frack113
|
33c6ff6b5f
|
add powershell_suspicious_win32_pnpentity
|
2021-08-23 13:17:35 +02:00 |
|
Max Altgelt
|
82dde594d1
|
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 11:20:30 +02:00 |
|
Florian Roth
|
a0f72e5f6f
|
rule: suspicious splwow64 process starts
|
2021-08-23 10:41:42 +02:00 |
|
Florian Roth
|
dc3ed771b5
|
rule: EfsPotato Named Pipe
|
2021-08-23 08:32:50 +02:00 |
|
frack113
|
fc9666fb4e
|
Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
|
2021-08-22 18:56:08 +02:00 |
|
frack113
|
0a410010a2
|
Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
|
2021-08-22 18:50:58 +02:00 |
|
SomeOne
|
295054dcbe
|
Replace old mitre techniques by new one
|
2021-08-22 13:57:56 +02:00 |
|
pbssubhash
|
6b66c0774c
|
Changing service to sysmon
|
2021-08-22 10:10:12 +05:30 |
|
frack113
|
064c65cb1f
|
Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
|
2021-08-21 18:04:52 +02:00 |
|
frack113
|
07a87aa7f8
|
Merge pull request #1858 from frack113/fix_pr718
Replace pr718
|
2021-08-21 18:02:30 +02:00 |
|
frack113
|
a44206bfa0
|
Some cleanup
|
2021-08-21 17:33:39 +02:00 |
|
pbssubhash
|
eee497f656
|
Title modification
|
2021-08-21 20:04:03 +05:30 |
|
pbssubhash
|
a415463f5b
|
Modified rule
|
2021-08-21 19:37:28 +05:30 |
|
pbssubhash
|
fba54b8d69
|
First Rule commit
|
2021-08-21 17:47:56 +05:30 |
|
frack113
|
42c90b9d20
|
fix powershell_psattack error
|
2021-08-21 10:05:47 +02:00 |
|
frack113
|
2f683b9ab7
|
fix powershell_clear_powershell_history error
|
2021-08-21 10:00:48 +02:00 |
|
frack113
|
0fb6c35b1f
|
Cleanup PS rules
|
2021-08-21 09:58:58 +02:00 |
|
frack113
|
da839775fe
|
Update PS rules
|
2021-08-21 09:50:59 +02:00 |
|
frack113
|
6c529f7ab2
|
Update PS rules
|
2021-08-21 09:33:52 +02:00 |
|
frack113
|
cb95582077
|
Update PowerShell rule
|
2021-08-21 09:08:38 +02:00 |
|
Florian Roth
|
b92346ba5f
|
Merge pull request #1882 from austinsonger/win_susp_bitstransfer.yml
win_susp_bitstransfer.yml
|
2021-08-20 16:53:52 +02:00 |
|
frack113
|
7ebd411190
|
update ref from conti_leak
|
2021-08-20 14:22:17 +02:00 |
|
Austin Songer
|
fe0e1353e0
|
Update win_susp_bitstransfer.yml
|
2021-08-19 22:24:23 -05:00 |
|
Austin Songer
|
8d57ae5ffd
|
Create win_susp_bitstransfer.yml
|
2021-08-19 21:57:37 -05:00 |
|
frack113
|
23ad8cd14e
|
remove bad rules
|
2021-08-19 18:30:32 +02:00 |
|
frack113
|
3283664154
|
Update remove useless rules
|
2021-08-19 18:28:44 +02:00 |
|
frack113
|
f1a84536c3
|
update fix
|
2021-08-19 17:55:41 +02:00 |
|
frack113
|
600c6233c2
|
Merge pull request #1874 from gs3cl/patch-1
Update win_nltest_query.yml
|
2021-08-19 16:18:20 +02:00 |
|
frack113
|
78212546a7
|
Merge pull request #1869 from frack113/redcanary_T1546.013
powershell_trigger_profiles T1546.013
|
2021-08-19 16:17:53 +02:00 |
|
frack113
|
90c9c08743
|
fix title
|
2021-08-19 16:09:31 +02:00 |
|
frack113
|
89b6e1108b
|
powershell_wmi_persistence fix errors
|
2021-08-19 15:42:19 +02:00 |
|
frack113
|
1266a66a8d
|
add powershell_wmi_persistence.yml
|
2021-08-19 15:37:28 +02:00 |
|
frack113
|
08af3a9429
|
Cleanup errors
|
2021-08-19 15:20:04 +02:00 |
|
frack113
|
60931d09b9
|
fix title error
|
2021-08-19 14:24:54 +02:00 |
|
gs3cl
|
bf9ac21ebc
|
Update win_nltest_recon.yml
change "startswith" to "contains"
|
2021-08-19 14:12:00 +02:00 |
|
frack113
|
b4a029ac3c
|
Add win_susp_screensaver_reg.yml
|
2021-08-19 13:55:09 +02:00 |
|
gs3cl
|
df829f0d45
|
Update and rename win_nltest_query.yml to win_nltest_recon.yml
changes based on feedback added
Update and rename win_nltest_query.yml to win_nltest_recon.yml
|
2021-08-19 08:26:33 +02:00 |
|
Florian Roth
|
459a0bdca1
|
Merge pull request #1870 from frack113/fix_fp_Renamed_Powershell
Fix some false positives in renamed powershell
|
2021-08-19 08:23:51 +02:00 |
|
gs3cl
|
92b72ffdc1
|
Update win_nltest_query.yml
modification based on new reports
1.https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)
-> for (selection_recon1 and seletion_recon2")
2.https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters -> nltest example
3.MITRE reference just for reference to MITRE to gain more insights
4.https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/
-> new Report about Trickbot with reference and usage of "nltest" therefore I included the option in this rule
|
2021-08-18 20:45:18 +00:00 |
|
Austin Songer
|
c9128687ee
|
Spelling Errors on Rules
|
2021-08-18 18:58:20 +00:00 |
|
Florian Roth
|
39ef3e0df9
|
Merge pull request #1872 from SigmaHQ/rule-devel
fix: FPs with WMIADAP.exe
|
2021-08-18 19:26:17 +02:00 |
|
frack113
|
768855e6d6
|
update modified after FP fix
|
2021-08-18 18:17:53 +02:00 |
|
Florian Roth
|
44013e25c8
|
fix: FPs with WMIADAP.exe
|
2021-08-18 17:26:57 +02:00 |
|
frack113
|
2d05eda1be
|
fix ContextInfo FP
|
2021-08-18 15:18:29 +02:00 |
|
frack113
|
48d0846b53
|
add powershell_trigger_profiles
|
2021-08-18 14:29:50 +02:00 |
|
frack113
|
6a282ad24a
|
fix many FP
|
2021-08-18 13:56:14 +02:00 |
|
Florian Roth
|
efcf1d9019
|
Merge pull request #1867 from SigmaHQ/rule-devel
fix: FPs with [reflection.assembly]::Load
|
2021-08-18 11:42:47 +02:00 |
|
Florian Roth
|
66c674e8e8
|
Merge pull request #1837 from phantinuss/master
generalise amsi bypass rule to CobaltStrike BOF injection pattern
|
2021-08-18 09:53:21 +02:00 |
|
Florian Roth
|
5fa5a412d5
|
fix: FPs with [reflection.assembly]::Load
|
2021-08-18 09:49:34 +02:00 |
|
Florian Roth
|
a0625ad074
|
Merge branch 'master' into rule-devel
|
2021-08-17 12:29:55 +02:00 |
|