Commit Graph

15089 Commits

Author SHA1 Message Date
Florian Roth df60f30cc1 Update file_event_win_cred_dump_tools_dropped_files.yml 2022-09-27 00:21:09 +02:00
Florian Roth e6d7ba8224 Merge branch 'master' into aurora-false-positive-fixing 2022-09-27 00:20:07 +02:00
Florian Roth 0503e2b8f7 fix: FPs on Azure 2022-09-27 00:17:53 +02:00
Florian Roth e1375467c5 fix: FPs with Azure hosts 2022-09-26 23:52:48 +02:00
frack113 9b0189b5f7 Add redcannary rules 2022-09-25 16:14:21 +02:00
frack113 fb84ee92bb Merge pull request #3504 from YamatoSecurity/update-app-uninstalled-rule
update application uninstalled rule
2022-09-23 07:24:30 +02:00
frack113 ac9b12b6bb Update win_builtin_remove_application.yml 2022-09-23 07:14:31 +02:00
frack113 ffcbe934ba Merge pull request #3515 from hazedav/network_connection
feat(backend): add support for linux.network_connection
2022-09-23 07:05:27 +02:00
frack113 3738d3a755 Merge pull request #3521 from rachelrice/fix_filename
fix: Rename Linux process creation rule to use established pattern
2022-09-23 07:00:38 +02:00
Yamato Security 6497cb7745 Keep at level: low 2022-09-23 03:37:00 +09:00
Rachel Rice 24e87d0f34 fix: Rename Linux process creation rule to use established pattern
One rule had filename beginning 'prox' rather than 'proc'.

Signed-off-by: Rachel Rice <rachel.rice@lacework.net>
2022-09-22 17:42:54 +01:00
frack113 ca200d9d75 Merge pull request #3509 from amjcyber/patch-2
Update win_impacket_psexec.yml
2022-09-22 17:49:02 +02:00
frack113 6c70c6d35a Update win_impacket_psexec.yml 2022-09-22 17:42:27 +02:00
frack113 a55749f27d Merge pull request #3516 from veramine/patch-1
Update proc_creation_win_commandline_path_traversal_evasion.yml
2022-09-21 18:20:23 +02:00
Florian Roth eeca6a898b fix: mitre attack tags 2022-09-21 18:16:02 +02:00
Florian Roth 2ffca9c8da fix: condition 2022-09-21 18:08:24 +02:00
Florian Roth 1699009393 Merge pull request #3518 from phantinuss/master
New evtx baseline and FP tuning
2022-09-21 18:07:23 +02:00
Florian Roth 026844026f fix: condition in sharpersist rule 2022-09-21 18:04:18 +02:00
Florian Roth 61a4a48ac0 fix: CommandLine field types 2022-09-21 18:02:42 +02:00
Florian Roth 8e011540b0 rule: createdump renamed 2022-09-21 16:30:47 +02:00
phantinuss cc5cda0a22 fix: needs to be contains now 2022-09-21 14:10:50 +02:00
phantinuss f940a43d8f workflow: use correct rule title 2022-09-21 13:51:20 +02:00
phantinuss 54add15167 workflow: fix wrong filename 2022-09-21 13:51:20 +02:00
phantinuss b7f20b884c fix: FPs from new evtx-baseline 2022-09-21 13:51:19 +02:00
phantinuss 40e0dfcb29 chore: add new known FPs 2022-09-21 13:45:28 +02:00
phantinuss e5e5cdd3b3 workflow: update evtx-baseline to v0.7 and add a new test for the data 2022-09-21 13:45:28 +02:00
phantinuss 4f6d4b7c80 fix: FP in testing environment 2022-09-21 13:45:26 +02:00
phantinuss ee850aaf2c Merge pull request #3517 from nasbench/fix-false-positives
Fix more FP in testing
2022-09-21 13:44:56 +02:00
Nasreddine Bencherchali 4a74129048 Fix after review 2022-09-21 13:12:21 +02:00
Nasreddine Bencherchali 7dd2af08e7 Update net_connection_win_python.yml 2022-09-21 12:16:15 +02:00
Nasreddine Bencherchali d9cd98838f Add descriptions 2022-09-21 12:02:15 +02:00
Nasreddine Bencherchali a0c3449079 Fix typo 2022-09-21 11:59:12 +02:00
Nasreddine Bencherchali e987fa6acb Update file_delete_win_sysinternals_sdelete_file_deletion.yml 2022-09-21 11:57:10 +02:00
Nasreddine Bencherchali e4e2177533 Update file_delete_win_sysinternals_sdelete_file_deletion.yml 2022-09-21 11:56:58 +02:00
Nasreddine Bencherchali 59530f49d4 Fix more FP in testing 2022-09-21 11:53:39 +02:00
Veramine 5fbebce703 Update proc_creation_win_commandline_path_traversal_evasion.yml
Removed extra space after the hyphen
2022-09-20 21:45:45 -07:00
Veramine 411d79017e Update proc_creation_win_commandline_path_traversal_evasion.yml
Changed to simpler CommandLine|contains and updated modified date.
2022-09-20 21:33:16 -07:00
frack113 90937933dd Merge pull request #3512 from phantinuss/master
fix: FP found in testing environment
2022-09-21 06:25:33 +02:00
frack113 d8dcddea25 Merge pull request #3513 from gs3cl/gsec-mod
new rule for the winpeas tool
2022-09-21 06:20:28 +02:00
Veramine fda2ca4308 Update proc_creation_win_commandline_path_traversal_evasion.yml
Fix FP with Citrix launcher
2022-09-20 17:20:19 -07:00
David Hazekamp ad6ddf5896 feat(backend): add support for linux.network_connection
Also remove evaluatorId
2022-09-20 13:47:17 -05:00
Florian Roth 83fbd7f258 Update proc_creation_win_winpeas_tool.yml 2022-09-20 17:45:13 +02:00
Florian Roth cb09f9d522 Update proc_creation_win_winpeas_tool.yml 2022-09-20 17:44:56 +02:00
Florian Roth 43b62bf79f Merge pull request #3514 from nasbench/fix-false-positives
Fix False-Positives In Testing
2022-09-20 11:45:22 +02:00
Nasreddine Bencherchali 2f7a54cc31 Fix FP 2022-09-20 11:20:33 +02:00
gs3cl 137653f08a fix format and delete 'OriginalFileName' 2022-09-20 11:04:12 +02:00
frack113 655b83e8fe Merge pull request #3503 from frack113/sensitive
Add posh_ps_sensitive_file_discovery
2022-09-20 06:55:27 +02:00
gs3cl 9e589736c2 Update proc_creation_win_winpeas_tool.yml 2022-09-19 23:23:28 +02:00
gs3cl 9bfd2c729f change condition and format 2022-09-19 23:00:02 +02:00
gs3cl 86a4f24ce8 del "domain" under CommandLine 2022-09-19 22:36:18 +02:00