phantinuss
|
35b027ee1c
|
Merge pull request #4184 from swachchhanda000/master
Added new rule that identifies the creation of a scheduled job by usi…
|
2023-04-21 13:31:22 +02:00 |
|
Nasreddine Bencherchali
|
add0ac0d9f
|
fix: update structure and metadata
|
2023-04-21 11:38:13 +02:00 |
|
Nasreddine Bencherchali
|
95edf4c9d6
|
Merge pull request #4177 from pH-T/master
feat: new hktl related rules and pwsh cmdlet updates
|
2023-04-21 11:24:57 +02:00 |
|
Nasreddine Bencherchali
|
aa22c02039
|
chore: order list
|
2023-04-21 11:14:55 +02:00 |
|
Nasreddine Bencherchali
|
cb5d421c4a
|
feat: update pr related hktl rules
|
2023-04-21 11:06:03 +02:00 |
|
swachchhanda
|
39e39187f2
|
mend
Corrected the syntax
|
2023-04-20 19:05:19 +05:45 |
|
swachchhanda
|
9504a5a7a7
|
mend
removed system_integrity
|
2023-04-20 17:31:26 +05:45 |
|
swachchhanda
|
b3f97c676d
|
Added new rule that identifies the creation of a scheduled job by using an XML file without the extension of '.xml'.
|
2023-04-20 17:12:04 +05:45 |
|
phantinuss
|
a8a8710dd6
|
Merge pull request #4148 from swachchhanda000/master
Added support for another way of execution of netsh
|
2023-04-20 12:30:43 +02:00 |
|
phantinuss
|
e640d9efe8
|
fix: minor
|
2023-04-20 12:11:22 +02:00 |
|
swachchhanda000
|
6e6b570b45
|
Merge branch 'SigmaHQ:master' into master
|
2023-04-20 15:22:22 +05:45 |
|
phantinuss
|
7f056da95b
|
fix: FPs found in different environments
|
2023-04-20 09:48:47 +02:00 |
|
phantinuss
|
689ef52c66
|
fix: remove leading whitespace
there can be double quotes which is a common pattern when using the command flag
|
2023-04-20 09:47:29 +02:00 |
|
Florian Roth
|
220916f59c
|
Merge pull request #4178 from nasbench/nash-rule-dev
feat: new rules and updates
|
2023-04-19 16:39:45 +02:00 |
|
Nasreddine Bencherchali
|
497d856245
|
fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
|
2023-04-19 15:50:29 +02:00 |
|
phantinuss
|
c6c226420d
|
Merge pull request #4172 from angelovioletti/master
Create proc_creation_win_rundll32_ext_drive.yml
|
2023-04-19 14:45:24 +02:00 |
|
Nasreddine Bencherchali
|
e95aaa1e5d
|
fix: small updates
|
2023-04-19 12:38:38 +02:00 |
|
Nasreddine Bencherchali
|
15b36c6577
|
fix: broken selection
|
2023-04-18 22:52:40 +02:00 |
|
Nasreddine Bencherchali
|
c64b907b8b
|
fix: filter
|
2023-04-18 22:50:18 +02:00 |
|
Nasreddine Bencherchali
|
83e352c52e
|
fix: some errors
|
2023-04-18 22:47:11 +02:00 |
|
Nasreddine Bencherchali
|
61c8364c20
|
feat: add rules related to rogue rdp
|
2023-04-18 22:13:30 +02:00 |
|
Nasreddine Bencherchali
|
9a2ee48ef8
|
feat: update multiple rules
|
2023-04-18 18:08:08 +02:00 |
|
Nasreddine Bencherchali
|
032570a080
|
feat: more winget updates
|
2023-04-18 03:35:42 +02:00 |
|
Nasreddine Bencherchali
|
f2eba9d125
|
feat: update winget related rules
|
2023-04-17 18:24:01 +02:00 |
|
pH-T
|
45a3133cc6
|
Merge branch 'SigmaHQ:master' into master
|
2023-04-17 13:55:00 +02:00 |
|
Paul Hager
|
0420e9c3bb
|
feat: various new hktl rules
