Commit Graph

10511 Commits

Author SHA1 Message Date
Florian Roth 11c216629b fix: thor sources for applocker with wrong prefix 2021-01-07 12:27:37 +01:00
GlebSukhodolskiy da5ec4e952 Update win_wmi_persistence.yml
Removed sequence of EIDs in Windows Security section.
2021-01-06 16:50:28 +03:00
yugoslavskiy 05c91cd12f Merge pull request #1238 from alx1m1k/oscd-3
[OSCD] T1030: Split A File Into Pieces - Lin/macOS
2021-01-06 00:33:12 +03:00
yugoslavskiy 057c33354a Merge pull request #1237 from alx1m1k/oscd-2
[OSCD] T1027.001: Binary Padding - Lin/macOS
2021-01-06 00:33:05 +03:00
yugoslavskiy befcad2df7 Merge pull request #1234 from w0rk3r/oscd1
[OSCD] Update win_susp_replace_lolbin.yml
2021-01-06 00:32:55 +03:00
yugoslavskiy 6ebcb10abd Merge pull request #1233 from V3T0/v3t0_oscd_lolbas_runonce_susp_execution
[OSCD] Added a rule to detect execution of runonce with suspicious parameters
2021-01-06 00:32:44 +03:00
yugoslavskiy 3bf1663503 Merge pull request #1232 from V3T0/v3t0_oscd_lolbas_tracker
[OSCD] Added a rule to detect the execution of tracker.exe with suspicious arguments
2021-01-06 00:32:35 +03:00
yugoslavskiy e4c302bf6f Merge pull request #1231 from vburov/patch-16
[OSCD] Detects LockerGoga Ransomware command line.
2021-01-06 00:30:08 +03:00
yugoslavskiy 2985836e36 Merge pull request #1140 from omkar72/oscd-5
[OSCD] adding shortened commands for Netsh in the existing rule
2021-01-06 00:24:43 +03:00
yugoslavskiy d25ca9b280 Merge pull request #1229 from zinint/1009-19-1
[OSCD] Detects Obfuscated Powershell via COMPRESS OBFUSCATION #19 (4104, 4103 + Services + process_creation)
2021-01-06 00:24:08 +03:00
yugoslavskiy 7889df6644 Merge pull request #1227 from stvetro/oscd-runscripthelper
[OSCD] - Runscripthelper.exe runs script (LoLBin)
2021-01-06 00:24:00 +03:00
yugoslavskiy 0ed153237e Merge pull request #1226 from stvetro/oscd-winword
[OSCD] - Force winword.exe to load DLL (LoLBin)
2021-01-06 00:23:52 +03:00
yugoslavskiy 1d2f027035 Merge pull request #1224 from stvetro/oscd
[OSCD] Verclsid.exe Runs COM Object (LOLBin)
2021-01-06 00:23:45 +03:00
yugoslavskiy f4578b0698 Merge pull request #1223 from zinint/1009-23-1
[OSCD] Detects Obfuscated Powershell via RUNDLL Launcher #23 (4104, 4103 + Services + process_creation)
2021-01-06 00:23:33 +03:00
yugoslavskiy 23519e47cd Merge pull request #1222 from feedb/oscd
[OSCD] zer0w
2021-01-06 00:23:25 +03:00
yugoslavskiy 93718975fb Merge pull request #1221 from grikos/OSCD_117_128
[OSCD] suspicious csi.exe (rcsi.exe)  LOLBAS detection rule
2021-01-06 00:23:13 +03:00
yugoslavskiy cd62929bb0 Merge pull request #1220 from aw350m33d/PS_exec_via_redirected_input_stream
[OSCD] LOLBIN 5 PowerShell with redirection of the input stream.
2021-01-06 00:23:06 +03:00
yugoslavskiy 70eff4b1fc Merge pull request #1219 from ryanplasma/rplas-SIGMA-547-page-37
[OSCD] Add Files Dropped to Program Files by Non-Priviledged Process Rule
2021-01-06 00:22:57 +03:00
yugoslavskiy a5bbccf16c Merge pull request #1214 from tas-kmanager/mt-oscd-sigma547-48-alternative
[OSCD] Always Install Elevated Alternative
2021-01-06 00:22:37 +03:00
yugoslavskiy a217a3cfc7 Merge pull request #1213 from alx1m1k/oscd
[OSCD] T1552.003: Suspicious history file operations - Linux/macOS
2021-01-06 00:21:19 +03:00
yugoslavskiy 066be03c19 Merge pull request #1212 from aleqs4ndr/oscd-2020
[OSCD] Added a rule to detect possible Zerologon exploitation
2021-01-06 00:21:12 +03:00
yugoslavskiy 29fe6e46d8 Merge pull request #1211 from zipa-original/win_persistence_telemetry
[OSCD] Added a rule to detect abusing windows telemetry for persistence
2021-01-06 00:20:51 +03:00
yugoslavskiy c71e0ae0ea Merge pull request #1209 from vburov/patch-15
[OSCD] Create win_susp_multiple_files_renamed_or_deleted.yml
2021-01-06 00:19:41 +03:00
yugoslavskiy 38661bbc10 Merge pull request #1208 from NikitaStormwind/RTT(17)
[OSCD] Atomic Red Team: Detected Windows Software Discovery (T1518)
