Commit Graph

2788 Commits

Author SHA1 Message Date
Yuliya Fomina ab8e9ed8e7 Create win_susp_winrm_AWL_bypass 2020-10-07 12:07:20 +03:00
grikos 391af43708 Update description & references 2020-10-07 10:32:51 +03:00
svch0stz c879378e35 Update win_susp_mounted_share_deletion.yml 2020-10-07 17:46:13 +11:00
svch0stz dabc092ab9 Create win_susp_mounted_share_deletion.yml 2020-10-07 17:34:48 +11:00
Vasilisa-L 5d01f71f62 CommandLine|contains -> CommandLine|contains|all:
Replaced wildcard expression with list of values
2020-10-07 08:43:22 +03:00
grikos 49119e162f Delete win_susp_rundll32_setupapi_installhinfsection.yml 2020-10-07 01:04:59 +03:00
grikos a5478950c7 Create win_susp_rundll32_setupapi_installhinfsection.yml 2020-10-07 00:34:00 +03:00
grikos 9d9f0bc373 Create win_susp_rundll32_setupapi_installhinfsection.yml 2020-10-07 00:18:41 +03:00
svch0stz 3d048ceba0 Update win_susp_copy_lateral_movement.yml 2020-10-07 08:18:09 +11:00
svch0stz ee2c79745f Update win_susp_wsl_lolbin.yml 2020-10-07 08:12:51 +11:00
grikos 6e02e6ac19 Change title and update description 2020-10-06 19:52:31 +03:00
Furkan CALISKAN bbb9fed3e6 Fixed for FP issues 2020-10-06 19:51:55 +03:00
ensar-pcs 60b3450fa8 [OSCD] win_syncappvpublishingserver_exe.yml added 2020-10-06 19:22:16 +03:00
Furkan CALISKAN 0023a22ead Added FP conditions and fileshare part for cmdline 2020-10-06 19:20:19 +03:00
Furkan CALISKAN a5ceba93a9 Fixed conditions 2020-10-06 19:15:30 +03:00
Furkan CALISKAN 52edc13d15 Fixed dates 2020-10-06 19:10:33 +03:00
grikos 79503c63dd fixed typo in att&ck mapping tag 2020-10-06 12:22:19 +03:00
grikos b93e64cd96 Update title according with the guideline 2020-10-06 11:59:20 +03:00
grikos 2638e2a80e newline at the end of file 2020-10-06 10:35:12 +03:00
grikos 6ae36993d9 Create win_susp_vboxdrvInst.yml 2020-10-06 10:18:34 +03:00
Vasilisa-L 5b31b8755d Update win_susp_pcwutl.yml 2020-10-06 08:55:01 +03:00
Vasiliy Burov 3f1d44e751 Update win_hack_hydra.yml 2020-10-05 23:52:55 +03:00
Vasiliy Burov f38738e530 Update win_hack_hydra.yml 2020-10-05 23:34:30 +03:00
Furkan CALISKAN ea6d60c58f Added print lolbin 2020-10-05 23:26:57 +03:00
Vasiliy Burov f6ec8673da Update win_hack_hydra.yml 2020-10-05 23:24:59 +03:00
Vasiliy Burov 6a01193661 Update win_hack_hydra.yml 2020-10-05 23:24:08 +03:00
Vasiliy Burov df704ba4fb Create win_hack_hydra.yml 2020-10-05 23:05:27 +03:00
Furkan CALISKAN db4804d6bf Merge branch 'master' of https://github.com/caliskanfurkan/sigma 2020-10-05 23:03:21 +03:00
Furkan CALISKAN 4d655138b2 Added findstr lolbin 2020-10-05 23:03:05 +03:00
Yuliya Fomina 815aa3c719 Edited win_susp_pcwutl 2020-10-05 14:00:21 +03:00
Furkan ÇALIŞKAN b147fc3296 Update win_susp_explorer.yml
Added known-fp
2020-10-05 13:22:43 +03:00
Yuliya Fomina 39f955d24d Revert "Create win_susp_pester.yml"
This reverts commit 577daa378a.
2020-10-05 13:14:35 +03:00
Yuliya Fomina 577daa378a Create win_susp_pester.yml 2020-10-05 12:22:50 +03:00
Yuliya Fomina ffc768e262 Create win_susp_pcwutl.yml 2020-10-05 11:30:24 +03:00
Furkan ÇALIŞKAN 85962665fd Update win_susp_explorer.yml 2020-10-05 10:49:54 +03:00
svch0stz 60bd6a3692 Update win_susp_copy_lateral_movement.yml 2020-10-05 14:35:20 +11:00
svch0stz dd2ab4082d Update win_susp_copy_lateral_movement.yml 2020-10-05 14:33:00 +11:00
svch0stz 641f3031bd Update win_susp_copy_lateral_movement.yml 2020-10-05 14:27:39 +11:00
svch0stz 3516819bf8 Delete win_net_use_admin_share.yml 2020-10-05 14:00:36 +11:00
svch0stz c675be41e2 Create win_net_use_admin_share.yml 2020-10-05 13:57:50 +11:00
svch0stz bc947fefc1 Create win_susp_wsl_lolbin.yml 2020-10-05 13:36:40 +11:00
Furkan CALISKAN 00cf61cc5b Added explorer.exe LOLbin, OSCD 2020-10-04 23:47:16 +03:00
Steven 05d2de4c26 - Cleaned up some more rules where 'service: sysmon' was combined with category
- Replaced 'service: sysmon' with category: ... for some more events to make the rules more product independent

       modified:   rules/windows/builtin/win_invoke_obfuscation_obfuscated_iex_services.yml
       modified:   rules/windows/malware/mal_azorult_reg.yml
       modified:   rules/windows/powershell/powershell_suspicious_profile_create.yml
       modified:   rules/windows/process_creation/sysmon_cmstp_execution.yml
       modified:   rules/windows/process_creation/win_apt_chafer_mar18.yml
       modified:   rules/windows/process_creation/win_apt_unidentified_nov_18.yml
       modified:   rules/windows/process_creation/win_hktl_createminidump.yml
       modified:   rules/windows/process_creation/win_mal_adwind.yml
       modified:   rules/windows/process_creation/win_silenttrinity_stage_use.yml
2020-10-02 10:45:29 +02:00
Steven 8b74abe0bc - Created new categories for sysmon events
- Replaced the explicit EventIDs with the reference to the category
- Moved the rules to the corresponding directories
2020-09-30 20:44:14 +02:00
Florian Roth c17ca6d5fe Merge pull request #1018 from savvyspoon/wcry-dns
WannaCry Killswitch domain DNS query
2020-09-29 09:27:21 +02:00
Florian Roth d7d9c0e772 Merge pull request #1021 from hieuttmmo/master
Sigma rule to detect AdFind.exe execution
2020-09-27 09:50:41 +02:00
Florian Roth 8020fe3c40 false positive condition 2020-09-26 17:03:29 +02:00
Florian Roth 60795f7050 Update win_susp_adfind.yml
Fear that a simple adfind.exe causes too many false positives
2020-09-26 17:02:39 +02:00
Florian Roth dbdd758365 Duplicate Rule
we already have a rule for that
2020-09-26 17:01:32 +02:00
Tran Trung Hieu d4dd0600ad Fix logsource service to process_creation 2020-09-26 21:45:23 +07:00