Nasreddine Bencherchali
|
7c38a5c496
|
chore: add nextron authors tag
|
2023-02-01 11:14:59 +01:00 |
|
frack113
|
dfdaecc52c
|
Order yaml field
|
2022-10-25 12:00:56 +02:00 |
|
frack113
|
931fb30853
|
old experimental rule promotion
|
2022-10-09 16:54:04 +02:00 |
|
Nasreddine Bencherchali
|
d03f6df250
|
Reference Update [Batch 1]
|
2022-07-07 15:24:15 +01:00 |
|
Florian Roth
|
db55be82b6
|
refactor: rule adjustments based on hayabusa
https://github.com/Yamato-Security/hayabusa-rules/blob/deb6026fcf452600829c52852f6283d2c808bc69/config/noisy_rules.txt
|
2022-06-18 08:39:02 +02:00 |
|
frack113
|
8de0027ca3
|
refactor condition
|
2022-06-03 15:35:24 +02:00 |
|
phantinuss
|
dbd68bf3f0
|
chore: test rules: capitalization on FP list entries
Entires to the false positive list should begin with
a capital letter. e.g. Unkown instead of unkown.
Fixed the existing rules accordingly
|
2022-05-09 16:07:44 +02:00 |
|
frack113
|
4631d0c482
|
remove invalid tag
|
2022-01-19 18:23:30 +01:00 |
|
frack113
|
01dc930c17
|
Change status for old rules
|
2021-11-27 11:33:14 +01:00 |
|
Florian Roth
|
b0c2d7b75a
|
fix: tags for WMI / execution / persistence
|
2021-09-01 16:34:50 +02:00 |
|
Florian Roth
|
1aac21ba79
|
fix: single list item issue
|
2021-09-01 14:03:42 +02:00 |
|
Florian Roth
|
505140d273
|
rule: extended WMI suspicious scripts rule
|
2021-09-01 13:57:48 +02:00 |
|
Florian Roth
|
e787420be1
|
rule: WMI filter content encoded executable
|
2021-09-01 13:57:36 +02:00 |
|
Steven
|
850a002840
|
Merge branch 'master' of https://github.com/SigmaHQ/sigma
|
2021-04-15 01:25:48 +02:00 |
|
Steven
|
0c9a82af89
|
- Remove 'service: sysmon' since defining the categories made the rules generic
|
2020-10-02 09:37:52 +02:00 |
|
Steven
|
8b74abe0bc
|
- Created new categories for sysmon events
- Replaced the explicit EventIDs with the reference to the category
- Moved the rules to the corresponding directories
|
2020-09-30 20:44:14 +02:00 |
|