Florian Roth
|
dd115ca74c
|
Merge pull request #3533 from YamatoSecurity/define-security-mitigations-service
define security-mitigations service
|
2022-09-27 23:47:26 +02:00 |
|
Yamato Security
|
e44e01e106
|
update modified tag
|
2022-09-28 06:32:34 +09:00 |
|
Yamato Security
|
979502921f
|
define security-mitigations service
|
2022-09-28 06:23:50 +09:00 |
|
frack113
|
f220b72b0a
|
Merge pull request #3528 from qasimqlf/master
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 19:32:27 +02:00 |
|
Qasim Qlf
|
ec657a3118
|
Merge branch 'master' into master
|
2022-09-27 16:26:22 +05:00 |
|
Florian Roth
|
e2aacfea35
|
Merge pull request #3519 from SigmaHQ/rule-devel
Rule devel
|
2022-09-27 12:05:22 +02:00 |
|
Florian Roth
|
be265d06ed
|
fix: casing of field
|
2022-09-27 11:51:48 +02:00 |
|
Florian Roth
|
be9fb6a6bd
|
Merge pull request #3523 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-09-27 11:10:11 +02:00 |
|
Florian Roth
|
d2f7ff8059
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-09-27 10:47:21 +02:00 |
|
Florian Roth
|
5e6a926ac3
|
fix: FPs
|
2022-09-27 10:47:19 +02:00 |
|
Florian Roth
|
e46d19e450
|
fix: condition
|
2022-09-27 10:30:34 +02:00 |
|
Florian Roth
|
43d9f3a13b
|
Merge branch 'master' into rule-devel
|
2022-09-27 10:29:03 +02:00 |
|
Florian Roth
|
8f617f4645
|
Merge pull request #3527 from qasimqlf/patch-7
Fix the filter
|
2022-09-27 10:24:33 +02:00 |
|
Qasim Qlf
|
de517ba8a2
|
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 13:21:48 +05:00 |
|
Qasim Qlf
|
600494adbc
|
Fix the filter
|
2022-09-27 13:11:08 +05:00 |
|
Florian Roth
|
408bf97181
|
Update proc_creation_win_susp_renamed_createdump.yml
|
2022-09-27 09:12:44 +02:00 |
|
Florian Roth
|
b53f08b081
|
Update proc_creation_win_process_dump_rundll32_comsvcs.yml
|
2022-09-27 09:12:06 +02:00 |
|
frack113
|
9bb830d2fc
|
Merge pull request #3524 from YamatoSecurity/add-diagnosis-scripted-to-windows-services-file
add diagnosis-scripted to windows services file
|
2022-09-27 06:44:27 +02:00 |
|
frack113
|
dd1fed29a0
|
Add shell-core service
|
2022-09-27 06:36:01 +02:00 |
|
Yamato Security
|
048de3fc81
|
add diagnosis-scripted to windows services file
|
2022-09-27 10:43:38 +09:00 |
|
Florian Roth
|
9b091811dd
|
Update proc_creation_win_uac_bypass_icmluautil.yml
|
2022-09-27 00:22:34 +02:00 |
|
Florian Roth
|
f9322f342c
|
Update proc_creation_win_susp_sharpview.yml
|
2022-09-27 00:22:10 +02:00 |
|
Florian Roth
|
224ea52dcd
|
Update proc_creation_win_cmstp_com_object_access.yml
|
2022-09-27 00:21:33 +02:00 |
|
Florian Roth
|
df60f30cc1
|
Update file_event_win_cred_dump_tools_dropped_files.yml
|
2022-09-27 00:21:09 +02:00 |
|
Florian Roth
|
e6d7ba8224
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-09-27 00:20:07 +02:00 |
|
Florian Roth
|
0503e2b8f7
|
fix: FPs on Azure
|
2022-09-27 00:17:53 +02:00 |
|
Florian Roth
|
e1375467c5
|
fix: FPs with Azure hosts
|
2022-09-26 23:52:48 +02:00 |
|
frack113
|
fb84ee92bb
|
Merge pull request #3504 from YamatoSecurity/update-app-uninstalled-rule
update application uninstalled rule
|
2022-09-23 07:24:30 +02:00 |
|
frack113
|
ac9b12b6bb
|
Update win_builtin_remove_application.yml
|
2022-09-23 07:14:31 +02:00 |
|
frack113
|
ffcbe934ba
|
Merge pull request #3515 from hazedav/network_connection
feat(backend): add support for linux.network_connection
|
2022-09-23 07:05:27 +02:00 |
|
frack113
|
3738d3a755
|
Merge pull request #3521 from rachelrice/fix_filename
fix: Rename Linux process creation rule to use established pattern
|
2022-09-23 07:00:38 +02:00 |
|
Yamato Security
|
6497cb7745
|
Keep at level: low
|
2022-09-23 03:37:00 +09:00 |
|
Rachel Rice
|
24e87d0f34
|
fix: Rename Linux process creation rule to use established pattern
One rule had filename beginning 'prox' rather than 'proc'.
