Commit Graph

15089 Commits

Author SHA1 Message Date
Florian Roth 677cf08bab Merge pull request #3583 from SigmaHQ/rule-devel
refactor: addition to Rubeus rule
2022-10-12 18:01:00 +02:00
Florian Roth 0a330250ea Merge pull request #3576 from phantinuss/master
FP fixes and minor QA
2022-10-12 18:00:11 +02:00
phantinuss c5fb5e1c95 fix: remove FPs found in goodlogs 2022-10-12 17:04:31 +02:00
phantinuss ca58e92d52 fix: FP found in testing environment 2022-10-12 16:59:25 +02:00
phantinuss 40f64a6b69 fix: unneeded fieldmapping for THOR/Aurora 2022-10-12 16:17:18 +02:00
nasreddine.bencherchali@nextron-systems.com 3ac4ad7643 Rename+Update Browser Remote Debugging Rule 2022-10-12 15:58:34 +02:00
frack113 df42555c3e Merge pull request #3575 from frack113/file_rename
Add definition for file_rename
2022-10-12 13:55:17 +02:00
nasreddine.bencherchali@nextron-systems.com 626effcad4 Update proc_creation_win_susp_plink_usage.yml 2022-10-12 11:25:01 +02:00
nasreddine.bencherchali@nextron-systems.com d3ca351834 New SSH.EXE rules 2022-10-12 11:24:54 +02:00
nasreddine.bencherchali@nextron-systems.com faad0209de Rename Plink Port Forward Rule 2022-10-12 11:24:28 +02:00
Nasreddine Bencherchali f55f4ca2d6 Update Rules 2022-10-12 10:04:15 +02:00
Nasreddine Bencherchali d42e5b5435 New Rules 2022-10-12 10:04:04 +02:00
Hendrik Baecker aa3c93e8dc Changed title 2022-10-12 09:05:27 +02:00
Hendrik Baecker 01ca4712f3 MSSQL stored procedure - maggie 2022-10-12 08:51:30 +02:00
frack113 f2aa1cacf0 Add OriginalFileName 2022-10-12 06:36:32 +02:00
frack113 8eed237931 Update proc_creation_win_unusual_parent_for_cmd.yml 2022-10-12 06:28:58 +02:00
frack113 4acc692633 Update proc_creation_win_susp_certutil_command.yml 2022-10-12 06:28:34 +02:00
Thomas Patzke cd017a3431 Make Sigma logo license explicit 2022-10-11 21:54:32 +02:00
frack113 9318ff3a45 Merge pull request #3578 from frack113/modified
Fix modified
2022-10-11 20:50:47 +02:00
frack113 d5b6451f90 Fix modified 2022-10-11 20:30:31 +02:00
phantinuss 50f3be2dfe fix: FP with winget installation 2022-10-11 19:24:32 +02:00
Gude5 2a1233c965 Updated some rules after review 2022-10-11 16:31:56 +02:00
phantinuss af9d04aa9c fix: FPs occurring when using winget upgrade 2022-10-11 16:25:03 +02:00
phantinuss b426785ba8 chore: new test for unknown value modifier 2022-10-11 16:25:03 +02:00
phantinuss 7d6e72a5b5 chore: fix redirect to stderr 2022-10-11 16:25:03 +02:00
Nasreddine Bencherchali 0e40a65bef Fix FP caused by short atoms
Added spaces to avoid fp
2022-10-11 14:37:34 +02:00
Nasreddine Bencherchali f5a0299e35 Fix FP from testing on Win7 2022-10-11 14:04:28 +02:00
Nasreddine Bencherchali 563a3d5646 Reduce level to medium 2022-10-11 14:04:14 +02:00
Tim Rauch cd6ee66a38 Updated some rules 2022-10-11 13:48:42 +02:00
Tim Rauch d84e281e96 Updated cbb9e3d1-2386-4e59-912e-62f1484f7a89 2022-10-11 13:42:24 +02:00
Tim Rauch c4fec44e5b Updated some rules 2022-10-11 13:28:59 +02:00
Tim Rauch a94832de90 Updated rule 488b44e7-3781-4a71-888d-c95abfacf44d 2022-10-11 12:39:40 +02:00
Tim Rauch 4ab6fe537a Updated some rules 2022-10-11 12:38:23 +02:00
Tim Rauch 204835e388 Updated rule 71c276aa-49cd-43d2-b920-2dcd3e6962d5 2022-10-11 12:00:59 +02:00
Tim Rauch 265d9bfe09 Updated rule 71c276aa-49cd-43d2-b920-2dcd3e6962d5 2022-10-11 11:59:46 +02:00
Florian Roth 8d9c11b26e Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2022-10-11 11:40:07 +02:00
Florian Roth 5ad51c4dea refactor: additional Rubeus indicators 2022-10-11 11:40:03 +02:00
Tim Rauch 3454738439 Merge branch 'master' 2022-10-11 11:32:20 +02:00
Gude5 2d5939e33b Merge branch 'SigmaHQ:master' into master 2022-10-11 11:29:48 +02:00
Tim Rauch b992a0e340 fix: updated rules after review 2022-10-11 11:29:08 +02:00
frack113 356f6d4528 Add definition 2022-10-11 11:07:37 +02:00
Florian Roth a55cea92e0 Merge pull request #3572 from nasbench/nasbench-rule-devel
Rule Dev - Small Updates
2022-10-11 00:40:35 +02:00
Florian Roth 41d2ece9f4 Merge pull request #3573 from SigmaHQ/rule-devel
rule: Process Hacker, PCHunter; ZINC APT UA
2022-10-11 00:40:21 +02:00
Florian Roth 0df87d76f2 fix: duplicate, list with one entry 2022-10-10 22:49:34 +02:00
Florian Roth 6714d65430 Merge pull request #3574 from nasbench/fix-false-positives
Fix FP Found In Testing
2022-10-10 18:58:28 +02:00
Nasreddine Bencherchali bf28e42f01 Fix FP Found In Testing 2022-10-10 17:33:14 +02:00
Florian Roth b2c012146e rules: pchunter, process hacker 2022-10-10 17:21:17 +02:00
Gude5 4a2a6037de Update rules/windows/process_creation/proc_creation_win_unusual_child_process_of_dns_exe.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:05:10 +02:00
Gude5 5275ade621 Update rules/windows/process_creation/proc_creation_win_susp_cmd_exectution_via_wmi.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:05:01 +02:00
Gude5 eb65a3f5c5 Update rules/windows/process_creation/proc_creation_win_remote_desktop_tunneling.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-10-10 17:04:38 +02:00