yugoslavskiy
|
d2087c276c
|
Merge pull request #1151 from zinint/1009-27-2
[OSCD] Detects Obfuscated Powershell via VAR++ Launcher #27 (Services)
|
2021-01-06 00:10:55 +03:00 |
|
yugoslavskiy
|
0bd955f097
|
Merge branch 'oscd' into oscd-5
|
2021-01-06 00:09:47 +03:00 |
|
yugoslavskiy
|
1f0d081c01
|
Merge pull request #1144 from NikitaStormwind/regular28(3)
[OSCD] Detects Obfuscated Powershell via Stdin in Scripts #28 (Services)
|
2021-01-05 23:23:00 +03:00 |
|
yugoslavskiy
|
1cfc0d17ef
|
Merge pull request #1141 from omkar72/oscd-6
[OSCD] suspicious clr logs creation
|
2021-01-05 23:22:36 +03:00 |
|
yugoslavskiy
|
82e5d031b0
|
Merge pull request #1139 from omkar72/oscd-4
[OSCD] script applications loading .net dll
|
2021-01-05 23:17:25 +03:00 |
|
yugoslavskiy
|
635ac44949
|
Merge pull request #1132 from remotephone/oscd_t1070_002
[OSCD] Adding t1070_002 - Clear mac system logs
|
2021-01-05 23:16:57 +03:00 |
|
yugoslavskiy
|
793d271d37
|
Merge pull request #1131 from oscd-initiative/oscd_sigma_art_macos_task_63
[OSCD] macOS hidden user creation
|
2021-01-05 23:16:36 +03:00 |
|
yugoslavskiy
|
a82c559816
|
Merge pull request #1130 from vburov/patch-13
[OSCD] Create powershell_cmdline_specific_encoded_methods.yml
|
2021-01-05 23:16:24 +03:00 |
|
yugoslavskiy
|
dd7a95ac74
|
Merge pull request #1081 from cy1337/patch-1
[OSCD] Added nltest LOLBIN
|
2021-01-05 23:16:14 +03:00 |
|
yugoslavskiy
|
a4101a6808
|
Merge pull request #1128 from alejandroortuno/local-group
[OSCD] Local System Groups Discovery
|
2021-01-05 23:14:47 +03:00 |
|
yugoslavskiy
|
db66f8365e
|
Merge pull request #1127 from alejandroortuno/account-creation
[OSCD] MacOS local account creation
|
2021-01-05 23:14:28 +03:00 |
|
yugoslavskiy
|
f2c6011c6b
|
Merge pull request #1126 from skirankumar/master
[OSCD]Sysmon_silenttrinity_stager_msbuild_activity.yml
|
2021-01-05 23:14:20 +03:00 |
|
yugoslavskiy
|
1c1c38e091
|
Merge pull request #1119 from uncleAntik/oscd
[OSCD] sqlps.exe LOLbin
|
2021-01-05 23:14:02 +03:00 |
|
yugoslavskiy
|
07ac09f9aa
|
Merge pull request #1114 from NikitaStormwind/regular29(3)
[OSCD] Detects Obfuscated Powershell via use Clip.exe in Scripts #29 (Services)
|
2021-01-05 23:13:48 +03:00 |
|
yugoslavskiy
|
220a4873c7
|
Merge pull request #1109 from NikitaStormwind/regular31(3)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (Services)
|
2021-01-05 23:13:38 +03:00 |
|
yugoslavskiy
|
9803dc8baa
|
Merge pull request #1108 from NikitaStormwind/regular30(3)
[OSCD] Detects Obfuscated Powershell via use Rundll32 in Scripts #30 (Services)
|
2021-01-05 23:13:27 +03:00 |
|
yugoslavskiy
|
39991a8ab6
|
Merge pull request #1106 from stvetro/2020
[OSCD] Suspicious ftp.exe usage (LOLBin)
|
2021-01-05 23:13:03 +03:00 |
|
yugoslavskiy
|
804db42b7a
|
Merge pull request #1105 from Vasilisa-L/OSCD_rasautou
[OSCD] Rasautou.exe LOLbin
|
2021-01-05 23:12:48 +03:00 |
|
yugoslavskiy
|
794cd7aaeb
|
Merge pull request #1104 from Vasilisa-L/OSCD_rpcping
[OSCD] rpcping lolbin
|
2021-01-05 23:12:35 +03:00 |
|
yugoslavskiy
|
05b03afddb
|
Merge pull request #1103 from concorde18/oscd_win_susp_diskshadow
[OSCD] win_susp_diskshadow
|
2021-01-05 23:10:55 +03:00 |
|
yugoslavskiy
|
d48bac226f
|
Merge pull request #1099 from NikitaStormwind/regular31(2)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (process_creation)
|
2021-01-05 23:10:46 +03:00 |
|
yugoslavskiy
|
32aea9ad2b
|
Merge pull request #1098 from NikitaStormwind/regular31
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (4104, 4103)
|
2021-01-05 23:10:28 +03:00 |
|
yugoslavskiy
|
ae3c0d0801
|
Merge pull request #1095 from esebese/task136
[OSCD]win_pe_exec_vsjitdebugger.yml added
|
2021-01-05 23:10:18 +03:00 |
|
yugoslavskiy
|
e492263a31
|
Merge pull request #1091 from alejandroortuno/sigma-local-account-rule
[OSCD] Local System Accounts Discovery
|
2021-01-05 23:10:09 +03:00 |
|
yugoslavskiy
|
d9a0f6c41a
|
Merge pull request #1090 from alejandroortuno/sigma-cron-rule
