Commit Graph

2749 Commits

Author SHA1 Message Date
frack113 c5263039ae Merge pull request #2798 from frack113/moonbounce
Add proc_creation_win_wmic_remote_command
2022-03-13 22:22:10 +01:00
Florian Roth 70954c8153 Update proc_creation_win_wmic_remote_command.yml 2022-03-13 13:22:10 +01:00
frack113 06f51aecf5 Add proc_creation_win_wmic_remote_command 2022-03-13 12:21:00 +01:00
frack113 283246cdd0 Fix selection_tools 2022-03-12 11:15:10 +01:00
frack113 0bab1f19a9 Add proc_creation_win_network_scan_loop 2022-03-12 10:53:12 +01:00
Florian Roth 52f2b7f966 Merge pull request #2795 from SigmaHQ/rule-devel
refactor: lsass dump files names, new: NTDS.dit exfiltration activity
2022-03-11 20:56:06 +01:00
Florian Roth 1141f00480 fix: more lists with only one parameter 2022-03-11 20:11:06 +01:00
Florian Roth 1691f09099 fix: list with one item 2022-03-11 20:00:33 +01:00
Florian Roth c843293e47 rules: NTDS.DIT exfiltration 2022-03-11 18:14:09 +01:00
Florian Roth b96d30acc7 docs: adjustments 2022-03-11 18:13:54 +01:00
Florian Roth d033831e98 refactor: increased level of ntdsutil usage 2022-03-11 17:04:58 +01:00
Florian Roth eb2f620089 fix: FP with Suspicius Schtasks rule 2022-03-11 17:04:33 +01:00
phantinuss 587691cdc1 fix: FPs found in production environment 2022-03-09 16:22:33 +01:00
Florian Roth 187ce70e4e refactor: schtasks creation, based on parent proc 2022-03-09 08:49:23 +01:00
Florian Roth c2e6adda9d docs: changed UltraVNC flags rule < Gamaredon 2022-03-09 08:17:14 +01:00
frack113 d27a6b63a6 Merge pull request #2787 from frack113/refactor_regex
Refactor regex
2022-03-09 06:42:02 +01:00
frack113 c6d37d4a78 fix yaml 2022-03-08 19:14:46 +01:00
frack113 5938569d3e Refactor regex 2022-03-08 19:07:37 +01:00
Florian Roth cd2b9a36f0 Merge pull request #2762 from redsand/fp_windows_shell_spawn_suspicious_program
Adding false positive filters for tenable nessus and amazon workspace
2022-03-08 18:37:35 +01:00
Florian Roth 50615f807c fix: indentation 2022-03-08 17:47:20 +01:00
Florian Roth 2ef5930e66 Merge pull request #2786 from SigmaHQ/rule-devel
fix: unused filter
2022-03-08 09:48:45 +01:00
Florian Roth 5e360806fc filter adjustments 2022-03-08 09:48:32 +01:00
Florian Roth d872b5a329 Merge pull request #2785 from d4rk-d4nph3/master
Added HermeticWiper IoC for Suspicious Call by Ordinal
2022-03-08 09:46:33 +01:00
Florian Roth ffd4470079 Merge pull request #2784 from frack113/refactor_regex
Refactor regex
2022-03-08 09:46:19 +01:00
Florian Roth 91a7b5a304 Merge branch 'master' into pr/2785 2022-03-08 08:43:59 +01:00
Florian Roth f6d5c1645b fix: unused filter
https://github.com/SigmaHQ/sigma/commit/df48b60cb47e9ca868ae4e7703f227500b6ad5da#commitcomment-68196360
2022-03-08 08:41:53 +01:00
Bhabesh f8593638a8 Fixing name to HermeticWizard 2022-03-08 10:44:43 +05:45
Bhabesh 63dd632af9 Added HermeticWiper IoC for Suspicious Call by Ordinal 2022-03-08 10:42:37 +05:45
frack113 143f5fe4e2 Fix yml 2022-03-07 19:37:33 +01:00
frack113 f9c0e21323 Refactor regex 2022-03-07 19:08:30 +01:00
Florian Roth 9824a9c0d5 Merge branch 'master' into rule-devel 2022-03-07 18:30:21 +01:00
Florian Roth eebd0439e8 Merge pull request #2782 from phantinuss/master
Increase Rule status
2022-03-07 18:15:04 +01:00
Florian Roth 5befed1fac fix: adjusted rules that use utf16le, extended others 2022-03-07 18:14:29 +01:00
phantinuss 48922db480 chore: increase rule status 2022-03-07 17:11:00 +01:00
phantinuss b10892129b docs: known FP, but has to be checked if action was legitimately issued 2022-03-07 17:11:00 +01:00
phantinuss b986a99be1 fix: FPs 2022-03-07 17:11:00 +01:00
phantinuss 3925d0c6c6 chore: increase rule status 2022-03-07 17:10:59 +01:00
phantinuss a4adfe96bd chore: increase status to stable 2022-03-07 17:10:59 +01:00
Florian Roth c93fd80482 Merge branch 'master' into rule-devel 2022-03-07 15:38:58 +01:00
Florian Roth 0d083039ab refactor: new PPLDump imphashes 2022-03-07 15:38:53 +01:00
Florian Roth b71417e807 refactor: more exact imphash matching 2022-03-07 12:03:32 +01:00
frack113 5d4035ea05 Fix contains 2022-03-06 20:50:19 +01:00
frack113 4db5798dd0 fix error 2022-03-06 20:43:34 +01:00
frack113 67189b6e51 refactor regex 2022-03-06 20:40:21 +01:00
frack113 793bf99c85 refactor regex 2022-03-06 20:15:32 +01:00
Florian Roth 97744dc9eb Merge pull request #2777 from frack113/regex_clean
refactor: regex
2022-03-06 17:54:51 +01:00
Florian Roth 1b0c7cc3b9 Merge pull request #2776 from frack113/lolbas
Add lolbas rules
2022-03-06 17:54:18 +01:00
frack113 18bb388574 refactor: regex 2022-03-06 13:38:47 +01:00
frack113 d7b73be2c7 Add Missing CurrentDirectory filter 2022-03-06 13:22:30 +01:00
frack113 cb7a776623 Add lolbas rules 2022-03-06 12:10:51 +01:00