Nasreddine Bencherchali
|
055f33a386
|
fix: add missing modified date
|
2023-01-13 17:13:17 +01:00 |
|
frack113
|
5d0b0f6663
|
Add more TaskName
|
2023-01-13 13:06:02 +01:00 |
|
frack113
|
80be90c331
|
Merge branch 'redcannary_20230113' of github.com:frack113/sigma into redcannary_20230113
|
2023-01-13 13:03:52 +01:00 |
|
frack113
|
a0cc836d0a
|
Add filter
|
2023-01-13 13:03:30 +01:00 |
|
Florian Roth
|
d088dc447d
|
docs: changes to status in AV rules
|
2023-01-13 12:39:49 +01:00 |
|
frack113
|
23620bc8aa
|
Update proc_creation_win_lsa_disablerestrictedadmin.yml
|
2023-01-13 12:31:28 +01:00 |
|
frack113
|
1b11e29fef
|
Move rules
|
2023-01-13 12:15:08 +01:00 |
|
frack113
|
e0434a3f2c
|
Add redcannary rules
|
2023-01-13 12:11:38 +01:00 |
|
frack113
|
e886902374
|
Update proc_creation_lnx_system_network_connections_discovery.yml
|
2023-01-13 10:12:10 +01:00 |
|
Veramine
|
d91a1d0903
|
filter some legitimate activity
Filter landscape-sysinfo tool calling who
|
2023-01-13 00:47:40 -08:00 |
|
Nasreddine Bencherchali
|
49a2873c7a
|
Merge pull request #3919 from ruppde/master
Add more ransomware strings
|
2023-01-13 00:37:54 +01:00 |
|
Nasreddine Bencherchali
|
7df1bd1a40
|
fix: remove duplicate entry
|
2023-01-13 00:26:38 +01:00 |
|
Nasreddine Bencherchali
|
135849eaf5
|
Merge pull request #3918 from SigmaHQ/rule-devel
add new IOC for PrivEsc tools list
|
2023-01-13 00:09:05 +01:00 |
|
Arnim Rupp
|
9868c00cc6
|
Add more ransomware strings
|
2023-01-13 00:08:55 +01:00 |
|
Florian Roth
|
29a61b8c70
|
Merge branch 'master' into rule-devel
|
2023-01-12 23:57:41 +01:00 |
|
Florian Roth
|
df1870df1e
|
add IOC for LocalPotato
|
2023-01-12 23:57:33 +01:00 |
|
Arnim Rupp
|
15e7271488
|
small fix for MS defender, uses e.g. Trojan:PHP/...
|
2023-01-12 23:46:52 +01:00 |
|
frack113
|
0c61fffa82
|
Merge pull request #3915 from frack113/appxdeployment
Add appxdeployment-server rule by eventid
|
2023-01-12 18:53:32 +01:00 |
|
frack113
|
4708bc61c6
|
Update win_appxdeployment_server_applocker_block.yml
|
2023-01-12 18:47:14 +01:00 |
|
frack113
|
b85d87ddf3
|
Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-01-12 18:39:46 +01:00 |
|
Nasreddine Bencherchali
|
e824131450
|
fix: add new ref
|
2023-01-12 18:37:35 +01:00 |
|
frack113
|
45d7d1cd30
|
Update win_software_restriction_policies_block.yml
|
2023-01-12 18:30:45 +01:00 |
|
frack113
|
1470c3ebce
|
Update win_software_restriction_policies_block.yml
|
2023-01-12 18:30:07 +01:00 |
|
frack113
|
b0b8c8cba6
|
Add win_software_restriction_policies_block
|
2023-01-12 18:20:12 +01:00 |
|
frack113
|
6d85fcb2b3
|
Add rule by eventid
|
2023-01-12 17:56:14 +01:00 |
|
Nasreddine Bencherchali
|
cd303fa0a4
|
Merge pull request #3877 from redsand/fp_library_alias_and_use_of_alias
feat: add defender cmdlet alias option
|
2023-01-12 17:28:39 +01:00 |
|
