Commit Graph

568 Commits

Author SHA1 Message Date
frack113 9b106dcc7d Merge pull request #1880 from austinsonger/azure_suppression_rule_created.yml
azure_suppression_rule_created.yml
2021-08-20 09:04:48 +02:00
frack113 d58b1e8e40 Merge pull request #1879 from austinsonger/azure_application_gateway_modified_or_deleted.yml
azure_application_gateway_modified_or_deleted.yml
2021-08-20 09:03:57 +02:00
frack113 4b08aac47f Merge pull request #1878 from austinsonger/azure_application_security_group_modified_or_deleted.yml
azure_application_security_group_modified_or_deleted.yml
2021-08-20 09:01:39 +02:00
Austin Songer 853c2eb41d Update microsoft365_potential_ransomware_activity.yml 2021-08-20 01:19:01 -05:00
Austin Songer f745593e80 Update microsoft365_potential_ransomware_activity.yml 2021-08-20 00:33:42 -05:00
Austin Songer 42fbc0cbfc Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 23:13:35 -05:00
Austin Songer bcb43cf728 Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 23:13:06 -05:00
Austin Songer b89910a38a Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 23:09:38 -05:00
frack113 f882ebda35 fix status 2021-08-20 06:08:28 +02:00
Austin Songer 54bda90685 Create microsoft365_user_restricted_from_sending_email.yml 2021-08-19 23:08:25 -05:00
Austin Songer 9b19190ea7 Create microsoft365_potential_ransomware_activity.yml 2021-08-19 23:05:05 -05:00
Austin Songer 99fbd4ef44 Create microsoft365_unusual_volume_of_file_deletion.yml 2021-08-19 23:00:23 -05:00
Austin Songer 810aae5ddd Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 21:58:36 -05:00
Austin Songer 0a3e57cc12 Update 2021-08-20 02:10:32 +00:00
Austin Songer 842ade16be Forgot to add my username to some of the rules. 2021-08-20 02:09:31 +00:00
Austin Songer 9a83836070 Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 21:00:36 -05:00
Austin Songer 6ae62488b3 Merge branch 'SigmaHQ:master' into azure_application_gateway_modified_or_deleted.yml 2021-08-19 20:32:35 -05:00
Austin Songer d2f87feb7b Merge branch 'SigmaHQ:master' into azure_application_security_group_modified_or_deleted.yml 2021-08-19 20:31:48 -05:00
frack113 0103b148f7 Merge pull request #1876 from rachelrice/update_cloudtrail_rules
Update AWS CloudTrail rules
2021-08-19 18:33:07 +02:00
frack113 39617c9807 Merge pull request #1865 from austinsonger/azure_keyvault_secrets_modified_or_deleted.yml
add azure_keyvault_secrets_modified_or_deleted.yml
2021-08-19 17:06:28 +02:00
Austin Songer cc51e054e3 Update azure_keyvault_secrets_modified_or_deleted.yml 2021-08-19 09:04:22 -05:00
Rachel Rice 67020bb0ff Update AWS CloudTrail rules
aws_elasticache_security_group_created.yml
aws_elasticache_security_group_modified_or_deleted.yml
Removed spaces from eventNames

