yugoslavskiy
|
d48bac226f
|
Merge pull request #1099 from NikitaStormwind/regular31(2)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (process_creation)
|
2021-01-05 23:10:46 +03:00 |
|
yugoslavskiy
|
32aea9ad2b
|
Merge pull request #1098 from NikitaStormwind/regular31
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (4104, 4103)
|
2021-01-05 23:10:28 +03:00 |
|
yugoslavskiy
|
ae3c0d0801
|
Merge pull request #1095 from esebese/task136
[OSCD]win_pe_exec_vsjitdebugger.yml added
|
2021-01-05 23:10:18 +03:00 |
|
yugoslavskiy
|
e492263a31
|
Merge pull request #1091 from alejandroortuno/sigma-local-account-rule
[OSCD] Local System Accounts Discovery
|
2021-01-05 23:10:09 +03:00 |
|
yugoslavskiy
|
d9a0f6c41a
|
Merge pull request #1090 from alejandroortuno/sigma-cron-rule
[OSCD] Scheduled Task/Job: Cron
|
2021-01-05 23:09:59 +03:00 |
|
yugoslavskiy
|
aa9182593a
|
Merge pull request #1087 from Vasilisa-L/OSCD_pester.bat
[OSCD] 109: Pester.bat
|
2021-01-05 23:09:47 +03:00 |
|
yugoslavskiy
|
c8da05fa5d
|
Merge pull request #1086 from remotephone/oscd
[OSCD] T1016 - linux/macOS firewall enumeration
|
2021-01-05 23:09:15 +03:00 |
|
yugoslavskiy
|
caf01c57bf
|
Merge pull request #1083 from omergunal/patch-8
[OSCD] T1082: System Information Discovery - Linux
|
2021-01-05 23:08:19 +03:00 |
|
yugoslavskiy
|
1992b1ac9f
|
Merge pull request #1074 from semanurguneysu/oscd
[OSCD] Create sysmon_abusing_debug_privilege.yml
|
2021-01-05 23:06:57 +03:00 |
|
yugoslavskiy
|
b5c78212ad
|
Merge pull request #1076 from nsaddler/oscd5
[OSCD] Powershell without powershell.exe Rule Added
|
2021-01-05 23:06:37 +03:00 |
|
yugoslavskiy
|
c7e9522f29
|
Merge pull request #1077 from uchakin/oscd
[OSCD] UAC bypass added
|
2021-01-05 23:06:24 +03:00 |
|
yugoslavskiy
|
e002ffa404
|
Merge pull request #1079 from omergunal/patch-6
[OSCD] T1070.004: File Deletion - Linux
|
2021-01-05 23:06:12 +03:00 |
|
yugoslavskiy
|
1939b815d6
|
Merge pull request #1078 from omergunal/patch-5
[OSCD] T1070.002: Clear Linux or Mac System Logs - Linux
|
2021-01-05 23:06:02 +03:00 |
|
yugoslavskiy
|
ff373b0f33
|
Update win_nltest_query.yml
|
2021-01-05 23:03:41 +03:00 |
|
yugoslavskiy
|
75feffb016
|
Merge pull request #1082 from omergunal/patch-7
[OSCD] T1201: Password Policy Discovery - Linux
|
2021-01-05 23:02:06 +03:00 |
|
yugoslavskiy
|
bceb3c8af0
|
Merge pull request #1047 from grikos/sigma/oscd
[OSCD] Registry modify via VBoxDrvInst
|
2021-01-05 23:00:20 +03:00 |
|
yugoslavskiy
|
3ef76437e4
|
Merge pull request #1055 from omergunal/patch-2
[OSCD] Scheduled Task/Job: At
|
2021-01-05 22:59:09 +03:00 |
|
yugoslavskiy
|
f65e7100ec
|
Merge pull request #1057 from omergunal/patch-4
[OSCD] T1057: Process Discovery
|
2021-01-05 22:58:35 +03:00 |
|
yugoslavskiy
|
87e5e5a7fc
|
Merge pull request #1069 from nsaddler/oscd3
[OSCD] Powershell Script Installed as a Service Rule added
|
2021-01-05 22:58:21 +03:00 |
|
yugoslavskiy
|
57947fbd39
|
Merge pull request #1044 from omergunal/patch-1
[OSCD] Linux - Install Root Certificate
|
2021-01-05 22:56:18 +03:00 |
|
yugoslavskiy
|
733277d490
|
Merge pull request #1248 from oscd-initiative/oscd_art_macos_task_28_T1083
[OSCD] ART sync, test T1083: File and Directory Discovery (macOS)
|
2021-01-05 22:55:40 +03:00 |
|
yugoslavskiy
|
f825003690
|
Merge pull request #1239 from alx1m1k/oscd-4
[OSCD] T1529: System Shutdown/Reboot - Lin/macOS
|
2021-01-05 22:55:14 +03:00 |
|
Florian Roth
|
40e0e3bc99
|
Merge pull request #1193 from w0rk3r/oscd_rules_improvement
[OSCD] Windows Rules - Review for improvements on selections and logic
|
2020-12-31 12:10:15 +01:00 |
|
Thomas Patzke
|
9b4c1662b0
|
Merge pull request #1240 from alx1m1k/oscd-5
[OSCD] T1070.006: File Time Attribute Change - Lin/macOS
|
2020-12-30 23:00:54 +01:00 |
|
Thomas Patzke
|
1dcc56a0b0
|
Merge pull request #1241 from alx1m1k/oscd-6