[OSCD] Scheduled Task/Job: Cron
|
2021-01-05 23:09:59 +03:00 |
|
yugoslavskiy
|
aa9182593a
|
Merge pull request #1087 from Vasilisa-L/OSCD_pester.bat
[OSCD] 109: Pester.bat
|
2021-01-05 23:09:47 +03:00 |
|
yugoslavskiy
|
c8da05fa5d
|
Merge pull request #1086 from remotephone/oscd
[OSCD] T1016 - linux/macOS firewall enumeration
|
2021-01-05 23:09:15 +03:00 |
|
yugoslavskiy
|
caf01c57bf
|
Merge pull request #1083 from omergunal/patch-8
[OSCD] T1082: System Information Discovery - Linux
|
2021-01-05 23:08:19 +03:00 |
|
yugoslavskiy
|
1992b1ac9f
|
Merge pull request #1074 from semanurguneysu/oscd
[OSCD] Create sysmon_abusing_debug_privilege.yml
|
2021-01-05 23:06:57 +03:00 |
|
yugoslavskiy
|
b5c78212ad
|
Merge pull request #1076 from nsaddler/oscd5
[OSCD] Powershell without powershell.exe Rule Added
|
2021-01-05 23:06:37 +03:00 |
|
yugoslavskiy
|
c7e9522f29
|
Merge pull request #1077 from uchakin/oscd
[OSCD] UAC bypass added
|
2021-01-05 23:06:24 +03:00 |
|
yugoslavskiy
|
e002ffa404
|
Merge pull request #1079 from omergunal/patch-6
[OSCD] T1070.004: File Deletion - Linux
|
2021-01-05 23:06:12 +03:00 |
|
yugoslavskiy
|
1939b815d6
|
Merge pull request #1078 from omergunal/patch-5
[OSCD] T1070.002: Clear Linux or Mac System Logs - Linux
|
2021-01-05 23:06:02 +03:00 |
|
yugoslavskiy
|
ff373b0f33
|
Update win_nltest_query.yml
|
2021-01-05 23:03:41 +03:00 |
|
yugoslavskiy
|
75feffb016
|
Merge pull request #1082 from omergunal/patch-7
[OSCD] T1201: Password Policy Discovery - Linux
|
2021-01-05 23:02:06 +03:00 |
|
yugoslavskiy
|
bceb3c8af0
|
Merge pull request #1047 from grikos/sigma/oscd
[OSCD] Registry modify via VBoxDrvInst
|
2021-01-05 23:00:20 +03:00 |
|
yugoslavskiy
|
3ef76437e4
|
Merge pull request #1055 from omergunal/patch-2
[OSCD] Scheduled Task/Job: At
|
2021-01-05 22:59:09 +03:00 |
|
yugoslavskiy
|
f65e7100ec
|
Merge pull request #1057 from omergunal/patch-4
[OSCD] T1057: Process Discovery
|
2021-01-05 22:58:35 +03:00 |
|
yugoslavskiy
|
87e5e5a7fc
|
Merge pull request #1069 from nsaddler/oscd3
[OSCD] Powershell Script Installed as a Service Rule added
|
2021-01-05 22:58:21 +03:00 |
|
yugoslavskiy
|
738bb4af90
|
Merge pull request #1041 from ryanplasma/rplas-SIGMA-547-page-13
[OSCD] Add Stored Credentials in Fake Files rule
|
2021-01-05 22:57:36 +03:00 |
|
yugoslavskiy
|
57947fbd39
|
Merge pull request #1044 from omergunal/patch-1
[OSCD] Linux - Install Root Certificate
|
2021-01-05 22:56:18 +03:00 |
|
yugoslavskiy
|
733277d490
|
Merge pull request #1248 from oscd-initiative/oscd_art_macos_task_28_T1083
[OSCD] ART sync, test T1083: File and Directory Discovery (macOS)
|
2021-01-05 22:55:40 +03:00 |
|
yugoslavskiy
|
f825003690
|
Merge pull request #1239 from alx1m1k/oscd-4
[OSCD] T1529: System Shutdown/Reboot - Lin/macOS
|
2021-01-05 22:55:14 +03:00 |
|
Dennis Potashnik
|
70d14b46ef
|
Aligning with newer stix-shifter version
|
2021-01-05 15:13:36 +02:00 |
|
Florian Roth
|
40e0e3bc99
|
Merge pull request #1193 from w0rk3r/oscd_rules_improvement
[OSCD] Windows Rules - Review for improvements on selections and logic
|
2020-12-31 12:10:15 +01:00 |
|
Thomas Patzke
|
789dfb3f47
|
Merge pull request #1291 from lprat/fix_issue_1285
fix issue 1285
|
2020-12-30 23:06:38 +01:00 |
|
Thomas Patzke
|
9b4c1662b0
|
Merge pull request #1240 from alx1m1k/oscd-5
[OSCD] T1070.006: File Time Attribute Change - Lin/macOS
|
2020-12-30 23:00:54 +01:00 |
|
Thomas Patzke
|
1dcc56a0b0
|
Merge pull request #1241 from alx1m1k/oscd-6
[OSCD] T1552.001: Credentials In Files - Lin/macOS
|
2020-12-30 22:59:49 +01:00 |
|
Thomas Patzke
|
e0f7dc125c
|
Merge pull request #1244 from oscd-initiative/oscd_art_macos_task_3_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (macOS)
|
2020-12-30 22:58:26 +01:00 |
|
Thomas Patzke
|
810485993a
|
Merge pull request #1245 from oscd-initiative/oscd_art_linux_task_4_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (Linux)
|
2020-12-30 22:57:59 +01:00 |
|