aws_s3_data_management_tampering.yml
Fix typo in title, use s3 as eventSource

aws_snapshot_backup_exfiltration.yml
Use ec2 as eventSource
2021-08-19 14:24:43 +01:00
Austin Songer 36406d5781 Fixed Spelling 2021-08-18 18:53:28 +00:00
frack113 c7d697e720 Merge pull request #1864 from austinsonger/azure_key_vault_modified_or_deleted.yml
azure_keyvault_modified_or_deleted.yml
2021-08-18 18:30:20 +02:00
Austin Songer 309e71491b Update azure_keyvault_key_modified_or_deleted.yml 2021-08-17 08:44:39 -05:00
Austin Songer 23d0477120 Update azure_keyvault_secrets_modified_or_deleted.yml 2021-08-17 08:42:41 -05:00
Austin Songer 16e0def41d Update and rename azure_vault_key_modified_or_deleted.yml to azure_keyvault_key_modified_or_deleted.yml 2021-08-17 08:31:22 -05:00
Austin Songer ecdcd8f843 Rename azure_key_vault_modified_or_deleted.yml to azure_keyvault_modified_or_deleted.yml 2021-08-17 08:30:10 -05:00
Austin Songer 49ab7d7bb6 Merge branch 'SigmaHQ:master' into azure_application_gateway_modified_or_deleted.yml 2021-08-17 08:29:18 -05:00
Austin Songer 9986515b59 Update azure_suppression_rule_created.yml 2021-08-17 00:04:11 -05:00
Austin Songer 84e96d5b4f Create azure_suppression_rule_created.yml 2021-08-17 00:04:00 -05:00
Austin Songer 1fcc1701b7 Create azure_keyvault_secrets_modified_or_deleted.yml 2021-08-16 23:54:57 -05:00
Austin Songer 7abceb07ce Create azure_vault_key_modified_or_deleted.yml 2021-08-16 23:50:56 -05:00
Austin Songer 758293e2f9 Delete azure_application_security_group_modified_or_deleted.yml 2021-08-16 23:42:15 -05:00
Austin Songer 824d64a9ce Create azure_key_vault_modified_or_deleted.yml 2021-08-16 23:41:43 -05:00
Austin Songer 3c8f27ba76 Create azure_application_security_group_modified_or_deleted.yml 2021-08-16 23:31:45 -05:00
Austin Songer 144cfcb016 Create azure_application_gateway_modified_or_deleted.yml 2021-08-16 23:30:30 -05:00
frack113 63733a623e Merge pull request #1861 from austinsonger/aws_eks_cluster_modified_or_deleted.yml
aws_eks_cluster_created_or_deleted.yml
2021-08-17 06:25:18 +02:00
frack113 2521ae2ed1 Merge pull request #1859 from austinsonger/gcp_vpn_tunnel_modified_or_deleted.yml
gcp_vpn_tunnel_modified_or_deleted.yml
2021-08-17 06:24:49 +02:00
frack113 accb675ed5 fix error space 2021-08-16 20:36:55 +02:00
Austin Songer 80062ff5cd Update aws_eks_cluster_created_or_deleted.yml 2021-08-16 12:42:14 -05:00
Austin Songer cfb863a98e Update aws_eks_cluster_created_or_deleted.yml 2021-08-16 11:52:22 -05:00
Austin Songer ed507b82f4 Update and rename aws_eks_cluster_modified_or_deleted.yml to aws_eks_cluster_created_or_deleted.yml 2021-08-16 09:58:48 -05:00
Austin Songer c7831a3d70 Update gcp_vpn_tunnel_modified_or_deleted.yml 2021-08-16 09:45:31 -05:00
frack113 c57ded1ecd Merge pull request #1852 from austinsonger/gcp_dns_zone_modified_or_deleted.yml
gcp_dns_zone_modified_or_deleted.yml
2021-08-16 07:37:28 +02:00
frack113 d710818eb2 Merge pull request #1851 from austinsonger/gcp_dlp_re-identifies_sensitive_information.yml
gcp_dlp_re-identifies_sensitive_information.yml
2021-08-16 07:37:02 +02:00
frack113 0973c51ef5 Merge pull request #1850 from austinsonger/aws_efs_fileshare_modified_or_deleted.yml
aws_efs_fileshare_modified_or_deleted.yml
2021-08-16 07:36:43 +02:00
frack113 37b8040e76 cleanup gcp_dlp_re-identifies_sensitive_information
Remove list with only 1 value
2021-08-16 06:28:40 +02:00
Austin Songer ae12f1f328 Update gcp_dlp_re-identifies_sensitive_information.yml 2021-08-15 22:57:54 -05:00
Austin Songer 2524adc6ca Update aws_efs_fileshare_mount_modified_or_deleted.yml 2021-08-15 22:54:11 -05:00