[OSCD] T1552.001: Credentials In Files - Lin/macOS
|
2020-12-30 22:59:49 +01:00 |
|
Thomas Patzke
|
e0f7dc125c
|
Merge pull request #1244 from oscd-initiative/oscd_art_macos_task_3_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (macOS)
|
2020-12-30 22:58:26 +01:00 |
|
Thomas Patzke
|
810485993a
|
Merge pull request #1245 from oscd-initiative/oscd_art_linux_task_4_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (Linux)
|
2020-12-30 22:57:59 +01:00 |
|
Thomas Patzke
|
aa5396cb9f
|
Merge pull request #1246 from oscd-initiative/oscd_art_macos_task_14_T1049
[OSCD] ART sync, test T1049: System Network Connections Discovery (macOS)
|
2020-12-30 22:57:29 +01:00 |
|
Thomas Patzke
|
fb9698345b
|
Merge pull request #1247 from oscd-initiative/oscd_art_linux_task_8__T1049
[OSCD] ART sync, test T1049: System Network Connections Discovery (Linux)
|
2020-12-30 22:57:11 +01:00 |
|
Thomas Patzke
|
6a7991ee96
|
Merge pull request #1250 from oscd-initiative/oscd_art_macos_task_41_T1518.001
[OSCD] ART sync, test T1518.001: Security Software Discovery (macOS)
|
2020-12-30 22:41:18 +01:00 |
|
Thomas Patzke
|
a88c853237
|
Merge pull request #1251 from oscd-initiative/oscd_art_linux_task_26_T1518.001
[OSCD] ART sync, test T1518.001: Security Software Discovery (Linux)
|
2020-12-30 22:40:32 +01:00 |
|
Thomas Patzke
|
436fd37655
|
Merge pull request #1252 from oscd-initiative/oscd_art_macos_task_55_T1553.001
[OSCD] ART sync, test T1553.001: Gatekeeper Bypass (macOS)
|
2020-12-30 22:39:36 +01:00 |
|
Thomas Patzke
|
5de952d488
|
Merge pull request #1253 from oscd-initiative/oscd_art_macos_task_60_T1562.001
[OSCD] ART sync, test T1562.001: Disable or Modify Tools (macOS)
|
2020-12-30 22:39:15 +01:00 |
|
Thomas Patzke
|
e223d34a6e
|
Merge pull request #1257 from alejandroortuno/service-scanning
[OSCD] Network Service Scanning
|
2020-12-30 22:35:47 +01:00 |
|
Thomas Patzke
|
5c03c4d4ec
|
Merge pull request #1258 from alejandroortuno/applescript
[OSCD] MacOS Applescript
|
2020-12-30 22:31:30 +01:00 |
|
Thomas Patzke
|
06c168d9b2
|
Merge pull request #1259 from alejandroortuno/firewall
[OSCD] Firewall Disable (Linux)
|
2020-12-30 22:30:41 +01:00 |
|
Florian Roth
|
ab408750ac
|
Merge pull request #1314 from Neo23x0/rule-devel
rule: Lazarus activity
|
2020-12-30 13:27:38 +01:00 |
|
Florian Roth
|
9ecaeb715f
|
Merge pull request #1317 from rtkdmasse/fix-missing-product-mouse-lock
Fix missing product mouse lock
|
2020-12-30 13:27:20 +01:00 |
|
ZikyHD
|
8a6b182fee
|
Update win_susp_adfind.yml
|
2020-12-29 14:41:46 +01:00 |
|
ZikyHD
|
ece829bb25
|
Update win_susp_adfind.yml
Typo on field name
|
2020-12-29 14:40:36 +01:00 |
|
Florian Roth
|
0a83f91386
|
Merge pull request #1321 from d4rk-d4nph3/master
Fixed typo in file format
|
2020-12-28 09:13:48 +01:00 |
|
Bhabesh Rai
|
bf77c8266a
|
Fixed typo in file format
|
2020-12-28 11:46:02 +05:45 |
|
Florian Roth
|
896fc21911
|
Merge pull request #1320 from d4rk-d4nph3/master
Added rule for CVE-2020-10148 SolarWinds Orion API Authentication Bypass
|
2020-12-27 20:37:36 +01:00 |
|
Florian Roth
|
a6212a4490
|
style: some minor style changes
|
2020-12-27 20:06:19 +01:00 |
|
Bhabesh Rai
|
1cfad987b0
|
Added rule for CVE-2020-10148 SolarWinds Orion API Authentication Bypass
|
2020-12-27 17:34:49 +05:45 |
|
Florian Roth
|
43033ab874
|
Update win_susp_emotet_rudll32_execution.yml
|
2020-12-25 09:05:55 +01:00 |
|
Tran Trung Hieu
|
d551b88d5c
|
Edit title convention
|
2020-12-25 14:21:26 +07:00 |
|
Tran Trung Hieu
|
4297e68704
|
Detect Emotet DLL loading by looking rundll32.exe
|
2020-12-25 14:09:40 +07:00 |
|
Daniel Masse
|
fedda17231
|
Update the azure image_load rule to be a generic sysmon rule
|
2020-12-23 16:29:49 -05:00 |
|
Daniel Masse
|
bf539fd1fe
|
Revert "Fix bug changing the logsource service to category"
This reverts commit 0f51e53d0e.
|
2020-12-23 15:50:49 -05:00 |
|