Commit Graph

6187 Commits

Author SHA1 Message Date
yugoslavskiy 2985836e36 Merge pull request #1140 from omkar72/oscd-5
[OSCD] adding shortened commands for Netsh in the existing rule
2021-01-06 00:24:43 +03:00
yugoslavskiy d25ca9b280 Merge pull request #1229 from zinint/1009-19-1
[OSCD] Detects Obfuscated Powershell via COMPRESS OBFUSCATION #19 (4104, 4103 + Services + process_creation)
2021-01-06 00:24:08 +03:00
yugoslavskiy 7889df6644 Merge pull request #1227 from stvetro/oscd-runscripthelper
[OSCD] - Runscripthelper.exe runs script (LoLBin)
2021-01-06 00:24:00 +03:00
yugoslavskiy 0ed153237e Merge pull request #1226 from stvetro/oscd-winword
[OSCD] - Force winword.exe to load DLL (LoLBin)
2021-01-06 00:23:52 +03:00
yugoslavskiy 1d2f027035 Merge pull request #1224 from stvetro/oscd
[OSCD] Verclsid.exe Runs COM Object (LOLBin)
2021-01-06 00:23:45 +03:00
yugoslavskiy f4578b0698 Merge pull request #1223 from zinint/1009-23-1
[OSCD] Detects Obfuscated Powershell via RUNDLL Launcher #23 (4104, 4103 + Services + process_creation)
2021-01-06 00:23:33 +03:00
yugoslavskiy 23519e47cd Merge pull request #1222 from feedb/oscd
[OSCD] zer0w
2021-01-06 00:23:25 +03:00
yugoslavskiy 93718975fb Merge pull request #1221 from grikos/OSCD_117_128
[OSCD] suspicious csi.exe (rcsi.exe)  LOLBAS detection rule
2021-01-06 00:23:13 +03:00
yugoslavskiy cd62929bb0 Merge pull request #1220 from aw350m33d/PS_exec_via_redirected_input_stream
[OSCD] LOLBIN 5 PowerShell with redirection of the input stream.
2021-01-06 00:23:06 +03:00
yugoslavskiy 70eff4b1fc Merge pull request #1219 from ryanplasma/rplas-SIGMA-547-page-37
[OSCD] Add Files Dropped to Program Files by Non-Priviledged Process Rule
2021-01-06 00:22:57 +03:00
yugoslavskiy a5bbccf16c Merge pull request #1214 from tas-kmanager/mt-oscd-sigma547-48-alternative
[OSCD] Always Install Elevated Alternative
2021-01-06 00:22:37 +03:00
yugoslavskiy 066be03c19 Merge pull request #1212 from aleqs4ndr/oscd-2020
[OSCD] Added a rule to detect possible Zerologon exploitation
2021-01-06 00:21:12 +03:00
yugoslavskiy 29fe6e46d8 Merge pull request #1211 from zipa-original/win_persistence_telemetry
[OSCD] Added a rule to detect abusing windows telemetry for persistence
2021-01-06 00:20:51 +03:00
yugoslavskiy c71e0ae0ea Merge pull request #1209 from vburov/patch-15
[OSCD] Create win_susp_multiple_files_renamed_or_deleted.yml
2021-01-06 00:19:41 +03:00
yugoslavskiy 38661bbc10 Merge pull request #1208 from NikitaStormwind/RTT(17)
[OSCD] Atomic Red Team: Detected Windows Software Discovery (T1518)
2021-01-06 00:19:20 +03:00
yugoslavskiy 2cf1994763 Merge pull request #1206 from w0rk3r/oscd5
[OSCD] Windows - Suspicious Service DACL Modification
2021-01-06 00:18:53 +03:00
yugoslavskiy aad2838f58 Merge pull request #1198 from tas-kmanager/mt-oscd-sigma547-50-rule2
[OSCD] Always Install Elevated - Slide 50 - Rule 2
2021-01-06 00:18:44 +03:00
yugoslavskiy 0b7babaa84 Merge pull request #1196 from tas-kmanager/mt-oscd-sigma547-50-rule1
[OSCD] Always Install Elevated - Slide 50 - Rule 1
2021-01-06 00:18:26 +03:00
yugoslavskiy fc1fa23440 Merge pull request #1191 from vburov/patch-14
[OSCD] Create powershell_cmdline_special_characters.yml
2021-01-06 00:18:12 +03:00
yugoslavskiy 8e50eeb4a9 Merge pull request #1187 from nsaddler/lolbas108
[OSCD] LOLBAS Manage-bde.yml
2021-01-06 00:18:02 +03:00
yugoslavskiy cfbd10ab8b Merge pull request #1186 from nsaddler/lolbas107_2
[OSCD] LOLBAS CL_Mutexverifiers - powershell
2021-01-06 00:17:54 +03:00
yugoslavskiy e91d48cc93 Merge pull request #1185 from nsaddler/lolbas107_1
[OSCD] LOLBAS CL_Mutexverifiers - process_creation
2021-01-06 00:17:46 +03:00
yugoslavskiy 9d1c695204 Merge pull request #1184 from nsaddler/lolbas106_1
[OSCD] LOLBAS CL_Invocation - powershell
2021-01-06 00:17:10 +03:00
yugoslavskiy def4a7dbb9 Merge pull request #1183 from nsaddler/lolbas106
