phantinuss
0b38237dbf
fix: add relation to now obsolete rule
2021-09-01 15:38:29 +02:00
phantinuss
ae9966bdcc
fix: unifying two overlapping rules
2021-09-01 14:48:32 +02:00
phantinuss
deefcaa8ac
fix: prevent possible FPs with the respective command only used as the last parameter
2021-09-01 14:33:46 +02:00
frack113
2dbbaf0180
fix missing char in date
2021-09-01 14:00:55 +02:00
frack113
e71fce6f11
fix errors
2021-09-01 13:55:14 +02:00
frack113
80dbfa7af5
add process_creation_alternate_data_streams.yml
2021-09-01 13:52:09 +02:00
phantinuss
9ffdced740
fix: implement suggestions from PR discussion
2021-09-01 10:21:37 +02:00
Cyb3rEng
470d64e66c
Updated Rule
...
Completed the following updates on the rule:
- Modified the title
- incremented 4 spaces for references and tags
- updated false positives
- updated author
- updated description in detection section.
2021-08-31 22:28:34 -06:00
Cyb3rEng
e0e1396dff
Updated Rule
...
Completed the following updates on the rule:
- Modified the title
- incremented 4 spaces for references and tags
- updated false positives
- updated author
- updated description in detection section.
2021-08-31 22:26:44 -06:00
Cyb3rEng
e7c7e4c061
Updated Rule
...
Detection changed to #useful_information
2021-08-31 22:24:28 -06:00
Cyb3rEng
f2b8b83fe3
Updated Rule
...
Completed the following updates on the rule:
- Modified the title
- incremented 4 spaces for references and tags
- updated false positives
- updated author
- updated description in detection section.
2021-08-31 22:23:45 -06:00
Cyb3rEng
0d2257fb19
Updated Rule
...
Completed the following updates on the rule:
- Modified the title
- incremented 4 spaces for references and tags
- updated false positives
- updated author
- updated description in detection section.
2021-08-31 22:22:01 -06:00
Cyb3rEng
1b9a0c4a01
Updated Rule
...
Completed the following updates on the rule:
- Modified the title
- incremented 4 spaces for references and tags
- updated false positives
- updated author
- updated description in detection section.
2021-08-31 22:20:17 -06:00
Cyb3rEng
d309784e58
Updated Rule
...
Modified Title
2021-08-31 22:12:34 -06:00
Cyb3rEng
93334878f5
Updated Rule
...
Completed the following updates on the rule:
- Modified the title
- incremented 4 spaces for references and tags
- updated false positives
- updated author
- updated description in detection section.
2021-08-31 22:09:57 -06:00
phantinuss
add1ad40f8
additional UAC bypass rule
2021-08-31 16:23:32 +02:00
phantinuss
59d8e0b866
add System IntegrityLevel to uac bypass rules, the level is not used most of the time, but might
2021-08-31 16:18:05 +02:00
phantinuss
3a9e10d081
bulk of new rules to match working UACMe UAC bypasses
2021-08-31 12:51:21 +02:00
phantinuss
50b8ca5110
add more COM interfaces and sharpen rule logic
2021-08-31 12:51:21 +02:00
frack113
b25fbbea54
Merge pull request #1957 from d4rk-d4nph3/master
...
Added new malwarebytes reference for Cab File Expansion rule
2021-08-31 09:54:47 +02:00
Bhabesh Rai
911c45201a
Added -F option support
2021-08-31 13:02:53 +05:45
Bhabesh Rai
e2bfaea10f
Added new malwarebytes reference for Cab File Expansion rule
2021-08-31 11:35:54 +05:45
Cyb3rEng
e913032865
Add files via upload
2021-08-30 21:50:16 -06:00
Cyb3rEng
5508ff45b6
Add files via upload
2021-08-30 21:47:36 -06:00
Florian Roth
36a227796a
Merge pull request #1945 from SigmaHQ/rule-devel
...
rules: cobalt strike rules refactored
2021-08-30 15:48:01 +02:00
Florian Roth
1ded4eb913
rules: cobalt strike rules refactored
2021-08-30 15:10:30 +02:00
frack113
970dfa2f92
Merge pull request #1938 from EvanYu0816/upstream-fixes
...
Fix Pass the Hash and NotPetya Ransomware rule
2021-08-28 21:02:04 +02:00
frack113
3e355c64db
Merge pull request #1939 from SigmaHQ/rule-devel
...
rule: UAC bypass by mocking dirs
2021-08-28 20:47:27 +02:00
Florian Roth
f78225c394
rule: UAC bypass by mocking dirs
2021-08-27 18:12:21 +02:00
Evan Yu
178d82e9cd
Fix NotPetya Ransomware rule
2021-08-27 11:53:50 -04:00
frack113
ff37a49dc0
Merge pull request #1930 from SigmaHQ/rule-devel
...
fix: FPs with whoami rule and 4688 event IDs without parent info
2021-08-27 06:27:30 +02:00
frack113
59000b993d
Merge pull request #1932 from mlp1515/french_user
...
Add French user
2021-08-26 17:12:39 +02:00
mlp1515
e1aa82b412
Update win_susp_tscon_localsystem.yml
...
French language settings
2021-08-26 12:50:24 +00:00
mlp1515
e9ed5f592c
Update sysmon_always_install_elevated_windows_installer.yml
...
French language settings
2021-08-26 12:48:59 +00:00
mlp1515
4f49f03460
Update sysmon_abusing_debug_privilege.yml
...
French language settings
2021-08-26 12:46:15 +00:00
mlp1515
a31422db74
Update win_susp_schtask_creation.yml
...
French language settings
2021-08-26 12:45:24 +00:00
mlp1515
5f419d6f35
Update win_susp_taskmgr_localsystem.yml
...
French language settings
2021-08-26 12:44:35 +00:00
mlp1515
5545403a9b
Update win_whoami_as_system.yml
...
French language settings
2021-08-26 12:43:33 +00:00
mlp1515
7ad927f28e
Update win_wmiprvse_spawning_process.yml
...
French language settings
2021-08-26 12:42:47 +00:00
mlp1515
644397e65c
Update win_exploit_cve_2019_1388.yml
...
French language settings
2021-08-26 12:41:36 +00:00
Florian Roth
24d8701f15
fix: null cannot be used in a list with other values
2021-08-26 13:54:18 +02:00
Florian Roth
a231aa73b3
fix: FPs with whoami rule and 4688 event IDs without parent info
2021-08-26 13:33:25 +02:00
f.hubaut
e66007a43d
fix file name case
2021-08-26 11:15:33 +02:00
frack113
a4021842de
Fix invalid tags
2021-08-25 09:15:57 +02:00
frack113
e849af9df0
Merge pull request #1915 from frack113/tags_cve
...
fix tags
2021-08-25 06:29:48 +02:00
Florian Roth
9f69cead8a
Merge pull request #1916 from SigmaHQ/rule-devel
...
refactor: changed level of rule, refactored RazerInstaller rule
2021-08-24 15:42:26 +02:00
Florian Roth
46e312ff0d
fix: error in modifier
2021-08-24 15:03:23 +02:00
Florian Roth
cc519552aa
refactor: RazorInstaller integrity level system
2021-08-24 14:54:07 +02:00
frack113
7753f8c22e
fix tags
2021-08-24 12:36:31 +02:00
Florian Roth
6ca30619ac
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
2021-08-24 12:30:42 +02:00