28 17:26:34 +02:00 |
|
Florian Roth
|
a563422c82
|
fix: filter definition in userinit rule
|
2022-09-28 17:08:23 +02:00 |
|
Tim Rauch
|
be1f1a4505
|
New Rules: transformed elastic to sigma rules
|
2022-09-28 16:45:22 +02:00 |
|
Nasreddine Bencherchali
|
4a5dcf8586
|
Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:42 +02:00 |
|
Nasreddine Bencherchali
|
69b31b19b1
|
Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:36 +02:00 |
|
Florian Roth
|
5391a5cab4
|
changed casing, increased level
|
2022-09-28 13:28:53 +02:00 |
|
Florian Roth
|
5ee44a6992
|
increased level
|
2022-09-28 13:27:23 +02:00 |
|
Nasreddine Bencherchali
|
b71644d0c8
|
New rules + small mitre update
|
2022-09-28 11:52:07 +02:00 |
|
Nasreddine Bencherchali
|
df6c167b17
|
New Rules
|
2022-09-28 10:48:51 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
d262ea2df8
|
New rules
|
2022-09-28 09:51:13 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
e987c669d0
|
Updates
|
2022-09-28 09:50:56 +02:00 |
|