securepeacock
|
364b5c9620
|
Create sysmon_process_hollowing.yml
Closed old request, and put rule into its appropriate file directory.
|
2022-01-25 15:57:03 -05:00 |
|
securepeacock
|
1cfa06e6e6
|
Update process_creation_rundll32_not_from_c_drive.yml
|
2022-01-25 14:43:30 -05:00 |
|
securepeacock
|
076b0c9246
|
Create process_creation_rundll32_not_from_c_drive.yml
Sample Log:
Process Create: RuleName: - UtcTime: 2022-01-25 17:12:12.156 ProcessGuid: {A931971D-2F6C-61F0-D700-000000005200} ProcessId: 724 Image: C:\Windows\notepad.exe FileVersion: 10.0.14393.0 (rs1_release.160715-1616) Description: Notepad Product: Microsoft® Windows® Operating System Company: Microsoft Corporation OriginalFileName: NOTEPAD.EXE CommandLine: "c:\windows\notepad.exe" CurrentDirectory: E:\ User: WINDOMAIN\vagrant LogonGuid: {A931971D-283E-61F0-3DF7-080000000000} LogonId: 0x8F73D TerminalSessionId: 1 IntegrityLevel: Medium Hashes: SHA1=40F2E778CF1EFFA957C719D2398E641EFF20E613,MD5=3B508CAE5DEBCBA928B5BC355517E2E6,SHA256=DA0ACEE8F60A460CFB5249E262D3D53211EBC4C777579E99C8202B761541110A,IMPHASH=968239BE2020F1C0DAFFDCDBD49E9C82 ParentProcessGuid: {A931971D-2F57-61F0-D600-000000005200} ParentProcessId: 936 ParentImage: C:\Windows\System32\rundll32.exe ParentCommandLine: "C:\Windows\System32\rundll32.exe" SharedFiles.dll,BasicScore ParentUser: WINDOMAIN\vagrant
|
2022-01-25 14:42:13 -05:00 |
|
frack113
|
a68cf58264
|
Merge pull request #2596 from frack113/blackbyte
Add win_re_blackbyte_ransomware
|
2022-01-25 20:39:05 +01:00 |
|
frack113
|
818b20b949
|
add posh_ps_clear_powershell_history
|
2022-01-25 19:58:18 +01:00 |
|
Max Altgelt
|
51d9aca239
|
chore: update modified date
|
2022-01-25 11:46:16 +01:00 |
|
Max Altgelt
|
0cad38be34
|
fix: Add filter for empty image to rule
|
2022-01-25 11:43:35 +01:00 |
|
frack113
|
8a47c56397
|
Merge pull request #2595 from frack113/red_20220123b
Windows Redcannary
|
2022-01-25 06:21:17 +01:00 |
|
frack113
|
f634962420
|
Merge pull request #2594 from frack113/red_20220123
Windows Redcannary tests
|
2022-01-25 06:20:53 +01:00 |
|
frack113
|
0d5618f8ef
|
Merge pull request #2593 from frack113/moonbounce
add win_pc_susp_instalutil
|
2022-01-25 06:20:38 +01:00 |
|
Florian Roth
|
f80f0d3696
|
rules: nircmd, nsudo, runx
|
2022-01-24 13:37:28 +01:00 |
|
Florian Roth
|
d9193efda3
|
Merge pull request #2597 from SigmaHQ/rule-devel
AdvancedRun and Bugfix
|
2022-01-24 12:39:51 +01:00 |
|
Florian Roth
|
9505a761e1
|
fix: bug in rule - missing backspace
|
2022-01-24 11:54:58 +01:00 |
|
frack113
|
4be9a6c3ad
|
Add win_re_blackbyte_ransomware
|
2022-01-24 10:03:52 +01:00 |
|
frack113
|
2dc0c2a8a9
|
fix field name case
|
2022-01-23 19:12:12 +01:00 |
|
frack113
|
f1959f25d7
|
Windows Redcannary
|
2022-01-23 16:37:59 +01:00 |
|
frack113
|
097704d834
|
add win_pc_susp_instalutil
|
2022-01-23 14:47:25 +01:00 |
|
frack113
|
1b8fa21be1
|
Fix space
|
2022-01-23 11:40:35 +01:00 |
|
frack113
|
90334e7f7c
|
Redcannary windows test
|
2022-01-23 11:37:01 +01:00 |
|
frack113
|
31e38623de
|
Update win_susp_curl_fileupload
|
2022-01-23 11:35:36 +01:00 |
|
frack113
|
5f71d21dc0
|
Merge pull request #2589 from frack113/discussions_2584
