Florian Roth
|
eeca6a898b
|
fix: mitre attack tags
|
2022-09-21 18:16:02 +02:00 |
|
Florian Roth
|
2ffca9c8da
|
fix: condition
|
2022-09-21 18:08:24 +02:00 |
|
Florian Roth
|
026844026f
|
fix: condition in sharpersist rule
|
2022-09-21 18:04:18 +02:00 |
|
Florian Roth
|
61a4a48ac0
|
fix: CommandLine field types
|
2022-09-21 18:02:42 +02:00 |
|
Florian Roth
|
8e011540b0
|
rule: createdump renamed
|
2022-09-21 16:30:47 +02:00 |
|
Florian Roth
|
2fe25f3c80
|
rule: sharpersist usage
|
2022-09-15 16:50:34 +02:00 |
|
Florian Roth
|
22d0e22d14
|
rule: 3proxy usage, fix: rule - missing contains
|
2022-09-14 10:22:01 +02:00 |
|
Florian Roth
|
37aed9ac3b
|
docs: add link
|
2022-09-13 13:38:32 +02:00 |
|
Florian Roth
|
3a38b63fff
|
refactor: chisel rules
|
2022-09-13 13:38:10 +02:00 |
|
Florian Roth
|
2d7e545cad
|
fix: list with one element
|
2022-09-13 08:38:57 +02:00 |
|
Florian Roth
|
c22974205f
|
Merge branch 'master' into rule-devel
|
2022-09-13 08:07:35 +02:00 |
|
Florian Roth
|
61422ca237
|
rule: UAC Bypass via ICMLuaUtil
|
2022-09-13 08:07:15 +02:00 |
|
Florian Roth
|
072a9d73eb
|
fix: changes to existing rules
|
2022-09-13 08:07:03 +02:00 |
|
Qasim Qlf
|
1eaad811b6
|
tag added
|
2022-09-12 14:15:48 +05:00 |
|
David André
|
93da67b593
|
Update proc_creation_win_renamed_vmnat.yml
Added accidentaly removed falsepositives
|
2022-09-11 13:13:58 +02:00 |
|
David André
|
5656a3a50b
|
Merge branch 'SigmaHQ:master' into add_renamed_vmnat
|
2022-09-11 13:06:21 +02:00 |
|
David ANDRE
|
d73aac41d3
|
Changes based on advice
|
2022-09-11 12:44:54 +02:00 |
|
frack113
|
21435629a0
|
Merge pull request #3482 from nasbench/nasbench-rule-devel
Rule Devel (New+Update)
|
2022-09-10 12:34:26 +02:00 |
|
Florian Roth
|
e7084eee04
|
Merge pull request #3487 from SigmaHQ/aurora-false-positive-fixing
fix: fixing multiple FPs with the use of VSCode
|
2022-09-10 12:07:01 +02:00 |
|
Florian Roth
|
0a5cfb93b3
|
fix: condition
|
2022-09-10 11:53:42 +02:00 |
|
Florian Roth
|
7dbdd4d1c6
|
fix: fixing multiple FPs with the use of VSCode
|
2022-09-10 11:42:44 +02:00 |
|
Florian Roth
|
a053be791c
|
Update proc_creation_win_user_discovery_get_aduser.yml
|
2022-09-10 09:49:14 +02:00 |
|
Florian Roth
|
a616647b08
|
lowered score of scheduled task + SYSTEM rule
|
2022-09-10 09:48:50 +02:00 |
|
Nasreddine Bencherchali
|
2552b75e72
|
Delete proc_creation_win_net_add_local_user.yml
|
2022-09-09 23:11:28 +02:00 |
|
David ANDRE
|
6182b43279
|
Add rule for renamed vmnat.exe
|
2022-09-09 16:40:17 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
14db9c9fb1
|
Update proc_creation_win_wmic_computersystem_recon.yml
|
2022-09-09 15:43:07 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
a71ce185d7
|
Fix
|
2022-09-09 15:32:03 +02:00 |
|
