Commit Graph

15089 Commits

Author SHA1 Message Date
Tim Rauch be1f1a4505 New Rules: transformed elastic to sigma rules 2022-09-28 16:45:22 +02:00
mpgn 652447696b Update datadog sigmac 2022-09-28 08:30:03 -04:00
Nasreddine Bencherchali 4a5dcf8586 Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-09-28 13:37:42 +02:00
Nasreddine Bencherchali 69b31b19b1 Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-09-28 13:37:36 +02:00
Florian Roth 5391a5cab4 changed casing, increased level 2022-09-28 13:28:53 +02:00
Florian Roth 5ee44a6992 increased level 2022-09-28 13:27:23 +02:00
Florian Roth ea25382110 increased level 2022-09-28 13:26:23 +02:00
Nasreddine Bencherchali b71644d0c8 New rules + small mitre update 2022-09-28 11:52:07 +02:00
Dieter Schmitz db4edb0aab Revert "Pushed first version of daily task (main.yaml)"
This reverts commit 1b0fbd89be.
2022-09-28 11:40:48 +02:00
Dieter Schmitz 1b0fbd89be Pushed first version of daily task (main.yaml)
Will create all uberAgent ESA files
2022-09-28 11:28:33 +02:00
Nasreddine Bencherchali df6c167b17 New Rules 2022-09-28 10:48:51 +02:00
Nasreddine Bencherchali e3b3265240 Update image_load_side_load_from_non_system_location.yml 2022-09-28 10:48:30 +02:00
frack113 a9dd6f7ff0 Add registry_set_change_winevt_channelaccess (#3505) 2022-09-28 09:53:46 +02:00
nasreddine.bencherchali@nextron-systems.com d262ea2df8 New rules 2022-09-28 09:51:13 +02:00
nasreddine.bencherchali@nextron-systems.com e987c669d0 Updates 2022-09-28 09:50:56 +02:00
frack113 ec6d237cd0 Merge pull request #3522 from frack113/redcannary_20220925
Add redcannary rules
2022-09-28 08:45:06 +02:00
Florian Roth e583d9fc39 Update proc_creation_win_w32tm.yml 2022-09-27 23:52:22 +02:00
Florian Roth 58b7c910dc Update proc_creation_win_w32tm.yml 2022-09-27 23:50:35 +02:00
Florian Roth 46ef664ec6 Merge pull request #3530 from securepeacock/patch-28
Update proc_creation_win_susp_psexesvc_as_system.yml
2022-09-27 23:47:45 +02:00
Florian Roth dd115ca74c Merge pull request #3533 from YamatoSecurity/define-security-mitigations-service
define security-mitigations service
2022-09-27 23:47:26 +02:00
Yamato Security e44e01e106 update modified tag 2022-09-28 06:32:34 +09:00
Yamato Security 979502921f define security-mitigations service 2022-09-28 06:23:50 +09:00
unknown a0275ab124 New pipename criteria from redcanary 2022-09-27 15:37:14 -04:00
securepeacock e90c91668d Update proc_creation_win_susp_psexesvc_as_system.yml
Typo Fixed
2022-09-27 13:45:53 -04:00
frack113 f220b72b0a Merge pull request #3528 from qasimqlf/master
Update proc_creation_win_uac_bypass_icmluautil.yml
2022-09-27 19:32:27 +02:00
Qasim Qlf ec657a3118 Merge branch 'master' into master 2022-09-27 16:26:22 +05:00
nasreddine.bencherchali@nextron-systems.com 43d12249a0 Renamed create remote thread rules 2022-09-27 12:13:16 +02:00
nasreddine.bencherchali@nextron-systems.com 27d08a2eb9 Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel 2022-09-27 12:09:37 +02:00
Florian Roth e2aacfea35 Merge pull request #3519 from SigmaHQ/rule-devel
Rule devel
2022-09-27 12:05:22 +02:00
Florian Roth be265d06ed fix: casing of field 2022-09-27 11:51:48 +02:00
Florian Roth 556441f4d8 Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing 2022-09-27 11:51:30 +02:00
Florian Roth 6eeee7eff4 fix: casing of field 2022-09-27 11:51:27 +02:00
Florian Roth be9fb6a6bd Merge pull request #3523 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-09-27 11:10:11 +02:00
Florian Roth d2f7ff8059 Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing 2022-09-27 10:47:21 +02:00
Florian Roth 5e6a926ac3 fix: FPs 2022-09-27 10:47:19 +02:00
Florian Roth e46d19e450 fix: condition 2022-09-27 10:30:34 +02:00
Florian Roth 43d9f3a13b Merge branch 'master' into rule-devel 2022-09-27 10:29:03 +02:00
nasreddine.bencherchali@nextron-systems.com a66ba61712 Fix small typos 2022-09-27 10:27:21 +02:00
Florian Roth 8f617f4645 Merge pull request #3527 from qasimqlf/patch-7
Fix the filter
2022-09-27 10:24:33 +02:00
Qasim Qlf de517ba8a2 Update proc_creation_win_uac_bypass_icmluautil.yml 2022-09-27 13:21:48 +05:00
Qasim Qlf 600494adbc Fix the filter 2022-09-27 13:11:08 +05:00
Sven Scharmentke 5d9edbbb28 Merge remote-tracking branch 'origin/master' into feature/ame-6.3 2022-09-27 09:48:24 +02:00
Florian Roth 408bf97181 Update proc_creation_win_susp_renamed_createdump.yml 2022-09-27 09:12:44 +02:00
Florian Roth b53f08b081 Update proc_creation_win_process_dump_rundll32_comsvcs.yml 2022-09-27 09:12:06 +02:00
frack113 9bb830d2fc Merge pull request #3524 from YamatoSecurity/add-diagnosis-scripted-to-windows-services-file
add diagnosis-scripted to windows services file
2022-09-27 06:44:27 +02:00
frack113 dd1fed29a0 Add shell-core service 2022-09-27 06:36:01 +02:00
Yamato Security 048de3fc81 add diagnosis-scripted to windows services file 2022-09-27 10:43:38 +09:00
Florian Roth 9b091811dd Update proc_creation_win_uac_bypass_icmluautil.yml 2022-09-27 00:22:34 +02:00
Florian Roth f9322f342c Update proc_creation_win_susp_sharpview.yml 2022-09-27 00:22:10 +02:00
Florian Roth 224ea52dcd Update proc_creation_win_cmstp_com_object_access.yml 2022-09-27 00:21:33 +02:00