Nasreddine Bencherchali
|
927b29e85a
|
Update proc_creation_win_susp_powershell_download_iex.yml
|
2022-09-02 14:28:47 +02:00 |
|
Nasreddine Bencherchali
|
e0a74d6238
|
Update proc_creation_win_net_default_accounts_manipulation.yml
|
2022-09-02 14:17:17 +02:00 |
|
Nasreddine Bencherchali
|
0bdd7ea35c
|
Update registry_set_sophos_av_tamaper.yml
|
2022-09-02 13:53:59 +02:00 |
|
Nasreddine Bencherchali
|
116a72c206
|
Fix FP
|
2022-09-02 13:31:49 +02:00 |
|
Nasreddine Bencherchali
|
3c83e6c51b
|
Update registry_set_sophos_av_tamaper.yml
|
2022-09-02 12:03:57 +02:00 |
|
Nasreddine Bencherchali
|
884891746b
|
Update proc_creation_win_powershell_amsi_bypass.yml
|
2022-09-02 12:02:18 +02:00 |
|
Nasreddine Bencherchali
|
37f08c4cbb
|
More updates
|
2022-09-02 11:52:13 +02:00 |
|
frack113
|
8bb29b0e66
|
Add proc_creation_win_frp
|
2022-09-02 10:29:40 +02:00 |
|
Nasreddine Bencherchali
|
b02a2ff2dc
|
Update proc_creation_win_net_default_accounts_manipulation.yml
|
2022-09-02 09:49:14 +02:00 |
|
Nasreddine Bencherchali
|
5f03a73dd2
|
Update proc_creation_win_susp_clsid_foldername.yml
|
2022-09-02 09:33:13 +02:00 |
|
frack113
|
9e5eefd71b
|
Merge pull request #3456 from phantinuss/master
fix: FP in testing environment
|
2022-09-02 09:30:21 +02:00 |
|
Nasreddine Bencherchali
|
ed88295732
|
Update proc_creation_win_susp_clsid_foldername.yml
|
2022-09-02 09:28:28 +02:00 |
|
phantinuss
|
48ac804c9e
|
fix: remove part of UNC path
|
2022-09-02 09:21:48 +02:00 |
|
Nasreddine Bencherchali
|
d0e7732ddd
|
Update proc_creation_win_susp_openas_rundll_usage.yml
|
2022-09-02 09:19:25 +02:00 |
|
Nasreddine Bencherchali
|
48c1104b1a
|
New+Update
|
2022-09-02 09:15:21 +02:00 |
|
frack113
|
fc3c5cf99a
|
Merge pull request #3455 from pH-T/master
new rule: susp net use combo
|
2022-09-02 06:58:32 +02:00 |
|
frack113
|
9a1a87de18
|
Update proc_creation_win_susp_net_use.yml
|
2022-09-02 06:42:47 +02:00 |
|
frack113
|
367e2fd0f9
|
Merge pull request #3450 from nasbench/master
Updates+New Rules
|
2022-09-02 06:39:15 +02:00 |
|
phantinuss
|
dee365f562
|
fix: FP in testing environment
|
2022-09-01 17:53:06 +02:00 |
|
FabFaeb
|
ab9e15f456
|
fix title
|
2022-09-01 17:05:32 +02:00 |
|
David ANDRE
|
1e791b85c0
|
Removing dev rule added by mistake
|
2022-09-01 15:44:16 +02:00 |
|
David ANDRE
|
33ff230ae1
|
Added modified date
|
2022-09-01 15:27:20 +02:00 |
|
David ANDRE
|
0b0190ccb1
|
Added quotes to strings
|
2022-09-01 15:22:26 +02:00 |
|
Paul Hager
|
6b2f12cbe6
|
fix: proc_creation_win_susp_net_use status
|
2022-09-01 15:01:38 +02:00 |
|
Paul Hager
|
a428756340
|
new rule: susp net use combo
|
2022-09-01 14:38:06 +02:00 |
|
David André
|
ae8cfb1ec0
|
