Commit Graph

15089 Commits

Author SHA1 Message Date
Florian Roth c0ff746d99 change: make uppercase in Sysmon version 2022-10-06 09:27:26 +02:00
Florian Roth 84641cc955 Update registry_set_susp_user_shell_folders.yml 2022-10-06 09:25:13 +02:00
Florian Roth f0196039ba Update proc_creation_win_susp_logoff.yml 2022-10-06 09:24:15 +02:00
Florian Roth f1435ea16b Update proc_creation_win_susp_logoff.yml 2022-10-06 09:23:37 +02:00
Florian Roth 881dd0c6d0 Update proc_creation_win_pdq_deploy.yml 2022-10-06 09:22:44 +02:00
Florian Roth c3e11104dd Merge pull request #3566 from SigmaHQ/rule-devel
More JuicyPotatoNG patterns
2022-10-06 08:55:34 +02:00
Florian Roth 15232621b1 refactor: another JuicyPotatoNG pattern 2022-10-06 08:47:23 +02:00
Florian Roth b6270dfcf0 Merge branch 'master' into rule-devel 2022-10-06 08:43:02 +02:00
Florian Roth 4063757b3a Merge pull request #3565 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG imphashes
2022-10-06 08:40:14 +02:00
Florian Roth d8c80d9193 docs: add ATT&CK technique id 2022-10-06 08:39:53 +02:00
Florian Roth 8419124990 docs: change modified date 2022-10-06 08:39:12 +02:00
Florian Roth a47ed32736 fix: unused selection in 23eee45e-933b-49f9-ae1b-df706d2d52ef 2022-10-06 08:38:40 +02:00
Florian Roth 98ee0f64a1 Merge pull request #3564 from frack113/issue_3552
Issue 3552
2022-10-06 08:31:41 +02:00
Florian Roth e92f2475b6 refactor: JuicyPotatoNG imphashes 2022-10-06 08:30:48 +02:00
frack113 32406c1915 Issue 3552 2022-10-06 06:50:54 +02:00
frack113 85d33e4af9 Merge pull request #3525 from vastlimits/feature/ame-7.0
Updated uberAgent backend to support version 7.0.
2022-10-06 06:42:57 +02:00
frack113 b1b7428a30 Merge pull request #3560 from redsand/fp_ec2_windows
FP: ignore amazon aws ec2 scripts
2022-10-06 06:41:22 +02:00
frack113 e9ed7d05e1 Merge pull request #3561 from redsand/backend_hawk_cfg_update
BACKEND: updating production config
2022-10-06 06:40:17 +02:00
Nasreddine Bencherchali dadec8b9f0 Update incorrect mitre tags 2022-10-06 00:35:40 +02:00
Nasreddine Bencherchali 545d8170e6 Update proc_creation_lnx_sudo_cve_2019_14287.yml 2022-10-06 00:18:18 +02:00
Florian Roth adfb7d58e8 Merge pull request #3563 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG pattern
2022-10-06 00:10:32 +02:00
Florian Roth d2777f4d02 refactor: JuicyPotatoNG pattern 2022-10-06 00:00:46 +02:00
Nasreddine Bencherchali 2c26614ce4 Update Wildcard + Int to Str fields 2022-10-05 23:15:20 +02:00
Tim Shelton febeadfb4c BACKEND: updating production config 2022-10-05 19:43:39 +00:00
Tim Shelton f65e795e22 FP: ignore amazon aws ec2 scripts 2022-10-05 19:40:37 +00:00
Nasreddine Bencherchali 7176d672b5 Fix wildcard 2022-10-05 17:21:34 +02:00
Nasreddine Bencherchali 88f10a5d39 Fix issues 2022-10-05 17:19:48 +02:00
Nasreddine Bencherchali 18e43cff02 Fix valid accounts tag 2022-10-05 17:18:01 +02:00
Florian Roth 2391bbf96c Merge pull request #3558 from SigmaHQ/aurora-false-positive-fixing
fix: FPs with MS IPs
2022-10-05 13:00:33 +02:00
Florian Roth a029de0390 fix: FPs noticed in testing env 2022-10-05 12:22:42 +02:00
Nasreddine Bencherchali 68937161a0 Add GMER + PCHunter 2022-10-05 12:04:11 +02:00
Nasreddine Bencherchali e2721f57e1 Update driver list with ELASTIC information 2022-10-05 11:01:29 +02:00
Nasreddine Bencherchali 40dcb9a4c9 Update + Rename 2022-10-05 10:42:29 +02:00
Nasreddine Bencherchali 16e377ef5e Fix 2022-10-04 23:12:37 +02:00
Nasreddine Bencherchali e810e907a1 Create posh_ps_psasyncshell.yml 2022-10-04 20:57:15 +02:00
Nasreddine Bencherchali 2ecf9ec7e1 Updates 2022-10-04 20:57:11 +02:00
Florian Roth 50b9a3e073 fix: FPs with MS IPs 2022-10-04 19:21:41 +02:00
Florian Roth ef0e5c76a5 Merge pull request #3557 from SigmaHQ/rule-devel
fix: wrong condition in whoami rule
2022-10-04 16:23:04 +02:00
Florian Roth eee1d2c1cb fix: wrong condition in whoami rule
https://github.com/SigmaHQ/sigma/issues/3556
2022-10-04 16:11:03 +02:00
Florian Roth c42a9548c8 Merge pull request #3555 from SigmaHQ/rule-devel
refactor: add extension
2022-10-04 12:46:58 +02:00
Florian Roth 27ca37ce8f refactor: add extension 2022-10-04 12:29:48 +02:00
Florian Roth 8ed5cc10c1 Merge pull request #3554 from SigmaHQ/rule-devel
rule: suspicious file drop by Exchange
2022-10-04 12:25:51 +02:00
Florian Roth 6088654ec9 docs: added ATT&CK tags 2022-10-04 11:50:45 +02:00
Florian Roth 53aa6295c2 rule: suspicious file drop by Exchange 2022-10-04 11:45:39 +02:00
Nasreddine Bencherchali 48cb48306e Update known-FPs.csv 2022-10-04 11:41:17 +02:00
Nasreddine Bencherchali 098d530577 Fix error in driver rule 2022-10-04 11:38:58 +02:00
Tim Rauch f61c82e7a1 fix: fixed FPs after failed Sigma Rule Test 2022-10-04 11:30:13 +02:00
Tim Rauch b6046803a0 fix: fixed rules after review 2022-10-04 10:06:15 +02:00
Gude5 f692271c0a Merge branch 'SigmaHQ:master' into master 2022-10-04 09:33:51 +02:00
Florian Roth 029900c284 Merge pull request #3548 from aaronherman/patch-1
Update description typo on "Phishing Pattern ISO in Archive"
2022-10-03 19:55:13 +02:00