Commit Graph

11789 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 927b29e85a Update proc_creation_win_susp_powershell_download_iex.yml 2022-09-02 14:28:47 +02:00
Nasreddine Bencherchali e0a74d6238 Update proc_creation_win_net_default_accounts_manipulation.yml 2022-09-02 14:17:17 +02:00
Nasreddine Bencherchali 0bdd7ea35c Update registry_set_sophos_av_tamaper.yml 2022-09-02 13:53:59 +02:00
Nasreddine Bencherchali 116a72c206 Fix FP 2022-09-02 13:31:49 +02:00
Nasreddine Bencherchali 3c83e6c51b Update registry_set_sophos_av_tamaper.yml 2022-09-02 12:03:57 +02:00
Nasreddine Bencherchali 884891746b Update proc_creation_win_powershell_amsi_bypass.yml 2022-09-02 12:02:18 +02:00
Nasreddine Bencherchali 37f08c4cbb More updates 2022-09-02 11:52:13 +02:00
frack113 8bb29b0e66 Add proc_creation_win_frp 2022-09-02 10:29:40 +02:00
Nasreddine Bencherchali b02a2ff2dc Update proc_creation_win_net_default_accounts_manipulation.yml 2022-09-02 09:49:14 +02:00
Nasreddine Bencherchali 5f03a73dd2 Update proc_creation_win_susp_clsid_foldername.yml 2022-09-02 09:33:13 +02:00
frack113 9e5eefd71b Merge pull request #3456 from phantinuss/master
fix: FP in testing environment
2022-09-02 09:30:21 +02:00
Nasreddine Bencherchali ed88295732 Update proc_creation_win_susp_clsid_foldername.yml 2022-09-02 09:28:28 +02:00
phantinuss 48ac804c9e fix: remove part of UNC path 2022-09-02 09:21:48 +02:00
Nasreddine Bencherchali d0e7732ddd Update proc_creation_win_susp_openas_rundll_usage.yml 2022-09-02 09:19:25 +02:00
Nasreddine Bencherchali 48c1104b1a New+Update 2022-09-02 09:15:21 +02:00
frack113 fc3c5cf99a Merge pull request #3455 from pH-T/master
new rule: susp net use combo
2022-09-02 06:58:32 +02:00
frack113 9a1a87de18 Update proc_creation_win_susp_net_use.yml 2022-09-02 06:42:47 +02:00
frack113 367e2fd0f9 Merge pull request #3450 from nasbench/master
Updates+New Rules
2022-09-02 06:39:15 +02:00
phantinuss dee365f562 fix: FP in testing environment 2022-09-01 17:53:06 +02:00
FabFaeb ab9e15f456 fix title 2022-09-01 17:05:32 +02:00
David ANDRE 1e791b85c0 Removing dev rule added by mistake 2022-09-01 15:44:16 +02:00
David ANDRE 33ff230ae1 Added modified date 2022-09-01 15:27:20 +02:00
David ANDRE 0b0190ccb1 Added quotes to strings 2022-09-01 15:22:26 +02:00
Paul Hager 6b2f12cbe6 fix: proc_creation_win_susp_net_use status 2022-09-01 15:01:38 +02:00
Paul Hager a428756340 new rule: susp net use combo 2022-09-01 14:38:06 +02:00
David André ae8cfb1ec0 Merge branch 'SigmaHQ:master' into master 2022-09-01 13:04:11 +02:00
David ANDRE a0a30bad8c Correcting values for startswith 2022-09-01 13:03:19 +02:00
Tim Shelton 1bb172e4ae False positive when commandline is only cmd.exe /c 2022-08-31 19:38:25 +00:00
Florian Roth 5a4b3d6b71 Update file_rename_win_ransomware.yml 2022-08-31 16:08:12 +02:00
Florian Roth 6e1c647019 Merge branch 'master' into aurora-false-positive-fixing 2022-08-31 13:55:52 +02:00
Florian Roth 65c6f82169 Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing 2022-08-31 13:55:46 +02:00
Florian Roth 893fc6c15d fix: FP with controller config 2022-08-31 13:55:43 +02:00
Nasreddine Bencherchali b0bd1a2184 Update win_msi_install_from_susp_locations.yml 2022-08-31 13:55:30 +02:00
Nasreddine Bencherchali 7b92cbb6d0 Create win_msi_install_from_susp_locations.yml 2022-08-31 13:54:50 +02:00
Nasreddine Bencherchali 783fd8b160 Create proc_creation_win_susp_schtasks_schedule_type.yml 2022-08-31 10:08:31 +02:00
FabFaeb df2ef5a2ee added missing newline 2022-08-31 09:59:29 +02:00
FabFaeb 3a020ce499 added "failed admin share mount" rule 2022-08-31 09:57:09 +02:00
Nasreddine Bencherchali 80098113d0 Update image_load_susp_cmstp.yml 2022-08-31 09:53:07 +02:00
Nasreddine Bencherchali 343b0ef199 Update net_connection_win_susp_cmstp.yml 2022-08-31 09:46:18 +02:00
Nasreddine Bencherchali 77c5640839 Update net_connection_win_susp_cmstp.yml 2022-08-31 09:42:25 +02:00
Nasreddine Bencherchali 399a18b762 Update net_connection_win_susp_cmstp.yml 2022-08-31 09:41:25 +02:00
Nasreddine Bencherchali ea183cae13 Updates+New Rules 2022-08-31 09:39:16 +02:00
Borna Talebi 8dfe06a33b Adding Google Chrome FP 2022-08-31 11:35:12 +04:30
Florian Roth aa0545b6c7 refactor: added extension to ransomware rule 2022-08-31 08:40:24 +02:00
Florian Roth 35d9e5f36a fix: syntax error, docs: change fp text 2022-08-30 11:29:11 +02:00
Florian Roth b5c57e97fc Merge branch 'master' into rule-devel 2022-08-30 09:14:37 +02:00
Florian Roth 52c5851ef6 rules: wmic extended, defendercheck, sharpldapwhoami 2022-08-30 09:13:25 +02:00
frack113 da72e3b7c0 Merge pull request #3441 from ionsor/patch-6
Update net_connection_win_dead_drop_resolvers.yml
2022-08-30 08:38:17 +02:00
frack113 f9b79161a5 Merge pull request #3444 from danielgottt/patch-7
Create proc_creation_win_deviceenroller_evasion.yml
2022-08-30 08:24:24 +02:00
frack113 45a87dd22d Update net_connection_win_dead_drop_resolvers.yml 2022-08-30 08:22:10 +02:00