Commit Graph

6187 Commits

Author SHA1 Message Date
Florian Roth 05763aea3f docs: level adjusted 2022-02-17 13:02:18 +01:00
Florian Roth dba4a43ef9 Merge pull request #2702 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
2022-02-17 13:02:07 +01:00
Florian Roth 5deb9af698 Update sysmon_reg_office_security.yml 2022-02-17 08:15:25 +01:00
Florian Roth 283475e064 Merge branch 'master' into aurora-false-positive-fixing 2022-02-17 08:13:38 +01:00
frack113 1a76bb82d6 Merge pull request #2700 from frack113/DOSfuscation
add win_pc_cmd_dosfuscation
2022-02-17 06:32:45 +01:00
frack113 3b02967ffb add win_pc_lolbin_wlrmdr 2022-02-16 19:53:46 +01:00
Florian Roth 50efc894bc add common "set" expressions
add common caret obfuscated "set" expressions often found in Invoke-Obfuscation code
2022-02-16 17:33:33 +01:00
Florian Roth 8850de3a2e exclude values that could be prone to FPs
Sorry, I have to disable some of the values. I guess these values would make the rule trigger many false positives.
2022-02-16 17:31:52 +01:00
Florian Roth 57271c3c00 fix: bugs in rules 2022-02-16 17:26:57 +01:00
frack113 fb71c1bb67 fix double double quote 2022-02-16 17:19:01 +01:00
Florian Roth 51bbe21c70 fix: more Aurora FP fixes 2022-02-16 17:16:50 +01:00
Florian Roth 2500c16aea fix: FPs noticed with Aurora 2022-02-16 17:00:27 +01:00
Florian Roth ab3f1f6e7d refactor: extend values - sam rule 2022-02-16 16:59:32 +01:00
phantinuss 9fce5735ad fix: remove unneded escape for " 2022-02-16 16:31:13 +01:00
phantinuss c92b5e8835 fix: known FP 2022-02-16 16:31:13 +01:00
phantinuss 27e4c333d6 fix: filter MS Office 2022-02-16 16:31:13 +01:00
phantinuss ebc27d7c9f fix: exclude cutepdf writer 2022-02-16 16:31:12 +01:00
phantinuss 6816f32c93 fix: remove trailing \ 2022-02-16 16:31:12 +01:00
phantinuss 3207f3ff47 fix: filter known software 2022-02-16 16:31:12 +01:00
phantinuss 5a03d8d5ac fix: filter known software 2022-02-16 16:31:12 +01:00
phantinuss e2f80e5aa8 fix: exclude msiexec from SysWOW64 2022-02-16 16:31:12 +01:00
phantinuss 3e254fe3e4 fix: exclude known office addins 2022-02-16 16:31:12 +01:00
phantinuss cc6613a799 fix: filter MS Office and Dropbox 2022-02-16 16:31:12 +01:00
phantinuss 741640cb10 fix: filter known extensions and toolbar entries 2022-02-16 16:31:12 +01:00
phantinuss ac8cd7516a fix: single list items 2022-02-16 16:31:11 +01:00
phantinuss 7b8ea16ca3 fix: single list item 2022-02-16 16:31:11 +01:00
phantinuss 5aee70f7d5 fix: exclude common FPs occuring on test system 2022-02-16 16:31:11 +01:00
phantinuss 12fffc5fd5 fix: more chocolatey FPs 2022-02-16 16:31:11 +01:00
phantinuss 96bf7421fc fix: reworked rule and added more FP filters 2022-02-16 16:31:11 +01:00
Florian Roth 93be74b2fb Merge pull request #2699 from phantinuss/checkbaseline
Fix FPs (Example Installation 4)
2022-02-15 20:07:49 +01:00
frack113 ac136f3e17 Merge pull request #2676 from redsand/fp_allow_dynatrace_behavior
Filtering fp of dynatrace behavior
2022-02-15 19:41:48 +01:00
frack113 98975ef50e add win_pc_cmd_dosfuscation 2022-02-15 17:58:39 +01:00
phantinuss c7d270956c fix: several FPs against a fresh installed Windows with example applications and basic user interaction 4 2022-02-15 16:40:04 +01:00
frack113 ce8cdf24ec Aurora FP 2022-02-14 18:08:51 +01:00
frack113 b632b6bda0 Fix invalid logsource 2022-02-14 06:48:22 +01:00
frack113 171edbd1bc Merge pull request #2694 from frack113/Red_20220213
Windows Redcannary
2022-02-14 06:34:20 +01:00
frack113 277d14f4ee Merge pull request #2696 from frack113/thedfirreport_qbot
Missing Qbot rules
2022-02-14 06:34:09 +01:00
frack113 7f15b7a802 Missing Qbot rules 2022-02-13 16:07:28 +01:00
frack113 82e08de42c Merge pull request #2693 from wagga40/master
Correct a typo in rule name
2022-02-13 16:00:40 +01:00
wagga40 fceb2c0de1 Correct bad commit 2022-02-13 13:34:28 +01:00
Florian Roth e49c142e08 Merge pull request #2695 from frack113/aurora_fp
Aurora Office FP
2022-02-13 12:34:40 +01:00
frack113 ce0a5033f8 Aurora Office FP 2022-02-13 11:29:52 +01:00
Florian Roth 22f23b654a fix: FPs noticed with Aurora 2022-02-13 11:24:28 +01:00
Florian Roth 1b7cc9b35a Merge pull request #2691 from frack113/red_20220212
Windows Redcannary
2022-02-13 11:23:20 +01:00
frack113 f288134b41 Windows Redcannary 2022-02-13 11:04:00 +01:00
wagga40 c840c1a7f7 Correct a typo in rule name 2022-02-13 09:34:43 +01:00
frack113 e61c9e4b2e Merge pull request #2690 from frack113/susp_temp_exe
add win_pc_susp_run_folder
2022-02-13 09:04:16 +01:00
frack113 7e3c088165 Windows Redcannary 2022-02-12 15:53:13 +01:00
Florian Roth 0feefdc751 Update win_pc_susp_run_folder.yml 2022-02-12 10:17:27 +01:00
Florian Roth 98dbfe1ff6 fix: too many matches on many programs
... running from every other locations
2022-02-12 00:44:42 +01:00