Nasreddine Bencherchali
|
179559a1db
|
Merge pull request #3811 from nasbench/nasbench-rule-devel
fix: typo in near operator
|
2022-12-22 16:14:14 +01:00 |
|
Nasreddine Bencherchali
|
57e51cca2a
|
fix: typo in near operator
|
2022-12-22 16:08:21 +01:00 |
|
Nasreddine Bencherchali
|
3fc4390767
|
Merge pull request #3809 from qasimqlf/patch-18
fix: updated targetUserName and ipAddress
|
2022-12-22 15:16:52 +01:00 |
|
Florian Roth
|
9aa823fe3b
|
Merge pull request #3810 from nasbench/nasbench-rule-devel
feat: rule dev and updates
|
2022-12-22 15:04:08 +01:00 |
|
Nasreddine Bencherchali
|
17aae0161d
|
fix: add other missing encoded @ symbol
|
2022-12-22 14:55:20 +01:00 |
|
Nasreddine Bencherchali
|
d6b6984567
|
fix: add encoded @ symbol
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-12-22 14:53:34 +01:00 |
|
Nasreddine Bencherchali
|
74f198460e
|
fix: add good ua as filter
|
2022-12-22 14:50:30 +01:00 |
|
Nasreddine Bencherchali
|
62a828e184
|
feat: more updates
|
2022-12-22 14:45:53 +01:00 |
|
Nasreddine Bencherchali
|
7ed105bccb
|
fix: add response code
|
2022-12-22 14:36:32 +01:00 |
|
Nasreddine Bencherchali
|
8fd9181392
|
fix: typo in selection
|
2022-12-22 14:35:22 +01:00 |
|
Nasreddine Bencherchali
|
cc3dce61d7
|
fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-22 14:25:50 +01:00 |
|
Nasreddine Bencherchali
|
3b54d8de79
|
fix: metadata
|
2022-12-22 12:20:18 +01:00 |
|
Nasreddine Bencherchali
|
f79c09c1ff
|
fix: duplicate id
|
2022-12-22 12:14:55 +01:00 |
|
Nasreddine Bencherchali
|
e61795a1ea
|
feat: proxynotshell owa variant rules
|
2022-12-22 12:10:29 +01:00 |
|
frack113
|
a9a0d6217d
|
Merge pull request #3808 from veramine/patch-11
Remove Logitech auto-updater false positive
|
2022-12-22 10:37:45 +01:00 |
|
frack113
|
e32ea31983
|
Merge pull request #3807 from frack113/issue_3724_v2
Issue 3724 v2
|
2022-12-22 10:32:22 +01:00 |
|
frack113
|
fec24ddd0f
|
Merge pull request #3806 from veramine/patch-10
Remove Windows 10 user experience false positive
|
2022-12-22 10:32:10 +01:00 |
|
Nasreddine Bencherchali
|
653b498315
|
fix: update modified field
|
2022-12-22 10:31:25 +01:00 |
|
Qasim Qlf
|
29377ddfff
|
fix: updated targetUserName and ipAddress
|
2022-12-22 14:16:25 +05:00 |
|
Veramine
|
5bdf52beae
|
Remove Logitech auto-updater false positive
|
2022-12-21 23:49:14 -08:00 |
|
frack113
|
a27dc6c43a
|
Check for issue 3724
|
2022-12-22 08:46:25 +01:00 |
|
Veramine
|
3bb741af66
|
Remove Windows 10 volume control false positive
https://superuser.com/questions/1175267/what-is-this-rundll32-instance-running
|
2022-12-21 23:41:39 -08:00 |
|
frack113
|
44a25df15f
|
Check for issue 3724
|
2022-12-22 08:41:37 +01:00 |
|
BlueTeamOps
|
426dc04fd1
|
Added timeframe
|
2022-12-22 07:56:14 +11:00 |
|
BlueTeamOps
|
855ca77253
|
Added a timeframe
|
2022-12-22 07:49:26 +11:00 |
|
BlueTeamOps
|
3b4bf47d59
|
Added timeframe
|
2022-12-22 07:40:48 +11:00 |
|
Nasreddine Bencherchali
|