David ANDRE
|
b75fb5abf5
|
Renamed suspicious in rules file names to susp
|
2022-09-09 15:12:47 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
051397b533
|
Update proc_creation_win_susp_schtasks_delete_all.yml
|
2022-09-09 15:10:49 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
c8fc1cf21e
|
Update proc_creation_win_user_discovery_get_aduser.yml
|
2022-09-09 15:04:36 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
70f9ff61ca
|
Big Update
|
2022-09-09 15:02:31 +02:00 |
|
Nasreddine Bencherchali
|
fbc7733078
|
Update proc_creation_win_susp_reg_add.yml
|
2022-09-08 22:52:24 +02:00 |
|
Nasreddine Bencherchali
|
dd67c4fd73
|
Dev
|
2022-09-08 22:50:57 +02:00 |
|
Florian Roth
|
358e8a567e
|
Merge pull request #3474 from SigmaHQ/aurora-false-positive-fixing
fix: schtasks in suspicious parents rule
|
2022-09-08 09:09:26 +02:00 |
|
Florian Roth
|
de68bf5559
|
fix: schtasks in suspicious parents rule
|
2022-09-08 09:00:58 +02:00 |
|
frack113
|
6813043323
|
Merge pull request #3468 from nasbench/nasbench-rule-devel
Rule Devel
|
2022-09-08 06:29:36 +02:00 |
|
frack113
|
6fea0e2c79
|
Merge pull request #3471 from qasimqlf/patch-5
Update proc_creation_win_bad_opsec_sacrificial_processes.yml
|
2022-09-08 06:28:25 +02:00 |
|
Nasreddine Bencherchali
|
b70ac17676
|
Fix
|
2022-09-07 21:58:22 +02:00 |
|
Florian Roth
|
43b56fed23
|
Merge pull request #3472 from SigmaHQ/rule-devel
rules: SysmonEnte, SharpEvtMute, sdelete rework
|
2022-09-07 21:06:03 +02:00 |
|
Florian Roth
|
a69d256367
|
rule: SharpEvtMute
|
2022-09-07 16:33:52 +02:00 |
|
Florian Roth
|
2ac92283e6
|
indentation and new hashes
|
2022-09-07 16:05:48 +02:00 |
|
Nasreddine Bencherchali
|
88e9794a74
|
Update proc_creation_win_system_exe_anomaly.yml
|
2022-09-07 14:15:10 +02:00 |
|
Qasim Qlf
|
bdccc5440a
|
Update proc_creation_win_bad_opsec_sacrificial_processes.yml
|
2022-09-07 15:28:06 +05:00 |
|
Nasreddine Bencherchali
|
dc90e08f3e
|
More updates
|
2022-09-07 12:02:09 +02:00 |
|
Nasreddine Bencherchali
|
62f5b327fa
|
Update proc_creation_win_inline_win_api_access.yml
|
2022-09-06 23:04:48 +02:00 |
|
Nasreddine Bencherchali
|
f952c02a5f
|
Update after review
|
2022-09-06 22:59:24 +02:00 |
|
Nasreddine Bencherchali
|
4f69b7058f
|
Update proc_creation_win_inline_win_api_access.yml
|
2022-09-06 16:57:55 +02:00 |
|
Nasreddine Bencherchali
|
7abe4a7c50
|
Update proc_creation_win_nslookup_poweshell_download.yml
|
2022-09-06 16:42:53 +02:00 |
|
Florian Roth
|
5de8a1b2f6
|
Merge pull request #3464 from YamatoSecurity/rule--nslookup-pwsh-download-cradle
rule add: nslookup pwsh download cradle
|
2022-09-06 11:21:15 +02:00 |
|
Florian Roth
|
4cdd5a5fec
|
Update proc_creation_win_nslookup_pwsh_download_cradle.yml
|
2022-09-06 10:53:10 +02:00 |
|