Florian Roth
|
677cf08bab
|
Merge pull request #3583 from SigmaHQ/rule-devel
refactor: addition to Rubeus rule
|
2022-10-12 18:01:00 +02:00 |
|
Florian Roth
|
0a330250ea
|
Merge pull request #3576 from phantinuss/master
FP fixes and minor QA
|
2022-10-12 18:00:11 +02:00 |
|
phantinuss
|
c5fb5e1c95
|
fix: remove FPs found in goodlogs
|
2022-10-12 17:04:31 +02:00 |
|
phantinuss
|
ca58e92d52
|
fix: FP found in testing environment
|
2022-10-12 16:59:25 +02:00 |
|
phantinuss
|
40f64a6b69
|
fix: unneeded fieldmapping for THOR/Aurora
|
2022-10-12 16:17:18 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
3ac4ad7643
|
Rename+Update Browser Remote Debugging Rule
|
2022-10-12 15:58:34 +02:00 |
|
frack113
|
df42555c3e
|
Merge pull request #3575 from frack113/file_rename
Add definition for file_rename
|
2022-10-12 13:55:17 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
626effcad4
|
Update proc_creation_win_susp_plink_usage.yml
|
2022-10-12 11:25:01 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
d3ca351834
|
New SSH.EXE rules
|
2022-10-12 11:24:54 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
faad0209de
|
Rename Plink Port Forward Rule
|
2022-10-12 11:24:28 +02:00 |
|
Nasreddine Bencherchali
|
f55f4ca2d6
|
Update Rules
|
2022-10-12 10:04:15 +02:00 |
|
Nasreddine Bencherchali
|
d42e5b5435
|
New Rules
|
2022-10-12 10:04:04 +02:00 |
|
Hendrik Baecker
|
aa3c93e8dc
|
Changed title
|
2022-10-12 09:05:27 +02:00 |
|
Hendrik Baecker
|
01ca4712f3
|
MSSQL stored procedure - maggie
|
2022-10-12 08:51:30 +02:00 |
|
frack113
|
f2aa1cacf0
|
Add OriginalFileName
|
2022-10-12 06:36:32 +02:00 |
|
frack113
|
8eed237931
|
Update proc_creation_win_unusual_parent_for_cmd.yml
|
2022-10-12 06:28:58 +02:00 |
|
frack113
|
4acc692633
|
Update proc_creation_win_susp_certutil_command.yml
|
2022-10-12 06:28:34 +02:00 |
|
Thomas Patzke
|
cd017a3431
|
Make Sigma logo license explicit
|
2022-10-11 21:54:32 +02:00 |
|
frack113
|
9318ff3a45
|
Merge pull request #3578 from frack113/modified
Fix modified
|
2022-10-11 20:50:47 +02:00 |
|
frack113
|
d5b6451f90
|
Fix modified
|
2022-10-11 20:30:31 +02:00 |
|
phantinuss
|
50f3be2dfe
|
fix: FP with winget installation
|
2022-10-11 19:24:32 +02:00 |
|
Gude5
|
2a1233c965
|
Updated some rules after review
|
2022-10-11 16:31:56 +02:00 |
|
phantinuss
|
af9d04aa9c
|
fix: FPs occurring when using winget upgrade
|
2022-10-11 16:25:03 +02:00 |
|
phantinuss
|
b426785ba8
|
chore: new test for unknown value modifier
|
2022-10-11 16:25:03 +02:00 |
|
phantinuss
|
7d6e72a5b5
|
chore: fix redirect to stderr
|
2022-10-11 16:25:03 +02:00 |
|
Nasreddine Bencherchali
|
0e40a65bef
|
Fix FP caused by short atoms
Added spaces to avoid fp
|
2022-10-11 14:37:34 +02:00 |
|
Nasreddine Bencherchali
|
f5a0299e35
|
Fix FP from testing on Win7
|
2022-10-11 14:04:28 +02:00 |
|
Nasreddine Bencherchali
|
563a3d5646
|
Reduce level to medium
|
2022-10-11 14:04:14 +02:00 |
|
Tim Rauch
|
cd6ee66a38
|
Updated some rules
|
2022-10-11 13:48:42 +02:00 |
|
Tim Rauch
|
d84e281e96
|
Updated cbb9e3d1-2386-4e59-912e-62f1484f7a89
|
2022-10-11 13:42:24 +02:00 |
|
Tim Rauch
|
c4fec44e5b
|
Updated some rules
|
2022-10-11 13:28:59 +02:00 |
|
Tim Rauch
|
a94832de90
|
Updated rule 488b44e7-3781-4a71-888d-c95abfacf44d
|
2022-10-11 12:39:40 +02:00 |
|
Tim Rauch
|
4ab6fe537a
|
Updated some rules
|
2022-10-11 12:38:23 +02:00 |
|
Tim Rauch
|
204835e388
|
Updated rule 71c276aa-49cd-43d2-b920-2dcd3e6962d5
|
2022-10-11 12:00:59 +02:00 |
|
Tim Rauch
|
265d9bfe09
|
Updated rule 71c276aa-49cd-43d2-b920-2dcd3e6962d5
|
2022-10-11 11:59:46 +02:00 |
|
Florian Roth
|
8d9c11b26e
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2022-10-11 11:40:07 +02:00 |
|
Florian Roth
|
5ad51c4dea
|
refactor: additional Rubeus indicators
|
2022-10-11 11:40:03 +02:00 |
|
Tim Rauch
|
3454738439
|
Merge branch 'master'
|
2022-10-11 11:32:20 +02:00 |
|
Gude5
|
2d5939e33b
|
Merge branch 'SigmaHQ:master' into master
|
2022-10-11 11:29:48 +02:00 |
|
Tim Rauch
|
b992a0e340
|
fix: updated rules after review
|
2022-10-11 11:29:08 +02:00 |
|
frack113
|
356f6d4528
|
Add definition
|
2022-10-11 11:07:37 +02:00 |
|
Florian Roth
|
a55cea92e0
|
Merge pull request #3572 from nasbench/nasbench-rule-devel
Rule Dev - Small Updates
|
2022-10-11 00:40:35 +02:00 |
|
Florian Roth
|
41d2ece9f4
|
Merge pull request #3573 from SigmaHQ/rule-devel
rule: Process Hacker, PCHunter; ZINC APT UA
|
2022-10-11 00:40:21 +02:00 |
|
Florian Roth
|
0df87d76f2
|
fix: duplicate, list with one entry
|
2022-10-10 22:49:34 +02:00 |
|
Florian Roth
|
6714d65430
|
Merge pull request #3574 from nasbench/fix-false-positives
Fix FP Found In Testing
|
2022-10-10 18:58:28 +02:00 |
|
Nasreddine Bencherchali
|
bf28e42f01
|
Fix FP Found In Testing
|
2022-10-10 17:33:14 +02:00 |
|
Florian Roth
|
b2c012146e
|
rules: pchunter, process hacker
|
2022-10-10 17:21:17 +02:00 |
|
Gude5
|
4a2a6037de
|
Update rules/windows/process_creation/proc_creation_win_unusual_child_process_of_dns_exe.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:05:10 +02:00 |
|
Gude5
|
5275ade621
|
Update rules/windows/process_creation/proc_creation_win_susp_cmd_exectution_via_wmi.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:05:01 +02:00 |
|
Gude5
|
eb65a3f5c5
|
Update rules/windows/process_creation/proc_creation_win_remote_desktop_tunneling.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2022-10-10 17:04:38 +02:00 |
|