e71d45b007
|
Merge branch 'SigmaHQ:master' into nasbench-rule-devel
|
2022-12-21 21:39:37 +01:00 |
|
Nasreddine Bencherchali
|
9d4bbec633
|
Merge pull request #3805 from zakibro/master
Create lnx_privileged_user_creation.yml
|
2022-12-21 21:35:59 +01:00 |
|
Nasreddine Bencherchali
|
4c7db89847
|
fix: improve overall structure
|
2022-12-21 20:40:29 +01:00 |
|
Nasreddine Bencherchali
|
b9ae5303f1
|
Merge pull request #2801 from tuanhxh1/master
add rules related to usage of "usermod"
|
2022-12-21 20:33:04 +01:00 |
|
zakibro
|
a0c07b2fba
|
Update rules/linux/builtin/lnx_privileged_user_creation.yml
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-21 19:31:34 +01:00 |
|
zakibro
|
14f006382a
|
Update rules/linux/builtin/lnx_privileged_user_creation.yml
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-21 19:31:24 +01:00 |
|
Nasreddine Bencherchali
|
d51ff694a4
|
fix: rule status
|
2022-12-21 19:23:23 +01:00 |
|
zakibro
|
0fa4f8a454
|
Create lnx_privileged_user_creation.yml
Adding new use case for tracking of Creation of privileged user in linux
|
2022-12-21 18:16:20 +01:00 |
|
Nasreddine Bencherchali
|
c97463e774
|
fix: update linux rules
|
2022-12-21 17:59:46 +01:00 |
|
sai prashanth pulisetti
|
3b6100ccd9
|
Create Possible Manipulation Of Tokens on a Windows computers remotely Detected via impersonate (#3803)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-12-21 13:27:22 +01:00 |
|
Nasreddine Bencherchali
|
120196b2fc
|
fix: resolve #2613
|
2022-12-21 10:33:31 +01:00 |
|
Florian Roth
|
b75c7d4bdb
|
Merge pull request #3802 from nasbench/nasbench-rule-devel
feat: updates and enhancements
|
2022-12-21 10:02:23 +01:00 |
|
Florian Roth
|
f9d1eb1f2d
|
Update proc_creation_win_renamed_office_processes.yml
|
2022-12-21 09:18:06 +01:00 |
|
Florian Roth
|
b157bef3de
|
fix: link to correct issue
|
2022-12-21 08:59:24 +01:00 |
|
Florian Roth
|
9372987801
|
fix: missing upper tick
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
|
2022-12-21 08:57:37 +01:00 |
|
Florian Roth
|
7e7cbe41c3
|
docs: change modified date
|
2022-12-21 08:57:05 +01:00 |
|
Florian Roth
|
7f4a84963c
|
style: reordered fields
|
2022-12-21 08:56:26 +01:00 |
|
Nasreddine Bencherchali
|
4b6f5f143d
|
feat: add more suspicious cases
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-12-21 00:18:44 +01:00 |
|
Nasreddine Bencherchali
|
7c46e4c3c0
|
fix: fix #2479
|
2022-12-21 00:11:04 +01:00 |
|
Florian Roth
|
2580b84de3
|
fix: typo
|
2022-12-21 00:07:51 +01:00 |
|
Nasreddine Bencherchali
|
beccf416da
|
feat: add two new rules
|
2022-12-20 23:44:44 +01:00 |
|
Nasreddine Bencherchali
|
321e54a3c3
|
Merge pull request #3801 from zakibro/master
Modifying Creation Of An User Account
|
2022-12-20 22:59:41 +01:00 |
|
Nasreddine Bencherchali
|
c36acb333f
|
fix: typo in comment
|
2022-12-20 22:28:49 +01:00 |
|
Nasreddine Bencherchali
|
6679347fe3
|
fix: rename files to follow convention
|
2022-12-20 22:25:49 +01:00 |
|