frack113
|
d10ecf5527
|
Merge pull request #3838 from redsand/fp_sysmon_werfault_child
FP when sysmon crashes and werfault gets launched
|
2022-12-30 10:08:09 +01:00 |
|
frack113
|
b2e93afba0
|
Update proc_creation_win_invoke_obfuscation_via_use_rundll32.yml
|
2022-12-30 09:53:25 +01:00 |
|
zydyka
|
d7bc30587f
|
Update proc_creation_win_sysmon_exploitation.yml
|
2022-12-30 09:00:57 +05:00 |
|
Nasreddine Bencherchali
|
1e29560591
|
fix: duplicate title
|
2022-12-30 01:10:03 +01:00 |
|
Nasreddine Bencherchali
|
2d5231ca2c
|
fix: broken selection
|
2022-12-30 00:58:17 +01:00 |
|
Nasreddine Bencherchali
|
c6fd915619
|
feat: updates and enhancements
|
2022-12-30 00:56:40 +01:00 |
|
Tim Shelton
|
aeab567fb9
|
FP when sysmon crashes and werfault gets launched
|
2022-12-29 21:18:26 +00:00 |
|
Nasreddine Bencherchali
|
1c2660b469
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2022-12-29 19:42:54 +01:00 |
|
frack113
|
b97a7e0b0f
|
Merge pull request #3837 from fukusuket/fix-powershell-token-obfuscation-regex
refactor: regex escapes in `|re` block(`{`, `}`, `"`, `backquote`)
|
2022-12-29 19:37:26 +01:00 |
|
Nasreddine Bencherchali
|
5e22c69c3c
|
feat: add file_access case in test (#3836)
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-29 19:35:21 +01:00 |
|
Nasreddine Bencherchali
|
964da01186
|
fix: test logic
|
2022-12-29 18:27:58 +01:00 |
|
Nasreddine Bencherchali
|
c2e8283806
|
fix: add missing try/except
|
2022-12-29 17:30:26 +01:00 |
|
Nasreddine Bencherchali
|
61901a97c7
|
Merge pull request #3832 from SigmaHQ/aurora-false-positive-fixing
fix: Discord FP
|
2022-12-29 17:25:27 +01:00 |
|
Nasreddine Bencherchali
|
d0920f0931
|
fix: small error in deletion
|
2022-12-29 17:23:38 +01:00 |
|
Nasreddine Bencherchali
|
e20cb470cc
|
fix: enhance element deletion
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-29 17:19:01 +01:00 |
|
Nasreddine Bencherchali
|
07cc91719c
|
fix: enhance selection
|
2022-12-29 17:14:21 +01:00 |
|
fukusuket
|
42ab7c0484
|
fix regex escape
|
2022-12-30 00:11:52 +09:00 |
|
Nasreddine Bencherchali
|
123202f112
|
feat: add file_access case in test
|
2022-12-29 15:30:57 +01:00 |
|
frack113
|
197615345b
|
Add missing lolbin OSBinaries (#3835)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-29 14:36:33 +01:00 |
|
Nasreddine Bencherchali
|
c2ad03cfa2
|
Merge pull request #3834 from nasbench/nasbench-rule-devel
feat: updates and new rules
|
2022-12-29 13:25:52 +01:00 |
|
Nasreddine Bencherchali
|
d38195ea31
|
fix: remove folder start
|
2022-12-29 11:32:37 +01:00 |
|
Nasreddine Bencherchali
|
425c29cf1c
|
feat: add new linux rules
|
2022-12-29 11:17:42 +01:00 |
|
Nasreddine Bencherchali
|
19396788db
|
Merge pull request #3831 from redsand/fp_suspicious_process_privilege
FP: filters out erl.exe running handle.exe with elevated privileges
|
2022-12-28 21:18:54 +01:00 |
|
Nasreddine Bencherchali
|
fb55d48abf
|
Merge pull request #3833 from SigmaHQ/rule-devel
fix: Windows Defender detection
|
2022-12-28 21:07:51 +01:00 |
|
Florian Roth
|
f3abafed94
|
fix: Windows Defender detection
|
2022-12-28 20:52:53 +01:00 |
|
