Commit Graph

15089 Commits

Author SHA1 Message Date
Paul Hager a428756340 new rule: susp net use combo 2022-09-01 14:38:06 +02:00
David André ae8cfb1ec0 Merge branch 'SigmaHQ:master' into master 2022-09-01 13:04:11 +02:00
David ANDRE a0a30bad8c Correcting values for startswith 2022-09-01 13:03:19 +02:00
Florian Roth 3ada2ad393 Merge pull request #3453 from redsand/fp_cmd_with_no_ending
False positive when commandline is only cmd.exe /c
2022-08-31 23:08:29 +02:00
Tim Shelton 1bb172e4ae False positive when commandline is only cmd.exe /c 2022-08-31 19:38:25 +00:00
Florian Roth 5a4b3d6b71 Update file_rename_win_ransomware.yml 2022-08-31 16:08:12 +02:00
Florian Roth 6e1c647019 Merge branch 'master' into aurora-false-positive-fixing 2022-08-31 13:55:52 +02:00
Florian Roth 65c6f82169 Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing 2022-08-31 13:55:46 +02:00
Florian Roth 893fc6c15d fix: FP with controller config 2022-08-31 13:55:43 +02:00
Nasreddine Bencherchali b0bd1a2184 Update win_msi_install_from_susp_locations.yml 2022-08-31 13:55:30 +02:00
Nasreddine Bencherchali 7b92cbb6d0 Create win_msi_install_from_susp_locations.yml 2022-08-31 13:54:50 +02:00
Nasreddine Bencherchali 35f102f8a0 Update known-FPs.csv 2022-08-31 11:40:39 +02:00
Nasreddine Bencherchali 475bb1a90b Update known-FPs.csv 2022-08-31 11:12:18 +02:00
Nasreddine Bencherchali b0768ed5cd Update known-FPs.csv 2022-08-31 11:05:41 +02:00
Nasreddine Bencherchali b7fe798a8d Update known-FPs.csv 2022-08-31 10:24:04 +02:00
Nasreddine Bencherchali 783fd8b160 Create proc_creation_win_susp_schtasks_schedule_type.yml 2022-08-31 10:08:31 +02:00
FabFaeb df2ef5a2ee added missing newline 2022-08-31 09:59:29 +02:00
FabFaeb 3a020ce499 added "failed admin share mount" rule 2022-08-31 09:57:09 +02:00
Nasreddine Bencherchali 80098113d0 Update image_load_susp_cmstp.yml 2022-08-31 09:53:07 +02:00
Florian Roth 05d60e39c4 Merge pull request #3449 from bornatalebi/master
Adding Google Chrome FP
2022-08-31 09:47:50 +02:00
Nasreddine Bencherchali 343b0ef199 Update net_connection_win_susp_cmstp.yml 2022-08-31 09:46:18 +02:00
Nasreddine Bencherchali 77c5640839 Update net_connection_win_susp_cmstp.yml 2022-08-31 09:42:25 +02:00
Nasreddine Bencherchali 399a18b762 Update net_connection_win_susp_cmstp.yml 2022-08-31 09:41:25 +02:00
Nasreddine Bencherchali ea183cae13 Updates+New Rules 2022-08-31 09:39:16 +02:00
Borna Talebi 8dfe06a33b Adding Google Chrome FP 2022-08-31 11:35:12 +04:30
Florian Roth aa0545b6c7 refactor: added extension to ransomware rule 2022-08-31 08:40:24 +02:00
Florian Roth f62d53e670 Merge pull request #3448 from SigmaHQ/rule-devel
rules: wmic extended, defendercheck, sharpldapwhoami
2022-08-30 11:38:45 +02:00
Florian Roth 35d9e5f36a fix: syntax error, docs: change fp text 2022-08-30 11:29:11 +02:00
Florian Roth b5c57e97fc Merge branch 'master' into rule-devel 2022-08-30 09:14:37 +02:00
Florian Roth 52c5851ef6 rules: wmic extended, defendercheck, sharpldapwhoami 2022-08-30 09:13:25 +02:00
frack113 da72e3b7c0 Merge pull request #3441 from ionsor/patch-6
Update net_connection_win_dead_drop_resolvers.yml
2022-08-30 08:38:17 +02:00
frack113 f9b79161a5 Merge pull request #3444 from danielgottt/patch-7
Create proc_creation_win_deviceenroller_evasion.yml
2022-08-30 08:24:24 +02:00
frack113 45a87dd22d Update net_connection_win_dead_drop_resolvers.yml 2022-08-30 08:22:10 +02:00
Wagga 4573ab0a21 Fix a lot of typos in rules text and comments #Part 3 (#3446) 2022-08-30 08:21:25 +02:00
Gott 8809fc6a8e Update proc_creation_win_deviceenroller_evasion.yml
Made corrections frack presented
2022-08-29 15:23:17 -04:00
Florian Roth 36eadcae87 Merge pull request #3442 from phantinuss/master
fix: FP found in testing environment
2022-08-29 20:37:35 +02:00
Florian Roth d9a5265ce7 Merge pull request #3445 from wagga40/master
Fix a lot of typos in rules text and comments
2022-08-29 20:37:14 +02:00
Wagga 9db9d25b68 Update file_event_win_susp_winword_startup.yml 2022-08-29 20:16:41 +02:00
Wagga 6c42bfb64b Update file_event_win_powershell_startup_shortcuts.yml 2022-08-29 20:15:54 +02:00
Wagga 8dbeedf728 Update file_event_win_powershell_startup_shortcuts.yml 2022-08-29 20:14:47 +02:00
Wagga 691aae2638 Update proc_creation_win_ntfs_short_name_path_use_image.yml 2022-08-29 20:13:14 +02:00
Wagga a693e181ff Update registry_set_disable_uac_registry.yml 2022-08-29 20:12:10 +02:00
Wagga 277032b460 Update registry_set_mpnotify_persistence.yml 2022-08-29 20:11:29 +02:00
Wagga 63ea4d7fb6 Update registry_set_fax_dll_persistance.yml 2022-08-29 20:10:25 +02:00
Wagga cb4f834845 Update posh_ps_nishang_malicious_commandlets.yml
Typo in detection : https://github.com/samratashok/nishang/blob/master/Utility/Add-Persistence.ps1
2022-08-29 18:53:22 +02:00
Wagga 8a9d63bba1 Update proc_creation_win_wmic_remote_service.yml 2022-08-29 18:50:04 +02:00
Wagga 86b448b715 Update proc_creation_win_lolbin_register_app.yml 2022-08-29 18:49:17 +02:00
Wagga 351d8bcc40 Update proc_creation_win_wmic_unquoted_service_search.yml 2022-08-29 18:48:29 +02:00
Wagga 7c0bd62e9f Update proc_creation_win_cmd_redirection_susp_folder.yml 2022-08-29 18:47:44 +02:00
Wagga 6494e185cf Update image_load_vmware_xfer_load_dll_from_nondefault_path.yml 2022-08-29 18:46:34 +02:00