Florian Roth
|
05763aea3f
|
docs: level adjusted
|
2022-02-17 13:02:18 +01:00 |
|
Florian Roth
|
dba4a43ef9
|
Merge pull request #2702 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-02-17 13:02:07 +01:00 |
|
Florian Roth
|
5deb9af698
|
Update sysmon_reg_office_security.yml
|
2022-02-17 08:15:25 +01:00 |
|
Florian Roth
|
283475e064
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-02-17 08:13:38 +01:00 |
|
frack113
|
1a76bb82d6
|
Merge pull request #2700 from frack113/DOSfuscation
add win_pc_cmd_dosfuscation
|
2022-02-17 06:32:45 +01:00 |
|
frack113
|
3b02967ffb
|
add win_pc_lolbin_wlrmdr
|
2022-02-16 19:53:46 +01:00 |
|
Florian Roth
|
50efc894bc
|
add common "set" expressions
add common caret obfuscated "set" expressions often found in Invoke-Obfuscation code
|
2022-02-16 17:33:33 +01:00 |
|
Florian Roth
|
8850de3a2e
|
exclude values that could be prone to FPs
Sorry, I have to disable some of the values. I guess these values would make the rule trigger many false positives.
|
2022-02-16 17:31:52 +01:00 |
|
Florian Roth
|
57271c3c00
|
fix: bugs in rules
|
2022-02-16 17:26:57 +01:00 |
|
frack113
|
fb71c1bb67
|
fix double double quote
|
2022-02-16 17:19:01 +01:00 |
|
Florian Roth
|
51bbe21c70
|
fix: more Aurora FP fixes
|
2022-02-16 17:16:50 +01:00 |
|
Florian Roth
|
2500c16aea
|
fix: FPs noticed with Aurora
|
2022-02-16 17:00:27 +01:00 |
|
Florian Roth
|
ab3f1f6e7d
|
refactor: extend values - sam rule
|
2022-02-16 16:59:32 +01:00 |
|
phantinuss
|
9fce5735ad
|
fix: remove unneded escape for "
|
2022-02-16 16:31:13 +01:00 |
|
phantinuss
|
c92b5e8835
|
fix: known FP
|
2022-02-16 16:31:13 +01:00 |
|
phantinuss
|
27e4c333d6
|
fix: filter MS Office
|
2022-02-16 16:31:13 +01:00 |
|
phantinuss
|
ebc27d7c9f
|
fix: exclude cutepdf writer
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
6816f32c93
|
fix: remove trailing \
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
3207f3ff47
|
fix: filter known software
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
5a03d8d5ac
|
fix: filter known software
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
e2f80e5aa8
|
fix: exclude msiexec from SysWOW64
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
3e254fe3e4
|
fix: exclude known office addins
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
cc6613a799
|
fix: filter MS Office and Dropbox
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
741640cb10
|
fix: filter known extensions and toolbar entries
|
2022-02-16 16:31:12 +01:00 |
|
phantinuss
|
ac8cd7516a
|
fix: single list items
|
2022-02-16 16:31:11 +01:00 |
|
phantinuss
|
7b8ea16ca3
|
fix: single list item
|
2022-02-16 16:31:11 +01:00 |
|
phantinuss
|
5aee70f7d5
|
fix: exclude common FPs occuring on test system
|
2022-02-16 16:31:11 +01:00 |
|
phantinuss
|
12fffc5fd5
|
fix: more chocolatey FPs
|
2022-02-16 16:31:11 +01:00 |
|
phantinuss
|
96bf7421fc
|
fix: reworked rule and added more FP filters
|
2022-02-16 16:31:11 +01:00 |
|
Florian Roth
|
93be74b2fb
|
Merge pull request #2699 from phantinuss/checkbaseline
Fix FPs (Example Installation 4)
|
2022-02-15 20:07:49 +01:00 |
|
frack113
|
ac136f3e17
|
Merge pull request #2676 from redsand/fp_allow_dynatrace_behavior
Filtering fp of dynatrace behavior
|
2022-02-15 19:41:48 +01:00 |
|
frack113
|
98975ef50e
|
add win_pc_cmd_dosfuscation
|
2022-02-15 17:58:39 +01:00 |
|
phantinuss
|
c7d270956c
|
fix: several FPs against a fresh installed Windows with example applications and basic user interaction 4
|
2022-02-15 16:40:04 +01:00 |
|
frack113
|
ce8cdf24ec
|
Aurora FP
|
2022-02-14 18:08:51 +01:00 |
|
frack113
|
b632b6bda0
|
Fix invalid logsource
|
2022-02-14 06:48:22 +01:00 |
|
frack113
|
171edbd1bc
|
Merge pull request #2694 from frack113/Red_20220213
Windows Redcannary
|
2022-02-14 06:34:20 +01:00 |
|
frack113
|
277d14f4ee
|
Merge pull request #2696 from frack113/thedfirreport_qbot
Missing Qbot rules
|
2022-02-14 06:34:09 +01:00 |
|
frack113
|
7f15b7a802
|
Missing Qbot rules
|
2022-02-13 16:07:28 +01:00 |
|
frack113
|
82e08de42c
|
Merge pull request #2693 from wagga40/master
Correct a typo in rule name
|
2022-02-13 16:00:40 +01:00 |
|
wagga40
|
fceb2c0de1
|
Correct bad commit
|
2022-02-13 13:34:28 +01:00 |
|
Florian Roth
|
e49c142e08
|
Merge pull request #2695 from frack113/aurora_fp
Aurora Office FP
|
2022-02-13 12:34:40 +01:00 |
|
frack113
|
ce0a5033f8
|
Aurora Office FP
|
2022-02-13 11:29:52 +01:00 |
|
Florian Roth
|
22f23b654a
|
fix: FPs noticed with Aurora
|
2022-02-13 11:24:28 +01:00 |
|
Florian Roth
|
1b7cc9b35a
|
Merge pull request #2691 from frack113/red_20220212
Windows Redcannary
|
2022-02-13 11:23:20 +01:00 |
|
frack113
|
f288134b41
|
Windows Redcannary
|
2022-02-13 11:04:00 +01:00 |
|
wagga40
|
c840c1a7f7
|
Correct a typo in rule name
|
2022-02-13 09:34:43 +01:00 |
|
frack113
|
e61c9e4b2e
|
Merge pull request #2690 from frack113/susp_temp_exe
add win_pc_susp_run_folder
|
2022-02-13 09:04:16 +01:00 |
|
frack113
|
7e3c088165
|
Windows Redcannary
|
2022-02-12 15:53:13 +01:00 |
|
Florian Roth
|
0feefdc751
|
Update win_pc_susp_run_folder.yml
|
2022-02-12 10:17:27 +01:00 |
|
Florian Roth
|
98dbfe1ff6
|
fix: too many matches on many programs
... running from every other locations
|
2022-02-12 00:44:42 +01:00 |
|