|
2023-04-17 12:08:30 +02:00 |
|
Qasim Qlf
|
52ca56335e
|
fix: image name
|
2023-04-14 20:44:27 +05:00 |
|
Florian Roth
|
836091e953
|
Merge pull request #4170 from nasbench/nash-rule-dev
feat: rule updates
|
2023-04-14 16:26:21 +02:00 |
|
Nasreddine Bencherchali
|
fa84af599a
|
fix: update filter
|
2023-04-14 12:00:22 +02:00 |
|
Nasreddine Bencherchali
|
1363db5ff3
|
fix: typos
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
|
2023-04-14 11:54:04 +02:00 |
|
Nasreddine Bencherchali
|
5f6614b273
|
feat: update hh.exe related rules
|
2023-04-12 16:12:33 +02:00 |
|
Nasreddine Bencherchali
|
bb7aabb4b4
|
chore: author update
|
2023-04-12 16:11:58 +02:00 |
|
Nasreddine Bencherchali
|
59a5db8eaf
|
fix: update selection naming
|
2023-04-12 14:48:36 +02:00 |
|
angelovioletti
|
663d2c5059
|
Delete proc_creation_win_rundll32_ext_drive.yml
|
2023-04-12 14:22:24 +02:00 |
|
angelovioletti
|
f71c1c5348
|
Update proc_creation_win_lolbin_not_from_c_drive.yml
|
2023-04-12 14:21:54 +02:00 |
|
angelovioletti
|
da519ba868
|
Update proc_creation_win_rundll32_ext_drive.yml
|
2023-04-12 09:16:48 +02:00 |
|
angelovioletti
|
c2643de61e
|
Add new rule proc_creation_win_rundll32_ext_drive.yml
Rule to detect the execution of rundll32.exe processes where the current directory is an external drive, based on an analysis of BumbleBee.
|
2023-04-12 09:15:05 +02:00 |
|
Nasreddine Bencherchali
|
e3f2b80121
|
feat: add new flags
|
2023-04-12 03:40:38 +02:00 |
|
Nasreddine Bencherchali
|
8835f8c6c9
|
fix: remove space in filename
|
2023-04-12 03:25:34 +02:00 |
|
Nasreddine Bencherchali
|
4f4a9356c8
|
fix: remove duplicate uuid
|
2023-04-12 03:11:21 +02:00 |
|
Nasreddine Bencherchali
|
be3a56566e
|
feat: add rule related to CVE-2023-21554
|
2023-04-12 03:11:03 +02:00 |
|
Nasreddine Bencherchali
|
e898abc019
|
feat: rule updates
|
2023-04-12 02:57:44 +02:00 |
|
Nasreddine Bencherchali
|
2710bf4710
|
feat: new rules, updates and fp fixes (#4162)
|
2023-04-11 13:04:22 +02:00 |
|
swachchhanda000
|
3785bb3f47
|
Update rules/windows/process_creation/proc_creation_win_netsh_port_forwarding.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-04-07 11:05:03 +05:45 |
|
swachchhanda000
|
4bf667780e
|
Update rules/windows/process_creation/proc_creation_win_netsh_port_forwarding.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
|
2023-04-07 11:04:53 +05:45 |
|
Mohamed Ashraf
|
a7e34f7b3f
|
feat: new rule related rorschach ransomware activity (#4159)
|
2023-04-04 14:59:25 +02:00 |
|
Nasreddine Bencherchali
|
3d9372bef3
|
feat: new rules, updates and fp fixes (#4136)
|
2023-04-03 12:06:14 +02:00 |
|
Nasreddine Bencherchali
|
5138fef3e5
|
feat: update 3cx compromise related rules (#4156)
|
2023-03-31 15:01:41 +02:00 |
|
Nasreddine Bencherchali
|
f8313036a0
|
feat: new rule related to susp child process of 3CXDesktopApp (#4153)
|
2023-03-30 00:36:02 +02:00 |
|
Nasreddine Bencherchali
|
c08a50758b
|
feat: update
|
2023-03-29 18:59:24 +02:00 |
|