Commit Graph

15089 Commits

Author SHA1 Message Date
frack113 41c850e00b Use W3C cs-uri-query 2023-01-02 18:45:50 +01:00
frack113 a1a94a0b66 Update W3C field name 2023-01-02 16:39:55 +01:00
frack113 a6659bc7d8 Update W3C field name 2023-01-02 16:00:29 +01:00
frack113 99172a99e2 Update W3C field name 2023-01-02 15:56:10 +01:00
Nasreddine Bencherchali 9f2b1e081b Merge pull request #3853 from D3F7A5105/master
Rules for detecting changes in the storage paths of evtx logs
2023-01-02 15:55:35 +01:00
Nasreddine Bencherchali 241abb519e Merge pull request #3854 from nasbench/nasbench-rule-devel
feat: updates and enhancements
2023-01-02 15:51:54 +01:00
frack113 8720356684 Update field name 2023-01-02 15:49:45 +01:00
Nasreddine Bencherchali 579b450d17 fix: add missing date 2023-01-02 15:26:41 +01:00
Nasreddine Bencherchali 6819d264cc fix: update evtx tamper rules 2023-01-02 15:25:19 +01:00
Nasreddine Bencherchali 083d30c19d fix: title and add python filter 2023-01-02 15:02:28 +01:00
Nasreddine Bencherchali e23a63a60e fix: typo in field name 2023-01-02 14:52:35 +01:00
Nasreddine Bencherchali 3749416a30 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-02 14:50:27 +01:00
Nasreddine Bencherchali a99b5082e1 feat: updates and enhancements 2023-01-02 14:49:45 +01:00
Nasreddine Bencherchali b2180af63b Merge pull request #3852 from frack113/field_check
Field check
2023-01-02 12:30:29 +01:00
frack113 014684ddcd add win_dns_analytic_ prefix 2023-01-02 12:16:09 +01:00
frack113 b13a74adc9 Update from review 2023-01-02 12:05:54 +01:00
frack113 5e09d46226 Update rules/windows/builtin/dns_server_analytical/win_apt_gallium.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-02 11:56:08 +01:00
vadim 440706e971 Rules for detecting changes in the storage paths of evtx logs 2023-01-02 13:21:33 +03:00
frack113 e09850f968 fix field name 2023-01-02 11:06:57 +01:00
frack113 0e8d1f9b0d Check field name 2023-01-02 10:59:51 +01:00
frack113 31737db86c Merge pull request #3851 from frack113/deprecated
Update modified last change
2023-01-02 10:33:30 +01:00
frack113 9675030f75 Update modified last change 2023-01-02 08:44:46 +01:00
frack113 a26c94caf7 Merge pull request #3849 from frack113/linux_auditd
Add linux auditd check
2023-01-02 07:43:43 +01:00
frack113 27f3ba9257 Add linux auditd 2023-01-01 13:18:51 +01:00
frack113 0aad498425 Last lolbin (#3845)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-31 19:53:44 +01:00
Nasreddine Bencherchali 2240507e77 Merge pull request #3848 from frack113/linux_sysmon
Linux sysmon
2022-12-31 19:41:07 +01:00
frack113 6d0b86aae3 Keep only sysmon linux used 2022-12-31 19:14:40 +01:00
Nasreddine Bencherchali f67cd766d0 Merge pull request #3846 from fukusuket/fix-invalid-regex-escape
fix: remove incorrect backslash escape(in `|re` block)
2022-12-31 18:35:36 +01:00
frack113 b6426ab3f9 Fix file name 2022-12-31 18:23:37 +01:00
frack113 c2ce5d01fc Add sysmon linux v1.0.2 2022-12-31 18:08:11 +01:00
frack113 ddb5cd0ead Add sysmon linux v1.0.2 2022-12-31 18:04:21 +01:00
fukusuket 04ecbbded9 fix: typo modified 2022-12-31 21:57:05 +09:00
fukusuket 9298295c15 fix: remove invalid backslash escape 2022-12-31 21:35:07 +09:00
Fukusuke Takahashi 1ab7324ca0 fix: remove unneeded double backslash escape (#3844) 2022-12-31 08:32:46 +01:00
signalblur 73f56c2f0e Hidden Linux Binary Execution (#3108)
Co-authored-by: Florian Roth <venom14@gmail.com>
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-31 08:27:32 +01:00
Nasreddine Bencherchali 2d09f84cf5 Merge pull request #3842 from frack113/add_test
Add Field name test
2022-12-30 21:09:23 +01:00
Nasreddine Bencherchali 9397a996ab Merge pull request #3843 from fukusuket/refactor-remove-unneeded-backslash-escape
refactor: remove unneeded backslash escape in character class(in `|re` block)
2022-12-30 21:03:03 +01:00
Nasreddine Bencherchali 7dab38b19f fix: add missing modified date 2022-12-30 20:56:21 +01:00
frack113 481ae23c3e Make it more generic 2022-12-30 18:17:31 +01:00
fukusuket bd6243be7d fix: remove unneeded backslash escape in character class. 2022-12-31 00:33:00 +09:00
frack113 4a0b571598 add new test 2022-12-30 16:31:41 +01:00
frack113 3c2e1a6a3e add new test 2022-12-30 16:00:42 +01:00
frack113 2589ffe6b7 Merge pull request #3839 from nasbench/nasbench-rule-devel
feat: updates and enhancements
2022-12-30 11:55:56 +01:00
Nasreddine Bencherchali 261bb8758a Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-30 11:49:08 +01:00
frack113 aee5ca7afc Fix invalid field cast or name (#3841) 2022-12-30 11:46:21 +01:00
Nasreddine Bencherchali d4b9df608b fix: broken selection 2022-12-30 10:30:15 +01:00
Nasreddine Bencherchali 58f47b9875 fix: add known children appvlp 2022-12-30 10:24:25 +01:00
frack113 995b5918f2 Update rules/windows/process_creation/proc_creation_win_susp_shellexec_rundll_usage.yml 2022-12-30 10:21:54 +01:00
frack113 7639b0e307 Merge pull request #3840 from zydyka/patch-1
Update proc_creation_win_sysmon_exploitation.yml
2022-12-30 10:21:22 +01:00
frack113 f083c5f83f Merge branch 'master' into patch-1 2022-12-30 10:12:25 +01:00