[OSCD] LOLBAS CL_Invocation - process_creation
2021-01-06 00:17:01 +03:00
yugoslavskiy 6f2e8c56b2 Merge pull request #1182 from nsaddler/lolbas80
[OSCD] LOLBAS wab.yml
2021-01-06 00:16:53 +03:00
yugoslavskiy e1fd69f548 Merge pull request #1179 from SanWieb/OSCD_regedit_3
[OSCD] regedit.exe LOLbas 72 [3]
2021-01-06 00:16:45 +03:00
yugoslavskiy 8e6b77fc4f Merge pull request #1177 from OpalSec/oscd
[OSCD] Tasks 24, 25 & 26: Detection for Invoke-Obfuscation CLIP+, STDIN+ & VAR+ Launchers
2021-01-06 00:16:34 +03:00
yugoslavskiy 95d8a9daf0 Merge pull request #1174 from uncleAntik/update
[OSCD] LOLBin vsjitdebugger.exe #136
2021-01-06 00:16:20 +03:00
yugoslavskiy 252345ca00 Merge pull request #1173 from uncleAntik/fix
[OSCD] LOLBin te.exe #133
2021-01-06 00:16:12 +03:00
yugoslavskiy 1fd0afc58e Merge pull request #1167 from tas-kmanager/mt-oscd-sigma547-43
[OSCD] Add Accesschk tool usage rule
2021-01-06 00:14:08 +03:00
yugoslavskiy 5ade9208d5 Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
2021-01-06 00:12:34 +03:00
yugoslavskiy 5ec4e42569 Merge pull request #1165 from w0rk3r/oscd3
[OSCD] Updated win_etw_trace_evasion - Added new detections, Removed reference to deprecated rule and changed selections
2021-01-06 00:12:22 +03:00
yugoslavskiy 46eb01f3c5 Merge pull request #1164 from GlebSukhodolskiy/oscd_reg
[OSCD] Modified Rule "Autorun Keys Modification"
2021-01-06 00:11:58 +03:00
yugoslavskiy 4c8e0b201d Merge pull request #1162 from uncleAntik/131
[OSCD] LOLBin sqltoolsps.exe #131
2021-01-06 00:11:33 +03:00
yugoslavskiy b56a7181ce Merge pull request #1157 from invrep-de/oscd
[OSCD] Bad Opsec Powershell Artifacts
2021-01-06 00:11:24 +03:00
yugoslavskiy 319ebd158c Merge pull request #1155 from sn0w0tter/oscd2
[OSCD] LOLBAS atbroker suspicious creation of ATs
2021-01-06 00:11:13 +03:00
yugoslavskiy d2087c276c Merge pull request #1151 from zinint/1009-27-2
[OSCD] Detects Obfuscated Powershell via VAR++ Launcher #27 (Services)
2021-01-06 00:10:55 +03:00
yugoslavskiy 0bd955f097 Merge branch 'oscd' into oscd-5 2021-01-06 00:09:47 +03:00
yugoslavskiy 1f0d081c01 Merge pull request #1144 from NikitaStormwind/regular28(3)
[OSCD] Detects Obfuscated Powershell via Stdin in Scripts #28 (Services)
2021-01-05 23:23:00 +03:00
yugoslavskiy 1cfc0d17ef Merge pull request #1141 from omkar72/oscd-6
[OSCD] suspicious clr logs creation
2021-01-05 23:22:36 +03:00
yugoslavskiy 82e5d031b0 Merge pull request #1139 from omkar72/oscd-4
[OSCD] script applications loading .net dll
2021-01-05 23:17:25 +03:00
yugoslavskiy a82c559816 Merge pull request #1130 from vburov/patch-13
[OSCD] Create powershell_cmdline_specific_encoded_methods.yml
2021-01-05 23:16:24 +03:00
yugoslavskiy dd7a95ac74 Merge pull request #1081 from cy1337/patch-1
[OSCD] Added nltest LOLBIN
2021-01-05 23:16:14 +03:00
yugoslavskiy f2c6011c6b Merge pull request #1126 from skirankumar/master
[OSCD]Sysmon_silenttrinity_stager_msbuild_activity.yml
2021-01-05 23:14:20 +03:00
yugoslavskiy 1c1c38e091 Merge pull request #1119 from uncleAntik/oscd
[OSCD] sqlps.exe LOLbin
2021-01-05 23:14:02 +03:00
yugoslavskiy 07ac09f9aa Merge pull request #1114 from NikitaStormwind/regular29(3)
[OSCD] Detects Obfuscated Powershell via use Clip.exe in Scripts #29 (Services)
2021-01-05 23:13:48 +03:00
yugoslavskiy 220a4873c7 Merge pull request #1109 from NikitaStormwind/regular31(3)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (Services)
2021-01-05 23:13:38 +03:00
yugoslavskiy 9803dc8baa Merge pull request #1108 from NikitaStormwind/regular30(3)
[OSCD] Detects Obfuscated Powershell via use Rundll32 in Scripts #30 (Services)
2021-01-05 23:13:27 +03:00
yugoslavskiy 39991a8ab6 Merge pull request #1106 from stvetro/2020
[OSCD] Suspicious ftp.exe usage (LOLBin)
2021-01-05 23:13:03 +03:00
yugoslavskiy 804db42b7a Merge pull request #1105 from Vasilisa-L/OSCD_rasautou
[OSCD] Rasautou.exe LOLbin
2021-01-05 23:12:48 +03:00