Florian Roth
|
f581d77e5d
|
Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
|
2022-09-13 11:30:37 +02:00 |
|
Florian Roth
|
264bc0787d
|
fix: FP with Malwarebytes
|
2022-09-13 11:30:27 +02:00 |
|
Florian Roth
|
72aa55f1c7
|
Merge branch 'master' into aurora-false-positive-fixing
|
2022-09-13 08:07:26 +02:00 |
|
Florian Roth
|
5f164ebe12
|
style: indentation
|
2022-09-12 13:30:14 +02:00 |
|
Florian Roth
|
0bbb679e38
|
fix: FPs with veam backup shell
|
2022-09-12 13:29:51 +02:00 |
|
Qasim Qlf
|
1eaad811b6
|
tag added
|
2022-09-12 14:15:48 +05:00 |
|
Florian Roth
|
a5fe285776
|
fix: too many FPs during Windows update - User empty
|
2022-09-11 16:28:04 +02:00 |
|
David André
|
93da67b593
|
Update proc_creation_win_renamed_vmnat.yml
Added accidentaly removed falsepositives
|
2022-09-11 13:13:58 +02:00 |
|
David André
|
262f046351
|
Delete image_load_vmware_nondefault_path.yml
File added in wrong branch
|
2022-09-11 13:07:23 +02:00 |
|
David André
|
5656a3a50b
|
Merge branch 'SigmaHQ:master' into add_renamed_vmnat
|
2022-09-11 13:06:21 +02:00 |
|
David ANDRE
|
5b0c8f60e2
|
Removed trailing space
|
2022-09-11 12:36:44 +02:00 |
|
David ANDRE
|
c98997390b
|
Changes following advice
|
2022-09-11 12:35:05 +02:00 |
|
frack113
|
6e529bb9c8
|
Merge pull request #3484 from elhoim/add_samtheadmin
Add rule to detect samtheadmin computer name used by hacktool
|
2022-09-10 12:34:51 +02:00 |
|
frack113
|
21435629a0
|
Merge pull request #3482 from nasbench/nasbench-rule-devel
Rule Devel (New+Update)
|
2022-09-10 12:34:26 +02:00 |
|
Florian Roth
|
e7084eee04
|
Merge pull request #3487 from SigmaHQ/aurora-false-positive-fixing
fix: fixing multiple FPs with the use of VSCode
|
2022-09-10 12:07:01 +02:00 |
|
Florian Roth
|
0a5cfb93b3
|
fix: condition
|
2022-09-10 11:53:42 +02:00 |
|
Florian Roth
|
7dbdd4d1c6
|
fix: fixing multiple FPs with the use of VSCode
|
2022-09-10 11:42:44 +02:00 |
|
Florian Roth
|
a053be791c
|
Update proc_creation_win_user_discovery_get_aduser.yml
|
2022-09-10 09:49:14 +02:00 |
|
Florian Roth
|
a616647b08
|
lowered score of scheduled task + SYSTEM rule
|
2022-09-10 09:48:50 +02:00 |
|
Florian Roth
|
9ed14ce571
|
tightened the regular expression
|
2022-09-10 09:34:16 +02:00 |
|
Nasreddine Bencherchali
|
2552b75e72
|
Delete proc_creation_win_net_add_local_user.yml
|
2022-09-09 23:11:28 +02:00 |
|
frack113
|
b9cc206d9d
|
Update win_susp_computer_name.yml
|
2022-09-09 18:53:48 +02:00 |
|
frack113
|
3b8184a6b7
|
Merge pull request #3480 from phantinuss/master
fix: FP with windows defender
|
2022-09-09 18:49:37 +02:00 |
|
David ANDRE
|
6c1761a7b7
|
Revert "Merge branch 'master' of github.com:elhoim/sigma"
This reverts commit fc98278b19.
