Florian Roth
|
cbe7abc16e
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-02-21 18:49:45 +01:00 |
|
Florian Roth
|
921d46ca79
|
fix: FPs noticed with Aurora
|
2022-02-21 18:43:18 +01:00 |
|
Florian Roth
|
f1d962d140
|
Merge pull request #2717 from phantinuss/checkbaseline
New workflow action: Check sigma rules against baseline evtx files
|
2022-02-21 15:14:35 +01:00 |
|
Florian Roth
|
29dacbe6b6
|
Merge pull request #2716 from SigmaHQ/aurora-false-positive-fixing
Aurora and THOR false positive fixing
|
2022-02-21 14:46:31 +01:00 |
|
Rafael Teixeira
|
6ff13ddf68
|
Added root user files
|
2022-02-21 10:15:48 -03:00 |
|
phantinuss
|
df21201783
|
fix: FP
|
2022-02-21 11:09:20 +01:00 |
|
phantinuss
|
62949b0437
|
workflow: output cosmetics
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
3961774991
|
workflow: show error on sigma matches
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
fc8cf7d4a0
|
workflow: fix: missing . in path
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
a1c0c1c03d
|
workflow: add shebang to matchgrep.sh
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
2cecd0e6ef
|
workflow: rename steps
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
0c473a3e77
|
workflow: evaluate findings, exclude known FPs
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
20761d0332
|
workflow: link to latest release
|
2022-02-21 11:01:44 +01:00 |
|
phantinuss
|
48eefe29f7
|
workflow: verbose remove of deprecated rules
|
2022-02-21 11:01:43 +01:00 |
|
phantinuss
|
00f1f561dd
|
workflow: fix: missing -l grep flag
|
2022-02-21 11:01:43 +01:00 |
|
phantinuss
|
d3397929b4
|
workflow: fix: quote command with pipe
|
2022-02-21 11:01:43 +01:00 |
|
phantinuss
|
e6fe8fdedd
|
workflow: execute evtx-sigma-checker
|
2022-02-21 11:01:43 +01:00 |
|
Florian Roth
|
cfd5847063
|
Schtasks creation rule
|
2022-02-21 11:01:27 +01:00 |
|
Florian Roth
|
6ce58d7201
|
refactor: removed unnecessary regex
|
2022-02-21 11:01:18 +01:00 |
|
Florian Roth
|
d4327d2629
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-02-21 10:15:31 +01:00 |
|
Florian Roth
|
35d4c8bc69
|
fix: FPs noticed in THOR testing
|
2022-02-21 10:15:27 +01:00 |
|
frack113
|
fa083b5008
|
Merge pull request #2713 from frack113/tor
Simple TOR rules
|
2022-02-21 06:27:38 +01:00 |
|
frack113
|
2a0aa9a24b
|
Merge pull request #2711 from frack113/file_rename
add file_rename_win_not_dll_to_dll
|
2022-02-21 06:27:24 +01:00 |
|
frack113
|
15e659fed8
|
Rename win_etw_rename_to_dll.yml to file_rename_win_not_dll_to_dll.yml
|
2022-02-20 18:59:08 +01:00 |
|
frack113
|
4d8cbe89b7
|
Merge pull request #2714 from frack113/fix_reg_fp
Fix FP binary
|
2022-02-20 18:00:13 +01:00 |
|
frack113
|
dcf936bb6c
|
Rename win_pc_tor_browser.yml to proc_creation_win_tor_browser.yml
|
2022-02-20 17:59:53 +01:00 |
|
Florian Roth
|
dff806c5bc
|
changed description, fix: onion TLD position of '.'
|
2022-02-20 12:17:12 +01:00 |
|
Florian Roth
|
e7bf14c6dc
|
description and title
|
2022-02-20 12:14:57 +01:00 |
|
Florian Roth
|
505734730d
|
increased level
|
2022-02-20 12:14:14 +01:00 |
|
Florian Roth
|
d3c0d90ba7
|
increased level
|
2022-02-20 12:14:05 +01:00 |
|
frack113
|
470ca979b4
|
Fix FP binary
|
2022-02-20 11:31:08 +01:00 |
|
frack113
|
82660bbaf2
|
Simple TOR rules
|
2022-02-20 11:26:13 +01:00 |
|
frack113
|
604600ac2f
|
Merge pull request #2709 from frack113/fix_aurora_fp
Fix FP for win_pc_susp_run_folder
|
2022-02-20 09:05:17 +01:00 |
|
frack113
|
ec7af1fcaa
|
add win_etw_rename_to_dll
|
2022-02-19 18:30:14 +01:00 |
|
frack113
|
631a300236
|
Fix some FP
|
2022-02-19 10:25:26 +01:00 |
|
frack113
|
8cfab22acb
|
Add firewall-as basic rules
|
2022-02-19 10:18:49 +01:00 |
|
frack113
|
fde2e7b61e
|
Merge pull request #2706 from phantinuss/master
Fix FPs
|
2022-02-19 08:09:40 +01:00 |
|
phantinuss
|
f2be1ed1b8
|
fix: FPs
|
2022-02-18 13:04:25 +01:00 |
|
Florian Roth
|
1196387e90
|
fix: FPs noticed with Aurora
|
2022-02-18 12:53:17 +01:00 |
|
frack113
|
cabe5c5043
|
Merge pull request #2703 from frack113/lolbin
add win_pc_lolbin_wlrmdr
|
2022-02-17 19:26:19 +01:00 |
|
Florian Roth
|
e0d8f59f42
|
Update win_pc_lolbin_wlrmdr.yml
|
2022-02-17 16:24:52 +01:00 |
|
Florian Roth
|
cf1d3aad08
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-02-17 13:02:22 +01:00 |
|
Florian Roth
|
05763aea3f
|
docs: level adjusted
|
2022-02-17 13:02:18 +01:00 |
|
Florian Roth
|
dba4a43ef9
|
Merge pull request #2702 from SigmaHQ/aurora-false-positive-fixing
Aurora false positive fixing
|
2022-02-17 13:02:07 +01:00 |
|
Florian Roth
|
5deb9af698
|
Update sysmon_reg_office_security.yml
|
2022-02-17 08:15:25 +01:00 |
|
Florian Roth
|
283475e064
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-02-17 08:13:38 +01:00 |
|
frack113
|
1a76bb82d6
|
Merge pull request #2700 from frack113/DOSfuscation
add win_pc_cmd_dosfuscation
|
2022-02-17 06:32:45 +01:00 |
|
frack113
|
3b02967ffb
|
add win_pc_lolbin_wlrmdr
|
2022-02-16 19:53:46 +01:00 |
|
Florian Roth
|
50efc894bc
|
add common "set" expressions
add common caret obfuscated "set" expressions often found in Invoke-Obfuscation code
|
2022-02-16 17:33:33 +01:00 |
|
Florian Roth
|
8850de3a2e
|
exclude values that could be prone to FPs
Sorry, I have to disable some of the values. I guess these values would make the rule trigger many false positives.
|
2022-02-16 17:31:52 +01:00 |
|