Florian Roth
|
bc5ed3e453
|
fix: Discord FP
|
2022-12-28 20:39:26 +01:00 |
|
BlueTeamOps
|
05135ec828
|
Further improved several AWS rules (#3827)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-28 19:46:36 +01:00 |
|
Nasreddine Bencherchali
|
77113a7340
|
fix: author ref
|
2022-12-28 18:42:47 +01:00 |
|
Nasreddine Bencherchali
|
3677b9f2e6
|
fix: enhance fp filter
|
2022-12-28 18:42:12 +01:00 |
|
Nasreddine Bencherchali
|
7baadc4d3f
|
Merge pull request #3830 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-12-28 18:35:58 +01:00 |
|
Tim Shelton
|
f5fffd8e92
|
FP: filters out erl.exe running handle.exe with elevated privileges
|
2022-12-28 16:44:25 +00:00 |
|
Nasreddine Bencherchali
|
a37955efdb
|
Merge pull request #3828 from Korving-F/win_ldap_recon_addition
Update win_ldap_recon.yml
|
2022-12-28 17:00:11 +01:00 |
|
Nasreddine Bencherchali
|
a1038670aa
|
feat: add new reference
|
2022-12-28 16:17:46 +01:00 |
|
frack113
|
3b54304ac6
|
Update Workflow action (#3829)
|
2022-12-28 13:58:10 +01:00 |
|
Korving-F
|
bf79fa78bc
|
Updates modified timestamp
|
2022-12-28 14:52:27 +02:00 |
|
Florian Roth
|
737eacc671
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-12-28 13:28:56 +01:00 |
|
Florian Roth
|
3210af92fd
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-12-28 13:28:47 +01:00 |
|
Florian Roth
|
9ea8b2e2c1
|
fix: Discord FP
|
2022-12-28 13:28:45 +01:00 |
|
Frank Korving
|
0f55e70a4f
|
Update win_ldap_recon.yml
Adds additional IOC for [bloodhound.py](https://github.com/fox-it/BloodHound.py/blob/master/bloodhound/ad/domain.py#L427).
|
2022-12-28 13:45:37 +02:00 |
|
frack113
|
b3ec85b25b
|
Merge pull request #3826 from nasbench/fix-old-sigma-link
fix: rename links from old repo to SigmaHQ
|
2022-12-28 11:11:04 +01:00 |
|
Nasreddine Bencherchali
|
a25027fef8
|
fix: rename links from old repo to SigmaHQ
|
2022-12-27 21:05:16 +01:00 |
|
frack113
|
0392f92a0d
|
PowerShell Token Obfuscation (#3825)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-27 20:03:05 +01:00 |
|
frack113
|
e1707c8f50
|
rewrite issue 1555 (#3818)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-27 19:28:34 +01:00 |
|
Nasreddine Bencherchali
|
38a8696e51
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2022-12-27 17:01:07 +01:00 |
|
Nasreddine Bencherchali
|
85aa0220d0
|
Merge pull request #3819 from blueteam0ps/master
lnx_auditd_debugfs_usage.yml
|
2022-12-27 16:57:22 +01:00 |
|
Florian Roth
|
3e712480c4
|
Merge pull request #3824 from SigmaHQ/rule-devel
Htran/NATbypass, Greedy RAR
|
2022-12-27 16:34:33 +01:00 |
|
Nasreddine Bencherchali
|
88e56229cf
|
fix: indentation and selection names for clarity
|
2022-12-27 16:26:20 +01:00 |
|
Nasreddine Bencherchali
|
0d2ddb4a9b
|
fix: small selection fix for clarity
|
2022-12-27 16:23:09 +01:00 |
|
Nasreddine Bencherchali
|
256d6a839e
|
fix: update condition
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-27 16:13:56 +01:00 |
|
Florian Roth
|
32a17342b4
|
Update rules/windows/process_creation/proc_creation_win_rar_susp_greedy.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-27 15:46:37 +01:00 |
|