|
2022-09-09 16:55:12 +02:00 |
|
David ANDRE
|
6182b43279
|
Add rule for renamed vmnat.exe
|
2022-09-09 16:40:17 +02:00 |
|
David ANDRE
|
fc98278b19
|
Merge branch 'master' of github.com:elhoim/sigma
|
2022-09-09 16:12:59 +02:00 |
|
David ANDRE
|
9a77542bc6
|
Add comment to explain lack of eventID\nBetter description
|
2022-09-09 16:11:07 +02:00 |
|
David ANDRE
|
b170af5687
|
Added rule for sam the admin suspicious computer
|
2022-09-09 16:08:19 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
14db9c9fb1
|
Update proc_creation_win_wmic_computersystem_recon.yml
|
2022-09-09 15:43:07 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
a71ce185d7
|
Fix
|
2022-09-09 15:32:03 +02:00 |
|
David André
|
ae5dc248c8
|
Merge branch 'SigmaHQ:master' into rename_suspicious2
|
2022-09-09 15:18:35 +02:00 |
|
David ANDRE
|
b75fb5abf5
|
Renamed suspicious in rules file names to susp
|
2022-09-09 15:12:47 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
051397b533
|
Update proc_creation_win_susp_schtasks_delete_all.yml
|
2022-09-09 15:10:49 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
c8fc1cf21e
|
Update proc_creation_win_user_discovery_get_aduser.yml
|
2022-09-09 15:04:36 +02:00 |
|
nasreddine.bencherchali@nextron-systems.com
|
70f9ff61ca
|
Big Update
|
2022-09-09 15:02:31 +02:00 |
|
phantinuss
|
43e0d4fe6a
|
fix: FP with windows defender
|
2022-09-09 13:51:53 +02:00 |
|
phantinuss
|
38a2e76af8
|
fix: general filter should filter on both selections
|
2022-09-09 10:03:50 +02:00 |
|
Nasreddine Bencherchali
|
fbc7733078
|
Update proc_creation_win_susp_reg_add.yml
|
2022-09-08 22:52:24 +02:00 |
|
Nasreddine Bencherchali
|
dd67c4fd73
|
Dev
|
2022-09-08 22:50:57 +02:00 |
|
phantinuss
|
586b1c449f
|
fix: FP on race condition
|
2022-09-08 16:28:05 +02:00 |
|
Nasreddine Bencherchali
|
15713918cd
|
Rename
|
2022-09-08 10:26:23 +02:00 |
|
Nasreddine Bencherchali
|
baf603bb5c
|
Fix FP in testing
|
2022-09-08 10:24:27 +02:00 |
|
Florian Roth
|
358e8a567e
|
Merge pull request #3474 from SigmaHQ/aurora-false-positive-fixing
fix: schtasks in suspicious parents rule
|
2022-09-08 09:09:26 +02:00 |
|
Florian Roth
|
de68bf5559
|
fix: schtasks in suspicious parents rule
|
2022-09-08 09:00:58 +02:00 |
|
frack113
|
6813043323
|
Merge pull request #3468 from nasbench/nasbench-rule-devel
Rule Devel
|
2022-09-08 06:29:36 +02:00 |
|
frack113
|
6fea0e2c79
|
Merge pull request #3471 from qasimqlf/patch-5
Update proc_creation_win_bad_opsec_sacrificial_processes.yml
|
2022-09-08 06:28:25 +02:00 |
|
Nasreddine Bencherchali
|
b70ac17676
|
Fix
|
2022-09-07 21:58:22 +02:00 |
|
Florian Roth
|
43b56fed23
|
Merge pull request #3472 from SigmaHQ/rule-devel
rules: SysmonEnte, SharpEvtMute, sdelete rework
|
2022-09-07 21:06:03 +02:00 |
|
Florian Roth
|
1641f4590a
|
fix: duplicate UUIDs
|
2022-09-07 17:12:12 +02:00 |
|
Florian Roth
|
a69d256367
|
rule: SharpEvtMute
|
2022-09-07 16:33:52 +02:00 |
|