Move windows internal services to builtin
|
2022-01-21 18:39:32 +01:00 |
|
Florian Roth
|
7dabe5e7a8
|
Merge pull request #2591 from frack113/colorcpl
add win_fe_susp_colorcpl
|
2022-01-21 17:47:52 +01:00 |
|
Florian Roth
|
978381000f
|
Merge pull request #2588 from frack113/order_folder
Order rules
|
2022-01-21 17:47:09 +01:00 |
|
frack113
|
97f4bda4bc
|
add win_fe_susp_colorcpl
|
2022-01-21 14:16:35 +01:00 |
|
frack113
|
6eeb0723ed
|
Fix FP thanks aurora
|
2022-01-21 13:14:35 +01:00 |
|
frack113
|
7053d42e43
|
move to builtin
|
2022-01-21 11:59:13 +01:00 |
|
frack113
|
eb22807ddc
|
Order rules
|
2022-01-20 22:06:55 +01:00 |
|
frack113
|
137fc39c54
|
Merge pull request #2578 from frack113/red_20220119
Add Redcannary Windows Rules
|
2022-01-20 18:03:04 +01:00 |
|
frack113
|
0ae1e37ac9
|
Merge pull request #2586 from phantinuss/master
fix: typo unkown --> unknown
|
2022-01-20 11:36:33 +01:00 |
|
Florian Roth
|
8cf78fb4e6
|
rules: advancedrun executions
|
2022-01-20 11:08:08 +01:00 |
|
Florian Roth
|
e99d030754
|
Merge pull request #2585 from SigmaHQ/rule-devel
First code integrity rule - new log source
|
2022-01-20 11:06:20 +01:00 |
|
phantinuss
|
26c1c23305
|
fix: typo
|
2022-01-20 10:45:30 +01:00 |
|
Florian Roth
|
9b7b48c0e6
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2022-01-20 09:45:03 +01:00 |
|
Florian Roth
|
4395a6dafa
|
rule: code integrity failed driver load
|
2022-01-20 09:45:00 +01:00 |
|
frack113
|
caa4c7f977
|
Add Redcannary Windows Rules
|
2022-01-19 20:40:43 +01:00 |
|
Florian Roth
|
8a70729654
|
Merge pull request #2574 from SigmaHQ/rule-devel
rule: extended Defender exclusions rule
|
2022-01-19 20:32:14 +01:00 |
|
Florian Roth
|
86165466e5
|
Merge pull request #2577 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
|
2022-01-19 20:32:05 +01:00 |
|
Florian Roth
|
d6af219bed
|
Merge branch 'master' into pr/2573
|
2022-01-19 19:42:49 +01:00 |
|
Florian Roth
|
6835381e6a
|
Merge branch 'master' into rule-devel
|
2022-01-19 19:42:14 +01:00 |
|
Florian Roth
|
27912f20d1
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-01-19 19:41:39 +01:00 |
|
Florian Roth
|
e10decf584
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-01-19 19:41:09 +01:00 |
|
Florian Roth
|
51970e888e
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-01-19 19:40:51 +01:00 |
|
Florian Roth
|
ba3a71aa9a
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-01-19 18:35:20 +01:00 |
|
Florian Roth
|
94df11f53c
|
fix: FPs noticed with Aurora
|
2022-01-19 18:34:07 +01:00 |
|
frack113
|
4631d0c482
|
remove invalid tag
|
2022-01-19 18:23:30 +01:00 |
|
Tim Shelton
|
37243f5902
|
Updating formatting for more accurate mssql sqlps.exe detection
|
2022-01-19 14:49:00 +00:00 |
|
Florian Roth
|
d7de27ca3c
|
rule: extended Defender exclusions rule
|
2022-01-19 13:21:19 +01:00 |
|
Tim Shelton
|
dc1e150a46
|
adding support for mssql sqlps.exe
|
2022-01-18 23:55:04 +00:00 |
|
Tim Shelton
|
ec51cf6698
|
Allow wmi service to also perform, since winrm is being allowed
|
2022-01-18 22:20:55 +00:00 |
|
Tim Shelton
|
a0983a3659
|
Allow dsac to perform powershell execution over named pipes. DSAC - Active Directory Admin Client
|
2022-01-18 19:55:00 +00:00 |
|