Commit Graph

15089 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 179559a1db Merge pull request #3811 from nasbench/nasbench-rule-devel
fix: typo in near operator
2022-12-22 16:14:14 +01:00
Nasreddine Bencherchali 57e51cca2a fix: typo in near operator 2022-12-22 16:08:21 +01:00
Nasreddine Bencherchali 3fc4390767 Merge pull request #3809 from qasimqlf/patch-18
fix: updated targetUserName and ipAddress
2022-12-22 15:16:52 +01:00
Florian Roth 9aa823fe3b Merge pull request #3810 from nasbench/nasbench-rule-devel
feat: rule dev and updates
2022-12-22 15:04:08 +01:00
Nasreddine Bencherchali 17aae0161d fix: add other missing encoded @ symbol 2022-12-22 14:55:20 +01:00
Nasreddine Bencherchali d6b6984567 fix: add encoded @ symbol
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-12-22 14:53:34 +01:00
Nasreddine Bencherchali 74f198460e fix: add good ua as filter 2022-12-22 14:50:30 +01:00
Nasreddine Bencherchali 62a828e184 feat: more updates 2022-12-22 14:45:53 +01:00
Nasreddine Bencherchali 7ed105bccb fix: add response code 2022-12-22 14:36:32 +01:00
Nasreddine Bencherchali 8fd9181392 fix: typo in selection 2022-12-22 14:35:22 +01:00
Nasreddine Bencherchali cc3dce61d7 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-22 14:25:50 +01:00
Nasreddine Bencherchali 3b54d8de79 fix: metadata 2022-12-22 12:20:18 +01:00
Nasreddine Bencherchali f79c09c1ff fix: duplicate id 2022-12-22 12:14:55 +01:00
Nasreddine Bencherchali e61795a1ea feat: proxynotshell owa variant rules 2022-12-22 12:10:29 +01:00
frack113 a9a0d6217d Merge pull request #3808 from veramine/patch-11
Remove Logitech auto-updater false positive
2022-12-22 10:37:45 +01:00
frack113 e32ea31983 Merge pull request #3807 from frack113/issue_3724_v2
Issue 3724 v2
2022-12-22 10:32:22 +01:00
frack113 fec24ddd0f Merge pull request #3806 from veramine/patch-10
Remove Windows 10 user experience false positive
2022-12-22 10:32:10 +01:00
Nasreddine Bencherchali 653b498315 fix: update modified field 2022-12-22 10:31:25 +01:00
Qasim Qlf 29377ddfff fix: updated targetUserName and ipAddress 2022-12-22 14:16:25 +05:00
Veramine 5bdf52beae Remove Logitech auto-updater false positive 2022-12-21 23:49:14 -08:00
frack113 a27dc6c43a Check for issue 3724 2022-12-22 08:46:25 +01:00
Veramine 3bb741af66 Remove Windows 10 volume control false positive
https://superuser.com/questions/1175267/what-is-this-rundll32-instance-running
2022-12-21 23:41:39 -08:00
frack113 44a25df15f Check for issue 3724 2022-12-22 08:41:37 +01:00
BlueTeamOps 426dc04fd1 Added timeframe 2022-12-22 07:56:14 +11:00
BlueTeamOps 855ca77253 Added a timeframe 2022-12-22 07:49:26 +11:00
BlueTeamOps 3b4bf47d59 Added timeframe 2022-12-22 07:40:48 +11:00
Nasreddine Bencherchali e71d45b007 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-21 21:39:37 +01:00
Nasreddine Bencherchali 9d4bbec633 Merge pull request #3805 from zakibro/master
Create lnx_privileged_user_creation.yml
2022-12-21 21:35:59 +01:00
Nasreddine Bencherchali 4c7db89847 fix: improve overall structure 2022-12-21 20:40:29 +01:00
Nasreddine Bencherchali b9ae5303f1 Merge pull request #2801 from tuanhxh1/master
add rules related to usage of "usermod"
2022-12-21 20:33:04 +01:00
zakibro a0c07b2fba Update rules/linux/builtin/lnx_privileged_user_creation.yml
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 19:31:34 +01:00
zakibro 14f006382a Update rules/linux/builtin/lnx_privileged_user_creation.yml
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 19:31:24 +01:00
Nasreddine Bencherchali d51ff694a4 fix: rule status 2022-12-21 19:23:23 +01:00
zakibro 0fa4f8a454 Create lnx_privileged_user_creation.yml
Adding new use case for tracking of Creation of privileged user in linux
2022-12-21 18:16:20 +01:00
Nasreddine Bencherchali c97463e774 fix: update linux rules 2022-12-21 17:59:46 +01:00
sai prashanth pulisetti 3b6100ccd9 Create Possible Manipulation Of Tokens on a Windows computers remotely Detected via impersonate (#3803)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-21 13:27:22 +01:00
Nasreddine Bencherchali 120196b2fc fix: resolve #2613 2022-12-21 10:33:31 +01:00
Florian Roth b75c7d4bdb Merge pull request #3802 from nasbench/nasbench-rule-devel
feat: updates and enhancements
2022-12-21 10:02:23 +01:00
Florian Roth f9d1eb1f2d Update proc_creation_win_renamed_office_processes.yml 2022-12-21 09:18:06 +01:00
Florian Roth b157bef3de fix: link to correct issue 2022-12-21 08:59:24 +01:00
Florian Roth 9372987801 fix: missing upper tick
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 08:57:37 +01:00
Florian Roth 7e7cbe41c3 docs: change modified date 2022-12-21 08:57:05 +01:00
Florian Roth 7f4a84963c style: reordered fields 2022-12-21 08:56:26 +01:00
Nasreddine Bencherchali 4b6f5f143d feat: add more suspicious cases
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-12-21 00:18:44 +01:00
Nasreddine Bencherchali 7c46e4c3c0 fix: fix #2479 2022-12-21 00:11:04 +01:00
Florian Roth 2580b84de3 fix: typo 2022-12-21 00:07:51 +01:00
Nasreddine Bencherchali beccf416da feat: add two new rules 2022-12-20 23:44:44 +01:00
Nasreddine Bencherchali 321e54a3c3 Merge pull request #3801 from zakibro/master
Modifying Creation Of An User Account
2022-12-20 22:59:41 +01:00
Nasreddine Bencherchali c36acb333f fix: typo in comment 2022-12-20 22:28:49 +01:00
Nasreddine Bencherchali 6679347fe3 fix: rename files to follow convention 2022-12-20 22:25:49 +01:00