2021-01-06 00:19:20 +03:00
yugoslavskiy 2cf1994763 Merge pull request #1206 from w0rk3r/oscd5
[OSCD] Windows - Suspicious Service DACL Modification
2021-01-06 00:18:53 +03:00
yugoslavskiy aad2838f58 Merge pull request #1198 from tas-kmanager/mt-oscd-sigma547-50-rule2
[OSCD] Always Install Elevated - Slide 50 - Rule 2
2021-01-06 00:18:44 +03:00
yugoslavskiy e0286abb62 Merge pull request #1197 from w0rk3r/oscd_rules_improvement2
[OSCD] Small improvements on others rules
2021-01-06 00:18:36 +03:00
yugoslavskiy 0b7babaa84 Merge pull request #1196 from tas-kmanager/mt-oscd-sigma547-50-rule1
[OSCD] Always Install Elevated - Slide 50 - Rule 1
2021-01-06 00:18:26 +03:00
yugoslavskiy fc1fa23440 Merge pull request #1191 from vburov/patch-14
[OSCD] Create powershell_cmdline_special_characters.yml
2021-01-06 00:18:12 +03:00
yugoslavskiy 8e50eeb4a9 Merge pull request #1187 from nsaddler/lolbas108
[OSCD] LOLBAS Manage-bde.yml
2021-01-06 00:18:02 +03:00
yugoslavskiy cfbd10ab8b Merge pull request #1186 from nsaddler/lolbas107_2
[OSCD] LOLBAS CL_Mutexverifiers - powershell
2021-01-06 00:17:54 +03:00
yugoslavskiy e91d48cc93 Merge pull request #1185 from nsaddler/lolbas107_1
[OSCD] LOLBAS CL_Mutexverifiers - process_creation
2021-01-06 00:17:46 +03:00
yugoslavskiy 9d1c695204 Merge pull request #1184 from nsaddler/lolbas106_1
[OSCD] LOLBAS CL_Invocation - powershell
2021-01-06 00:17:10 +03:00
yugoslavskiy def4a7dbb9 Merge pull request #1183 from nsaddler/lolbas106
[OSCD] LOLBAS CL_Invocation - process_creation
2021-01-06 00:17:01 +03:00
yugoslavskiy 6f2e8c56b2 Merge pull request #1182 from nsaddler/lolbas80
[OSCD] LOLBAS wab.yml
2021-01-06 00:16:53 +03:00
yugoslavskiy e1fd69f548 Merge pull request #1179 from SanWieb/OSCD_regedit_3
[OSCD] regedit.exe LOLbas 72 [3]
2021-01-06 00:16:45 +03:00
yugoslavskiy 8e6b77fc4f Merge pull request #1177 from OpalSec/oscd
[OSCD] Tasks 24, 25 & 26: Detection for Invoke-Obfuscation CLIP+, STDIN+ & VAR+ Launchers
2021-01-06 00:16:34 +03:00
yugoslavskiy 95d8a9daf0 Merge pull request #1174 from uncleAntik/update
[OSCD] LOLBin vsjitdebugger.exe #136
2021-01-06 00:16:20 +03:00
yugoslavskiy 252345ca00 Merge pull request #1173 from uncleAntik/fix
[OSCD] LOLBin te.exe #133
2021-01-06 00:16:12 +03:00
yugoslavskiy aeb448cd4d Merge pull request #1171 from alejandroortuno/network-sniffing
[OSCD] MacOS Network Sniffing
2021-01-06 00:15:52 +03:00
yugoslavskiy ebc6451b86 Merge pull request #1170 from alejandroortuno/startup-items
[OSCD] MacOS Startup Items
2021-01-06 00:15:45 +03:00
yugoslavskiy ad739f7f29 Merge pull request #1169 from remotephone/oscd_t1113
[OSCD] - T1113 - macOS Screencapture via builtin screencapture utility
2021-01-06 00:15:37 +03:00
yugoslavskiy d50c081f3f Merge pull request #1168 from remotephone/oscd_t1056_002
[OSCD] macOS - T1056.002 - GUI Input capture
2021-01-06 00:15:30 +03:00
yugoslavskiy 1fd0afc58e Merge pull request #1167 from tas-kmanager/mt-oscd-sigma547-43
[OSCD] Add Accesschk tool usage rule
2021-01-06 00:14:08 +03:00
yugoslavskiy 5ade9208d5 Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
2021-01-06 00:12:34 +03:00
yugoslavskiy 5ec4e42569 Merge pull request #1165 from w0rk3r/oscd3
[OSCD] Updated win_etw_trace_evasion - Added new detections, Removed reference to deprecated rule and changed selections
2021-01-06 00:12:22 +03:00
yugoslavskiy 46eb01f3c5 Merge pull request #1164 from GlebSukhodolskiy/oscd_reg
[OSCD] Modified Rule "Autorun Keys Modification"
2021-01-06 00:11:58 +03:00
yugoslavskiy 4c8e0b201d Merge pull request #1162 from uncleAntik/131
[OSCD] LOLBin sqltoolsps.exe #131
2021-01-06 00:11:33 +03:00
yugoslavskiy b56a7181ce Merge pull request #1157 from invrep-de/oscd
[OSCD] Bad Opsec Powershell Artifacts
2021-01-06 00:11:24 +03:00
yugoslavskiy 319ebd158c Merge pull request #1155 from sn0w0tter/oscd2
[OSCD] LOLBAS atbroker suspicious creation of ATs
2021-01-06 00:11:13 +03:00