Commit Graph

3685 Commits

Author SHA1 Message Date
Florian Roth eeca6a898b fix: mitre attack tags 2022-09-21 18:16:02 +02:00
Florian Roth 2ffca9c8da fix: condition 2022-09-21 18:08:24 +02:00
Florian Roth 026844026f fix: condition in sharpersist rule 2022-09-21 18:04:18 +02:00
Florian Roth 61a4a48ac0 fix: CommandLine field types 2022-09-21 18:02:42 +02:00
Florian Roth 8e011540b0 rule: createdump renamed 2022-09-21 16:30:47 +02:00
Florian Roth 2fe25f3c80 rule: sharpersist usage 2022-09-15 16:50:34 +02:00
Florian Roth 22d0e22d14 rule: 3proxy usage, fix: rule - missing contains 2022-09-14 10:22:01 +02:00
Florian Roth 37aed9ac3b docs: add link 2022-09-13 13:38:32 +02:00
Florian Roth 3a38b63fff refactor: chisel rules 2022-09-13 13:38:10 +02:00
Florian Roth 2d7e545cad fix: list with one element 2022-09-13 08:38:57 +02:00
Florian Roth c22974205f Merge branch 'master' into rule-devel 2022-09-13 08:07:35 +02:00
Florian Roth 61422ca237 rule: UAC Bypass via ICMLuaUtil 2022-09-13 08:07:15 +02:00
Florian Roth 072a9d73eb fix: changes to existing rules 2022-09-13 08:07:03 +02:00
Qasim Qlf 1eaad811b6 tag added 2022-09-12 14:15:48 +05:00
David André 93da67b593 Update proc_creation_win_renamed_vmnat.yml
Added accidentaly removed falsepositives
2022-09-11 13:13:58 +02:00
David André 5656a3a50b Merge branch 'SigmaHQ:master' into add_renamed_vmnat 2022-09-11 13:06:21 +02:00
David ANDRE d73aac41d3 Changes based on advice 2022-09-11 12:44:54 +02:00
frack113 21435629a0 Merge pull request #3482 from nasbench/nasbench-rule-devel
Rule Devel (New+Update)
2022-09-10 12:34:26 +02:00
Florian Roth e7084eee04 Merge pull request #3487 from SigmaHQ/aurora-false-positive-fixing
fix: fixing multiple FPs with the use of VSCode
2022-09-10 12:07:01 +02:00
Florian Roth 0a5cfb93b3 fix: condition 2022-09-10 11:53:42 +02:00
Florian Roth 7dbdd4d1c6 fix: fixing multiple FPs with the use of VSCode 2022-09-10 11:42:44 +02:00
Florian Roth a053be791c Update proc_creation_win_user_discovery_get_aduser.yml 2022-09-10 09:49:14 +02:00
Florian Roth a616647b08 lowered score of scheduled task + SYSTEM rule 2022-09-10 09:48:50 +02:00
Nasreddine Bencherchali 2552b75e72 Delete proc_creation_win_net_add_local_user.yml 2022-09-09 23:11:28 +02:00
David ANDRE 6182b43279 Add rule for renamed vmnat.exe 2022-09-09 16:40:17 +02:00
nasreddine.bencherchali@nextron-systems.com 14db9c9fb1 Update proc_creation_win_wmic_computersystem_recon.yml 2022-09-09 15:43:07 +02:00
nasreddine.bencherchali@nextron-systems.com a71ce185d7 Fix 2022-09-09 15:32:03 +02:00
David ANDRE b75fb5abf5 Renamed suspicious in rules file names to susp 2022-09-09 15:12:47 +02:00
nasreddine.bencherchali@nextron-systems.com 051397b533 Update proc_creation_win_susp_schtasks_delete_all.yml 2022-09-09 15:10:49 +02:00
nasreddine.bencherchali@nextron-systems.com c8fc1cf21e Update proc_creation_win_user_discovery_get_aduser.yml 2022-09-09 15:04:36 +02:00
nasreddine.bencherchali@nextron-systems.com 70f9ff61ca Big Update 2022-09-09 15:02:31 +02:00
Nasreddine Bencherchali fbc7733078 Update proc_creation_win_susp_reg_add.yml 2022-09-08 22:52:24 +02:00
Nasreddine Bencherchali dd67c4fd73 Dev 2022-09-08 22:50:57 +02:00
Florian Roth 358e8a567e Merge pull request #3474 from SigmaHQ/aurora-false-positive-fixing
fix: schtasks in suspicious parents rule
2022-09-08 09:09:26 +02:00
Florian Roth de68bf5559 fix: schtasks in suspicious parents rule 2022-09-08 09:00:58 +02:00
frack113 6813043323 Merge pull request #3468 from nasbench/nasbench-rule-devel
Rule Devel
2022-09-08 06:29:36 +02:00
frack113 6fea0e2c79 Merge pull request #3471 from qasimqlf/patch-5
Update proc_creation_win_bad_opsec_sacrificial_processes.yml
2022-09-08 06:28:25 +02:00
Nasreddine Bencherchali b70ac17676 Fix 2022-09-07 21:58:22 +02:00
Florian Roth 43b56fed23 Merge pull request #3472 from SigmaHQ/rule-devel
rules: SysmonEnte, SharpEvtMute, sdelete rework
2022-09-07 21:06:03 +02:00
Florian Roth a69d256367 rule: SharpEvtMute 2022-09-07 16:33:52 +02:00
Florian Roth 2ac92283e6 indentation and new hashes 2022-09-07 16:05:48 +02:00
Nasreddine Bencherchali 88e9794a74 Update proc_creation_win_system_exe_anomaly.yml 2022-09-07 14:15:10 +02:00
Qasim Qlf bdccc5440a Update proc_creation_win_bad_opsec_sacrificial_processes.yml 2022-09-07 15:28:06 +05:00
Nasreddine Bencherchali dc90e08f3e More updates 2022-09-07 12:02:09 +02:00
Nasreddine Bencherchali 62f5b327fa Update proc_creation_win_inline_win_api_access.yml 2022-09-06 23:04:48 +02:00
Nasreddine Bencherchali f952c02a5f Update after review 2022-09-06 22:59:24 +02:00
Nasreddine Bencherchali 4f69b7058f Update proc_creation_win_inline_win_api_access.yml 2022-09-06 16:57:55 +02:00
Nasreddine Bencherchali 7abe4a7c50 Update proc_creation_win_nslookup_poweshell_download.yml 2022-09-06 16:42:53 +02:00
Florian Roth 5de8a1b2f6 Merge pull request #3464 from YamatoSecurity/rule--nslookup-pwsh-download-cradle
rule add: nslookup pwsh download cradle
2022-09-06 11:21:15 +02:00
Florian Roth 4cdd5a5fec Update proc_creation_win_nslookup_pwsh_download_cradle.yml 2022-09-06 10:53:10 +02:00