Tim Rauch
|
be1f1a4505
|
New Rules: transformed elastic to sigma rules
|
2022-09-28 16:45:22 +02:00 |
|
mpgn
|
652447696b
|
Update datadog sigmac
|
2022-09-28 08:30:03 -04:00 |
|
Nasreddine Bencherchali
|
4a5dcf8586
|
Update rules/windows/process_creation/proc_creation_win_susp_7zip_dmp.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:42 +02:00 |
|
Nasreddine Bencherchali
|
69b31b19b1
|
Update rules/windows/process_creation/proc_creation_win_renamed_rurat.yml
Co-authored-by: Florian Roth <venom14@gmail.com>
|
2022-09-28 13:37:36 +02:00 |
|
Florian Roth
|
5391a5cab4
|
changed casing, increased level
|
2022-09-28 13:28:53 +02:00 |
|
Florian Roth
|
5ee44a6992
|
increased level
|
2022-09-28 13:27:23 +02:00 |
|
Florian Roth
|
ea25382110
|
increased level
|
2022-09-28 13:26:23 +02:00 |
|
Nasreddine Bencherchali
|
b71644d0c8
|
New rules + small mitre update
|
2022-09-28 11:52:07 +02:00 |
|
Dieter Schmitz
|
db4edb0aab
|
Revert "Pushed first version of daily task (main.yaml)"
This reverts commit 1b0fbd89be.
|
2022-09-28 11:40:48 +02:00 |
|
Dieter Schmitz
|
1b0fbd89be
|
Pushed first version of daily task (main.yaml)
Will create all uberAgent ESA files
|
2022-09-28 11:28:33 +02:00 |
|
Nasreddine Bencherchali
|
df6c167b17
|
New Rules
|
2022-09-28 10:48:51 +02:00 |
|
Nasreddine Bencherchali
|
e3b3265240
|
Update image_load_side_load_from_non_system_location.yml
|
2022-09-28 10:48:30 +02:00 |
|
frack113
|
a9dd6f7ff0
|
Add registry_set_change_winevt_channelaccess (#3505)
|
2022-09-28 09:53:46 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
d262ea2df8
|
New rules
|
2022-09-28 09:51:13 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
e987c669d0
|
Updates
|
2022-09-28 09:50:56 +02:00 |
|
frack113
|
ec6d237cd0
|
Merge pull request #3522 from frack113/redcannary_20220925
Add redcannary rules
|
2022-09-28 08:45:06 +02:00 |
|
Florian Roth
|
e583d9fc39
|
Update proc_creation_win_w32tm.yml
|
2022-09-27 23:52:22 +02:00 |
|
Florian Roth
|
58b7c910dc
|
Update proc_creation_win_w32tm.yml
|
2022-09-27 23:50:35 +02:00 |
|
Florian Roth
|
46ef664ec6
|
Merge pull request #3530 from securepeacock/patch-28
Update proc_creation_win_susp_psexesvc_as_system.yml
|
2022-09-27 23:47:45 +02:00 |
|
Florian Roth
|
dd115ca74c
|
Merge pull request #3533 from YamatoSecurity/define-security-mitigations-service
define security-mitigations service
|
2022-09-27 23:47:26 +02:00 |
|
Yamato Security
|
e44e01e106
|
update modified tag
|
2022-09-28 06:32:34 +09:00 |
|
Yamato Security
|
979502921f
|
define security-mitigations service
|
2022-09-28 06:23:50 +09:00 |
|
unknown
|
a0275ab124
|
New pipename criteria from redcanary
|
2022-09-27 15:37:14 -04:00 |
|
securepeacock
|
e90c91668d
|
Update proc_creation_win_susp_psexesvc_as_system.yml
Typo Fixed
|
2022-09-27 13:45:53 -04:00 |
|
frack113
|
f220b72b0a
|
Merge pull request #3528 from qasimqlf/master
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 19:32:27 +02:00 |
|
Qasim Qlf
|
ec657a3118
|
Merge branch 'master' into master
|
2022-09-27 16:26:22 +05:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
43d12249a0
|
Renamed create remote thread rules
|
2022-09-27 12:13:16 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
27d08a2eb9
|
Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel
|
2022-09-27 12:09:37 +02:00 |
|
Florian Roth
|
e2aacfea35
|
Merge pull request #3519 from SigmaHQ/rule-devel
Rule devel
|
2022-09-27 12:05:22 +02:00 |
|
Florian Roth
|
be265d06ed
|
fix: casing of field
|
2022-09-27 11:51:48 +02:00 |
|
Florian Roth
|
556441f4d8
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-09-27 11:51:30 +02:00 |
|
Florian Roth
|
6eeee7eff4
|
fix: casing of field
|
2022-09-27 11:51:27 +02:00 |
|
Florian Roth
|
be9fb6a6bd
|
Merge pull request #3523 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-09-27 11:10:11 +02:00 |
|
Florian Roth
|
d2f7ff8059
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-09-27 10:47:21 +02:00 |
|
Florian Roth
|
5e6a926ac3
|
fix: FPs
|
2022-09-27 10:47:19 +02:00 |
|
Florian Roth
|
e46d19e450
|
fix: condition
|
2022-09-27 10:30:34 +02:00 |
|
Florian Roth
|
43d9f3a13b
|
Merge branch 'master' into rule-devel
|
2022-09-27 10:29:03 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
a66ba61712
|
Fix small typos
|
2022-09-27 10:27:21 +02:00 |
|
Florian Roth
|
8f617f4645
|
Merge pull request #3527 from qasimqlf/patch-7
Fix the filter
|
2022-09-27 10:24:33 +02:00 |
|
Qasim Qlf
|
de517ba8a2
|
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 13:21:48 +05:00 |
|
Qasim Qlf
|
600494adbc
|
Fix the filter
|
2022-09-27 13:11:08 +05:00 |
|
Sven Scharmentke
|
5d9edbbb28
|
Merge remote-tracking branch 'origin/master' into feature/ame-6.3
|
2022-09-27 09:48:24 +02:00 |
|
Florian Roth
|
408bf97181
|
Update proc_creation_win_susp_renamed_createdump.yml
|
2022-09-27 09:12:44 +02:00 |
|
Florian Roth
|
b53f08b081
|
Update proc_creation_win_process_dump_rundll32_comsvcs.yml
|
2022-09-27 09:12:06 +02:00 |
|
frack113
|
9bb830d2fc
|
Merge pull request #3524 from YamatoSecurity/add-diagnosis-scripted-to-windows-services-file
add diagnosis-scripted to windows services file
|
2022-09-27 06:44:27 +02:00 |
|
frack113
|
dd1fed29a0
|
Add shell-core service
|
2022-09-27 06:36:01 +02:00 |
|
Yamato Security
|
048de3fc81
|
add diagnosis-scripted to windows services file
|
2022-09-27 10:43:38 +09:00 |
|
Florian Roth
|
9b091811dd
|
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 00:22:34 +02:00 |
|
Florian Roth
|
f9322f342c
|
Update proc_creation_win_susp_sharpview.yml
|
2022-09-27 00:22:10 +02:00 |
|
Florian Roth
|
224ea52dcd
|
Update proc_creation_win_cmstp_com_object_access.yml
|
2022-09-27 00:21:33 +02:00 |
|