Commit Graph

8897 Commits

Author SHA1 Message Date
Nasreddine Bencherchali f3171177d8 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-18 10:24:04 +01:00
Nasreddine Bencherchali 4682f3fb7a fix: broken title 2023-01-17 19:14:32 +01:00
Nasreddine Bencherchali 8f46f2f061 fix: fp in firewall rule 2023-01-17 19:07:30 +01:00
Nasreddine Bencherchali 1c0bf6e262 feat: update windows firewall rules 2023-01-17 19:01:37 +01:00
Nasreddine Bencherchali 1c340493c6 fix: broken logsource 2023-01-17 01:13:50 +01:00
Nasreddine Bencherchali 459ba25cce Merge branch 'nasbench-rule-devel' of https://github.com/nasbench/sigma into nasbench-rule-devel 2023-01-17 01:01:38 +01:00
Nasreddine Bencherchali b6e4c45ef0 Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2023-01-17 01:01:23 +01:00
Nasreddine Bencherchali 85fb255bc9 feat: new rules and updates 2023-01-17 01:00:44 +01:00
Nasreddine Bencherchali 3d77511102 fix: improve fp description slightly 2023-01-16 16:30:08 +01:00
phantinuss 99c5c46397 fix: FP found in testing 2023-01-16 15:38:52 +01:00
frack113 0625ceca36 Merge pull request #3926 from frack113/redcannary_20230115
Add redcannary rules
2023-01-16 12:26:27 +01:00
Nasreddine Bencherchali 679207b6c4 fix: update metadata 2023-01-16 11:15:45 +01:00
Nasreddine Bencherchali 09731e8547 fix: update modified date 2023-01-16 10:50:23 +01:00
jkb 391173c153 Correcting filepath parameter
According to Microsoft documentation, the parameter is -Filepath not -File-path. See: https://learn.microsoft.com/en-us/powershell/module/pki/import-certificate?view=windowsserver2022-ps
2023-01-16 10:46:02 +01:00
Nasreddine Bencherchali fd823045a9 fix: fp in msiexec rule 2023-01-16 10:28:15 +01:00
frack113 c3f285d945 Add redcannary rules 2023-01-15 12:01:11 +01:00
frack113 2b0b680775 Merge pull request #3925 from frack113/lsa-server
Microsoft-Windows-LSA
2023-01-13 18:24:43 +01:00
Nasreddine Bencherchali c7f1f52b7b fix: apply suggestions from code review 2023-01-13 18:19:32 +01:00
Nasreddine Bencherchali 9783297262 Merge pull request #3922 from frack113/redcannary_20230113
New rules based on Redcannary AtomicRedTeam 2023-01-13
2023-01-13 18:18:32 +01:00
Nasreddine Bencherchali 432710c47b fix: description 2023-01-13 18:01:10 +01:00
frack113 c6942cba65 Add lsa-server 2023-01-13 17:58:40 +01:00
frack113 deeac89f36 Add lsa-server 2023-01-13 17:56:02 +01:00
Nasreddine Bencherchali 8707345be7 fix: add related metadata 2023-01-13 17:21:21 +01:00
frack113 5d0b0f6663 Add more TaskName 2023-01-13 13:06:02 +01:00
frack113 80be90c331 Merge branch 'redcannary_20230113' of github.com:frack113/sigma into redcannary_20230113 2023-01-13 13:03:52 +01:00
frack113 a0cc836d0a Add filter 2023-01-13 13:03:30 +01:00
frack113 23620bc8aa Update proc_creation_win_lsa_disablerestrictedadmin.yml 2023-01-13 12:31:28 +01:00
frack113 1b11e29fef Move rules 2023-01-13 12:15:08 +01:00
frack113 e0434a3f2c Add redcannary rules 2023-01-13 12:11:38 +01:00
Florian Roth 29a61b8c70 Merge branch 'master' into rule-devel 2023-01-12 23:57:41 +01:00
Florian Roth df1870df1e add IOC for LocalPotato 2023-01-12 23:57:33 +01:00
frack113 0c61fffa82 Merge pull request #3915 from frack113/appxdeployment
Add appxdeployment-server rule by eventid
2023-01-12 18:53:32 +01:00
frack113 4708bc61c6 Update win_appxdeployment_server_applocker_block.yml 2023-01-12 18:47:14 +01:00
frack113 b85d87ddf3 Apply suggestions from code review
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2023-01-12 18:39:46 +01:00
Nasreddine Bencherchali e824131450 fix: add new ref 2023-01-12 18:37:35 +01:00
frack113 45d7d1cd30 Update win_software_restriction_policies_block.yml 2023-01-12 18:30:45 +01:00
frack113 1470c3ebce Update win_software_restriction_policies_block.yml 2023-01-12 18:30:07 +01:00
frack113 b0b8c8cba6 Add win_software_restriction_policies_block 2023-01-12 18:20:12 +01:00
frack113 6d85fcb2b3 Add rule by eventid 2023-01-12 17:56:14 +01:00
Nasreddine Bencherchali cd303fa0a4 Merge pull request #3877 from redsand/fp_library_alias_and_use_of_alias
feat: add defender cmdlet alias option
2023-01-12 17:28:39 +01:00
Nasreddine Bencherchali a3fa8e8a90 Merge pull request #3914 from redsand/fp_citrix_receiver
FP: citrix receiver storefront
2023-01-12 17:25:08 +01:00
Tim Shelton 09b3e43afc Removing filter specification in condition 2023-01-12 16:21:58 +00:00
redsand (Tim Shelton) 3007d98844 Merge branch 'SigmaHQ:master' into fp_library_alias_and_use_of_alias 2023-01-12 10:19:47 -06:00
redsand (Tim Shelton) 88308b713c Update rules/windows/powershell/powershell_script/posh_ps_tamper_defender.yml
whatever you guys want, im good with. i like @neo23x0 suggestion

Co-authored-by: Florian Roth <venom14@gmail.com>
2023-01-12 10:14:14 -06:00
Tim Shelton ae51f1c472 FP: citrix receiver storefront 2023-01-12 16:09:36 +00:00
Nasreddine Bencherchali a5df41cf39 fix: update title and description 2023-01-12 15:49:40 +01:00
Nasreddine Bencherchali 9a671e25d9 fix: add missing eid 400 2023-01-12 15:12:20 +01:00
Nasreddine Bencherchali 90c1e45d83 feat: add new reg variant of dev mode 2023-01-12 15:05:53 +01:00
Nasreddine Bencherchali e7a2e1c169 fix: remove version from name
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-12 10:37:34 +01:00
Nasreddine Bencherchali 0470f45246 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-01-12 10:36:13 +01:00