Signed-off-by: Rachel Rice <rachel.rice@lacework.net>
|
2022-09-22 17:42:54 +01:00 |
|
frack113
|
ca200d9d75
|
Merge pull request #3509 from amjcyber/patch-2
Update win_impacket_psexec.yml
|
2022-09-22 17:49:02 +02:00 |
|
frack113
|
6c70c6d35a
|
Update win_impacket_psexec.yml
|
2022-09-22 17:42:27 +02:00 |
|
frack113
|
a55749f27d
|
Merge pull request #3516 from veramine/patch-1
Update proc_creation_win_commandline_path_traversal_evasion.yml
|
2022-09-21 18:20:23 +02:00 |
|
Florian Roth
|
eeca6a898b
|
fix: mitre attack tags
|
2022-09-21 18:16:02 +02:00 |
|
Florian Roth
|
2ffca9c8da
|
fix: condition
|
2022-09-21 18:08:24 +02:00 |
|
Florian Roth
|
1699009393
|
Merge pull request #3518 from phantinuss/master
New evtx baseline and FP tuning
|
2022-09-21 18:07:23 +02:00 |
|
Florian Roth
|
026844026f
|
fix: condition in sharpersist rule
|
2022-09-21 18:04:18 +02:00 |
|
Florian Roth
|
61a4a48ac0
|
fix: CommandLine field types
|
2022-09-21 18:02:42 +02:00 |
|
Florian Roth
|
8e011540b0
|
rule: createdump renamed
|
2022-09-21 16:30:47 +02:00 |
|
phantinuss
|
cc5cda0a22
|
fix: needs to be contains now
|
2022-09-21 14:10:50 +02:00 |
|
phantinuss
|
f940a43d8f
|
workflow: use correct rule title
|
2022-09-21 13:51:20 +02:00 |
|
phantinuss
|
54add15167
|
workflow: fix wrong filename
|
2022-09-21 13:51:20 +02:00 |
|
phantinuss
|
b7f20b884c
|
fix: FPs from new evtx-baseline
|
2022-09-21 13:51:19 +02:00 |
|
phantinuss
|
40e0dfcb29
|
chore: add new known FPs
|
2022-09-21 13:45:28 +02:00 |
|
phantinuss
|
e5e5cdd3b3
|
workflow: update evtx-baseline to v0.7 and add a new test for the data
|
2022-09-21 13:45:28 +02:00 |
|
phantinuss
|
4f6d4b7c80
|
fix: FP in testing environment
|
2022-09-21 13:45:26 +02:00 |
|
phantinuss
|
ee850aaf2c
|
Merge pull request #3517 from nasbench/fix-false-positives
Fix more FP in testing
|
2022-09-21 13:44:56 +02:00 |
|