Commit Graph

1852 Commits

Author SHA1 Message Date
Florian Roth 62c9468180 Merge pull request #1832 from SigmaHQ/rule-devel
Whoami Refactoring
2021-08-12 14:28:28 +02:00
Florian Roth d9d543e545 refactor: removed OriginalFileName from rule to improve compatibilty 2021-08-12 13:28:24 +02:00
Florian Roth 34d70de084 rule: whoami anomalies 2021-08-12 13:28:00 +02:00
Florian Roth bd0a2a1b9f rule: renamed whoami 2021-08-12 13:27:51 +02:00
Florian Roth 418a0bbf7e Merge pull request #1827 from phantinuss/master
2 new rules (Little Corporal Maldoc and keyword generic version of "ProxyShell MSExchange MailBox Export Pattern")
2021-08-12 11:41:50 +02:00
Florian Roth 6ed62b431e Merge pull request #1830 from SigmaHQ/rule-devel
SystemNightmare and Typo
2021-08-12 11:41:16 +02:00
Florian Roth 08883c8e32 refactor: removed old rule that uses Message field
Rules that use the "Message" field are prone to localisation issues and should be avoided whenever possible.

We can build what we call "keyword" rules in these cases and simply combine string values that are searched in the raw data as 1 of them or all of them. (see specs for details)
2021-08-12 09:27:50 +02:00
Florian Roth c8d481fd83 Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-08-11 10:10:32 +02:00
Florian Roth c1f9c33730 rule: SystemNightmare 2021-08-11 10:10:30 +02:00
Florian Roth d9d1e2c578 Merge pull request #1823 from SigmaHQ/rule-devel
rule: ProxyLogon rule for MS Exchange
2021-08-11 09:43:41 +02:00
frack113 63ead346e8 fix modified value 2021-08-10 19:09:34 +02:00
Florian Roth 73a4bd74dc fix: FPs script exec from temp 2021-08-10 17:10:46 +02:00
frack113 6d869feb43 update modified 2021-08-10 15:12:45 +02:00
Jon Galarneau 1544a351a3 Correcting regex in win_modif_of_services_for_via_commandline.yml
The ^ symbol designates the beginning of the string, but in this rule it is clearly intended to be the end of the string.
2021-08-10 08:29:39 -04:00
Florian Roth 17c6fc7038 rule: ProxyLogon rule for MS Exchange 2021-08-10 09:16:30 +02:00
Florian Roth 17fb418271 Merge pull request #1817 from SigmaHQ/rule-devel
rules: ProxyShell refactoring and new rule
2021-08-10 08:18:32 +02:00
Florian Roth dbf8aecd83 fix: typo in cmdlet name 2021-08-09 18:05:51 +02:00
Florian Roth a9ad4eda4a rules: ProxyShell refactoring and new rule 2021-08-09 17:57:34 +02:00
frack113 dd2aa8706d Merge pull request #1786 from j91321/anydesk
Silent installation of AnyDesk (Conti)
2021-08-09 08:57:32 +02:00
frack113 bacb44ab97 Merge pull request #1780 from Sam0x90/master
Adding detection rule for esentutl utility
2021-08-07 16:23:45 +02:00
frack113 f75f8fabab fix file name 2021-08-07 15:54:43 +02:00
frack113 07d21c58e8 Update process_susp_esentutl_params.yaml 2021-08-07 15:49:25 +02:00
frack113 89ee63f63b Merge pull request #1791 from SigmaHQ/rule-devel
More rules - including the ones for ProxyShell
2021-08-07 11:49:16 +02:00
Florian Roth 88a721a1ab docs: add space in title 2021-08-07 10:13:05 +02:00
Florian Roth 1dcf25878c Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-08-07 10:10:48 +02:00
Florian Roth 0a8904a61e fix: issues with new rule 2021-08-07 10:10:12 +02:00
frack113 5f89a29ea7 fix file name 2021-08-07 10:01:23 +02:00
Florian Roth 1ac49a2055 rule: ProxyShell patterns 2021-08-07 09:22:24 +02:00
Florian Roth c0360cd1ca change name and line breaks 2021-08-06 18:53:08 +02:00
Florian Roth 7de55075f7 fix: condition 2021-08-06 18:45:38 +02:00
Florian Roth d69e2333c8 various fixes 2021-08-06 18:44:54 +02:00
Florian Roth e02b85dc99 '--start-with-win' is pretty specific 2021-08-06 18:41:14 +02:00
Ján Trenčanský 2f3b48c347 Fix title 2021-08-06 14:18:30 +02:00
Ján Trenčanský 516e1ade6d Silent installation of AnyDesk 2021-08-06 14:06:35 +02:00
Sam0x90 96911e55b9 Adding detection rule for esentutl utility
Used by Conti affiliates to target NTDS file and MSEdge info
2021-08-06 00:55:57 +04:00
Florian Roth eb247704fe Merge pull request #1761 from d4rk-d4nph3/master
Added rule for Cabinet file expansion and Pypykatz
2021-08-05 15:50:12 +02:00
Florian Roth c44b22b52f Merge pull request #1762 from frack113/redcanary_collection
[OSCD] Redcanary TA0009 collection
2021-08-05 15:49:10 +02:00
Florian Roth a04aa6ac49 rule: ADCSPwn 2021-07-31 10:18:21 +02:00
frack113 f9aff7d403 fix product sysmon_apt_sourgrum.yml 2021-07-30 16:02:38 +02:00
Bhabesh Rai 9131ed6db5 Added rule for Cabinet file expansion 2021-07-30 12:36:05 +05:45
frack113 ccaffc79f7 update ref win_susp_psr_capture_screenshots.yml 2021-07-30 08:40:21 +02:00
frack113 dfa28944d0 update ref in sysmon_creation_mavinject_dll.yml 2021-07-30 08:31:37 +02:00
frack113 eff6b50a89 add process_creation_susp_recon.yml 2021-07-30 08:15:13 +02:00
Florian Roth ec9c15226f SeriousSAM PowerShell rule 2021-07-29 18:12:10 +02:00
Florian Roth 77c8225db3 Merge pull request #1745 from frack113/redcanary_t1115
[OSCD]  process_creation_clip.yml t1115
2021-07-28 16:24:15 +02:00
Florian Roth c3eced4ae7 Merge pull request #1748 from frack113/update_win_susp_rar_flags.yml
update win_susp_rar_flags.yml
2021-07-28 16:23:14 +02:00
Florian Roth dc4380d459 Merge pull request #1750 from frack113/redcanary_t1560.001_winzip
[OSCD] Redcanary t1560.001 winzip
2021-07-28 16:22:48 +02:00
Florian Roth 321a15d004 Merge pull request #1751 from frack113/redcanary_t1560.001_7zip
[OSCD] Redcanary t1560.001 7z
2021-07-28 16:22:31 +02:00
Florian Roth 6d5e695cd1 Merge pull request #1753 from frack113/redcanary_t1119
Redcanary t1119
2021-07-28 16:21:40 +02:00
frack113 8a885dd098 add process_creation_automated_collection.yml 2021-07-28 13:17:40 +02:00