Aaron Herman
|
580360b540
|
Update description typo
|
2022-10-01 10:52:35 -05:00 |
|
Florian Roth
|
626a362e8f
|
fix: missing condition
|
2022-10-01 16:09:53 +02:00 |
|
Florian Roth
|
65f531fb30
|
rule: Exchange Exploitation
|
2022-10-01 16:08:27 +02:00 |
|
Florian Roth
|
b568328103
|
Merge branch 'master' into rule-devel
|
2022-10-01 16:08:13 +02:00 |
|
Florian Roth
|
cd8ed9870c
|
fix: FPs noticed with Aurora
|
2022-09-30 20:01:07 +02:00 |
|
Nasreddine Bencherchali
|
7880e3a2b6
|
Fix FP
Make the FP fix more broad to cover more future cases
|
2022-09-29 22:29:47 +02:00 |
|
Nasreddine Bencherchali
|
afb2e7567d
|
Create web_cve_2022_36804_atlassian_bitbucket_command_injection.yml
|
2022-09-29 22:23:04 +02:00 |
|
Nasreddine Bencherchali
|
99a0c129ea
|
Create registry_set_register_custom_protocol_handler.yml
|
2022-09-29 22:06:18 +02:00 |
|
Nasreddine Bencherchali
|
bfc1d6a5b7
|
Create proc_creation_win_hh_chm_http.yml
|
2022-09-29 22:06:11 +02:00 |
|
Florian Roth
|
f84cdd3b74
|
fix: filter definition
|
2022-09-29 14:07:38 +02:00 |
|
Florian Roth
|
14fdf75ab5
|
fix: FPs noticed with THOR
|
2022-09-29 13:51:09 +02:00 |
|
Florian Roth
|
5b5c261c98
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-09-29 13:41:25 +02:00 |
|
Florian Roth
|
c31fe50f4d
|
fix: FPs noticed in THOR testing
|
2022-09-29 13:41:20 +02:00 |
|
Florian Roth
|
d8ff3339aa
|
antSword webshell
|
2022-09-29 13:31:16 +02:00 |
|
Nasreddine Bencherchali
|
47dbe6081d
|
Update proc_creation_win_susp_conhost.yml
|
2022-09-29 12:15:10 +02:00 |
|
Tim Rauch
|
119c9f5275
|
fix: fixed rules after failed Sigma Rule Tests
|
2022-09-29 11:30:45 +02:00 |
|
Nasreddine Bencherchali
|
cdd9aff032
|
Fix FP
|
2022-09-29 11:20:08 +02:00 |
|
Florian Roth
|
a888ecb8b8
|
Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
|
2022-09-29 11:01:29 +02:00 |
|
Florian Roth
|
5533d7367f
|
Merge pull request #3539 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-09-29 11:01:13 +02:00 |
|
Tim Rauch
|
58e5b9f419
|
fix: removed ' from references
|
2022-09-29 10:21:01 +02:00 |
|
Tim Rauch
|
81a112e35b
|
Fixed merge conflicts
|
2022-09-29 10:05:49 +02:00 |
|
Tim Rauch
|
d35ea51136
|
Merge branch 'master' of https://github.com/Gude5/sigma
|
2022-09-29 09:57:29 +02:00 |
|
Tim Rauch
|
8695880f36
|
fix: fixed rulename
|
2022-09-29 09:55:14 +02:00 |
|
Florian Roth
|
ec329f403a
|
fix: Aurora FPs with Nvidia update
|
2022-09-28 19:31:22 +02:00 |
|
Florian Roth
|
428cb6ab74
|
Merge pull request #3538 from SigmaHQ/rule-devel
fix: filter definition in userinit rule
|
2022-09-28 17:26:34 +02:00 |
|
Florian Roth
|
a563422c82
|
fix: filter definition in userinit rule
|
2022-09-28 17:08:23 +02:00 |
|
Tim Rauch
|
be1f1a4505
|
New Rules: transformed elastic to sigma rules
|
2022-09-28 16:45:22 +02:00 |
|
Nasreddine Bencherchali
|
4a5dcf8586
|
Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:42 +02:00 |
|
Nasreddine Bencherchali
|
69b31b19b1
|
Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:36 +02:00 |
|
Florian Roth
|
5391a5cab4
|
changed casing, increased level
|
2022-09-28 13:28:53 +02:00 |
|
Florian Roth
|
5ee44a6992
|
increased level
|
2022-09-28 13:27:23 +02:00 |
|
Florian Roth
|
ea25382110
|
increased level
|
2022-09-28 13:26:23 +02:00 |
|
Nasreddine Bencherchali
|
b71644d0c8
|
New rules + small mitre update
|
2022-09-28 11:52:07 +02:00 |
|
Nasreddine Bencherchali
|
df6c167b17
|
New Rules
|
2022-09-28 10:48:51 +02:00 |
|
Nasreddine Bencherchali
|
e3b3265240
|
Update image_load_side_load_from_non_system_location.yml
|
2022-09-28 10:48:30 +02:00 |
|
frack113
|
a9dd6f7ff0
|
Add registry_set_change_winevt_channelaccess (#3505)
|
2022-09-28 09:53:46 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
d262ea2df8
|
New rules
|
2022-09-28 09:51:13 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
e987c669d0
|
Updates
|
2022-09-28 09:50:56 +02:00 |
|
frack113
|
ec6d237cd0
|
Merge pull request #3522 from frack113/redcannary_20220925
Add redcannary rules
|
2022-09-28 08:45:06 +02:00 |
|
Florian Roth
|
e583d9fc39
|
Update proc_creation_win_w32tm.yml
|
2022-09-27 23:52:22 +02:00 |
|
Florian Roth
|
58b7c910dc
|
Update proc_creation_win_w32tm.yml
|
2022-09-27 23:50:35 +02:00 |
|
Florian Roth
|
46ef664ec6
|
Merge pull request #3530 from securepeacock/patch-28
Update proc_creation_win_susp_psexesvc_as_system.yml
|
2022-09-27 23:47:45 +02:00 |
|
Yamato Security
|
e44e01e106
|
update modified tag
|
2022-09-28 06:32:34 +09:00 |
|
Yamato Security
|
979502921f
|
define security-mitigations service
|
2022-09-28 06:23:50 +09:00 |
|
unknown
|
a0275ab124
|
New pipename criteria from redcanary
|
2022-09-27 15:37:14 -04:00 |
|
securepeacock
|
e90c91668d
|
Update proc_creation_win_susp_psexesvc_as_system.yml
Typo Fixed
|
2022-09-27 13:45:53 -04:00 |
|
Qasim Qlf
|
ec657a3118
|
Merge branch 'master' into master
|
2022-09-27 16:26:22 +05:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
43d12249a0
|
Renamed create remote thread rules
|
2022-09-27 12:13:16 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
27d08a2eb9
|
Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel
|
2022-09-27 12:09:37 +02:00 |
|
Florian Roth
|
e2aacfea35
|
Merge pull request #3519 from SigmaHQ/rule-devel
Rule devel
|
2022-09-27 12:05:22 +02:00 |
|