Nasreddine Bencherchali
|
a3fa8e8a90
|
Merge pull request #3914 from redsand/fp_citrix_receiver
FP: citrix receiver storefront
|
2023-01-12 17:25:08 +01:00 |
|
Tim Shelton
|
09b3e43afc
|
Removing filter specification in condition
|
2023-01-12 16:21:58 +00:00 |
|
redsand (Tim Shelton)
|
3007d98844
|
Merge branch 'SigmaHQ:master' into fp_library_alias_and_use_of_alias
|
2023-01-12 10:19:47 -06:00 |
|
redsand (Tim Shelton)
|
88308b713c
|
Update rules/windows/powershell/powershell_script/posh_ps_tamper_defender.yml
whatever you guys want, im good with. i like @neo23x0 suggestion
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2023-01-12 10:14:14 -06:00 |
|
Tim Shelton
|
ae51f1c472
|
FP: citrix receiver storefront
|
2023-01-12 16:09:36 +00:00 |
|
TheLawsOfChaos
|
52e40d10ef
|
feat: updates multiple mitre tech/sub-tech/tactics (#3913)
|
2023-01-12 17:04:38 +01:00 |
|
Nasreddine Bencherchali
|
a5df41cf39
|
fix: update title and description
|
2023-01-12 15:49:40 +01:00 |
|
Nasreddine Bencherchali
|
9a671e25d9
|
fix: add missing eid 400
|
2023-01-12 15:12:20 +01:00 |
|
Nasreddine Bencherchali
|
90c1e45d83
|
feat: add new reg variant of dev mode
|
2023-01-12 15:05:53 +01:00 |
|
Nasreddine Bencherchali
|
0ccda79d4e
|
Merge pull request #3908 from nasbench/nasbench-rule-devel
feat: new rules and updates
|
2023-01-12 11:03:33 +01:00 |
|
Nasreddine Bencherchali
|
e7a2e1c169
|
fix: remove version from name
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2023-01-12 10:37:34 +01:00 |
|
Nasreddine Bencherchali
|
0470f45246
|
fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2023-01-12 10:36:13 +01:00 |
|
cyb3rjy0t
|
644dfd7620
|
ADS stored DLL execution using Rundll32
|
2023-01-11 21:34:52 -05:00 |
|
Tim Brown
|
4b52acd2fe
|
feat: add rules for BGP and LDP authentication failures
|
2023-01-12 01:59:16 +01:00 |
|
Nasreddine Bencherchali
|
67ea98a6db
|
feat: more updates and fixes
|
2023-01-12 01:05:48 +01:00 |
|
Nasreddine Bencherchali
|
d0b2e2cbba
|
fix: more fp and duplicate id
|
2023-01-11 23:47:12 +01:00 |
|
Nasreddine Bencherchali
|
b6b1eba014
|
fix: fp and add related fields
|
2023-01-11 23:39:15 +01:00 |
|
Nasreddine Bencherchali
|
debd658aac
|
feat: new rules related to appx packages
|
2023-01-11 23:04:37 +01:00 |
|
Nasreddine Bencherchali
|
f4d4526d0f
|
fix: fp found in testing
|
2023-01-11 20:05:55 +01:00 |
|
Nasreddine Bencherchali
|
e0217640e8
|
fix: remove duplicate entries
|
2023-01-11 16:34:03 +01:00 |
|
Nasreddine Bencherchali
|
75b6b4fa59
|
fix: add missing modified date
|
2023-01-11 16:28:45 +01:00 |
|
Nasreddine Bencherchali
|
7edac96e63
|
fix: add modified
|
2023-01-11 16:27:49 +01:00 |
|
pH-T
|
5cc5f4db6d
|
fix: syntax error
|
2023-01-11 16:27:17 +01:00 |
|
Paul Hager
|
69ffa7f51b
|
feat: updated rules for coverage of CVE-2015-2291
|
2023-01-11 16:24:05 +01:00 |
|