Merge branch 'SigmaHQ:master' into master
|
2022-09-01 13:04:11 +02:00 |
|
David ANDRE
|
a0a30bad8c
|
Correcting values for startswith
|
2022-09-01 13:03:19 +02:00 |
|
Tim Shelton
|
1bb172e4ae
|
False positive when commandline is only cmd.exe /c
|
2022-08-31 19:38:25 +00:00 |
|
Florian Roth
|
5a4b3d6b71
|
Update file_rename_win_ransomware.yml
|
2022-08-31 16:08:12 +02:00 |
|
Florian Roth
|
6e1c647019
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-08-31 13:55:52 +02:00 |
|
Florian Roth
|
65c6f82169
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-08-31 13:55:46 +02:00 |
|
Florian Roth
|
893fc6c15d
|
fix: FP with controller config
|
2022-08-31 13:55:43 +02:00 |
|
Nasreddine Bencherchali
|
b0bd1a2184
|
Update win_msi_install_from_susp_locations.yml
|
2022-08-31 13:55:30 +02:00 |
|
Nasreddine Bencherchali
|
7b92cbb6d0
|
Create win_msi_install_from_susp_locations.yml
|
2022-08-31 13:54:50 +02:00 |
|
Nasreddine Bencherchali
|
783fd8b160
|
Create proc_creation_win_susp_schtasks_schedule_type.yml
|
2022-08-31 10:08:31 +02:00 |
|
FabFaeb
|
df2ef5a2ee
|
added missing newline
|
2022-08-31 09:59:29 +02:00 |
|
FabFaeb
|
3a020ce499
|
added "failed admin share mount" rule
|
2022-08-31 09:57:09 +02:00 |
|
Nasreddine Bencherchali
|
80098113d0
|
Update image_load_susp_cmstp.yml
|
2022-08-31 09:53:07 +02:00 |
|
Nasreddine Bencherchali
|
343b0ef199
|
Update net_connection_win_susp_cmstp.yml
|
2022-08-31 09:46:18 +02:00 |
|
Nasreddine Bencherchali
|
77c5640839
|
Update net_connection_win_susp_cmstp.yml
|
2022-08-31 09:42:25 +02:00 |
|
Nasreddine Bencherchali
|
399a18b762
|
Update net_connection_win_susp_cmstp.yml
|
2022-08-31 09:41:25 +02:00 |
|
Nasreddine Bencherchali
|
ea183cae13
|
Updates+New Rules
|
2022-08-31 09:39:16 +02:00 |
|
Borna Talebi
|
8dfe06a33b
|
Adding Google Chrome FP
|
2022-08-31 11:35:12 +04:30 |
|
Florian Roth
|
aa0545b6c7
|
refactor: added extension to ransomware rule
|
2022-08-31 08:40:24 +02:00 |
|
Florian Roth
|
35d9e5f36a
|
fix: syntax error, docs: change fp text
|
2022-08-30 11:29:11 +02:00 |
|
Florian Roth
|
b5c57e97fc
|
Merge branch 'master' into rule-devel
|
2022-08-30 09:14:37 +02:00 |
|
Florian Roth
|
52c5851ef6
|
rules: wmic extended, defendercheck, sharpldapwhoami
|
2022-08-30 09:13:25 +02:00 |
|
frack113
|
da72e3b7c0
|
Merge pull request #3441 from ionsor/patch-6
Update net_connection_win_dead_drop_resolvers.yml
|
2022-08-30 08:38:17 +02:00 |
|
frack113
|
f9b79161a5
|
Merge pull request #3444 from danielgottt/patch-7
Create proc_creation_win_deviceenroller_evasion.yml
|
2022-08-30 08:24:24 +02:00 |
|
frack113
|
45a87dd22d
|
Update net_connection_win_dead_drop_resolvers.yml
|
2022-08-30 08:22:10 +02:00 |
|