Commit Graph

3604 Commits

Author SHA1 Message Date
Nasreddine Bencherchali f6026b6972 Update proc_creation_win_susp_schtasks_disable.yml 2022-09-02 14:39:52 +02:00
Nasreddine Bencherchali 927b29e85a Update proc_creation_win_susp_powershell_download_iex.yml 2022-09-02 14:28:47 +02:00
Nasreddine Bencherchali e0a74d6238 Update proc_creation_win_net_default_accounts_manipulation.yml 2022-09-02 14:17:17 +02:00
Nasreddine Bencherchali 884891746b Update proc_creation_win_powershell_amsi_bypass.yml 2022-09-02 12:02:18 +02:00
Nasreddine Bencherchali 37f08c4cbb More updates 2022-09-02 11:52:13 +02:00
Nasreddine Bencherchali b02a2ff2dc Update proc_creation_win_net_default_accounts_manipulation.yml 2022-09-02 09:49:14 +02:00
Nasreddine Bencherchali 5f03a73dd2 Update proc_creation_win_susp_clsid_foldername.yml 2022-09-02 09:33:13 +02:00
Nasreddine Bencherchali ed88295732 Update proc_creation_win_susp_clsid_foldername.yml 2022-09-02 09:28:28 +02:00
Nasreddine Bencherchali d0e7732ddd Update proc_creation_win_susp_openas_rundll_usage.yml 2022-09-02 09:19:25 +02:00
Nasreddine Bencherchali 48c1104b1a New+Update 2022-09-02 09:15:21 +02:00
frack113 fc3c5cf99a Merge pull request #3455 from pH-T/master
new rule: susp net use combo
2022-09-02 06:58:32 +02:00
frack113 9a1a87de18 Update proc_creation_win_susp_net_use.yml 2022-09-02 06:42:47 +02:00
frack113 367e2fd0f9 Merge pull request #3450 from nasbench/master
Updates+New Rules
2022-09-02 06:39:15 +02:00
Paul Hager 6b2f12cbe6 fix: proc_creation_win_susp_net_use status 2022-09-01 15:01:38 +02:00
Paul Hager a428756340 new rule: susp net use combo 2022-09-01 14:38:06 +02:00
Tim Shelton 1bb172e4ae False positive when commandline is only cmd.exe /c 2022-08-31 19:38:25 +00:00
Nasreddine Bencherchali 783fd8b160 Create proc_creation_win_susp_schtasks_schedule_type.yml 2022-08-31 10:08:31 +02:00
Nasreddine Bencherchali ea183cae13 Updates+New Rules 2022-08-31 09:39:16 +02:00
Florian Roth 35d9e5f36a fix: syntax error, docs: change fp text 2022-08-30 11:29:11 +02:00
Florian Roth b5c57e97fc Merge branch 'master' into rule-devel 2022-08-30 09:14:37 +02:00
Florian Roth 52c5851ef6 rules: wmic extended, defendercheck, sharpldapwhoami 2022-08-30 09:13:25 +02:00
frack113 f9b79161a5 Merge pull request #3444 from danielgottt/patch-7
Create proc_creation_win_deviceenroller_evasion.yml
2022-08-30 08:24:24 +02:00
Wagga 4573ab0a21 Fix a lot of typos in rules text and comments #Part 3 (#3446) 2022-08-30 08:21:25 +02:00
Gott 8809fc6a8e Update proc_creation_win_deviceenroller_evasion.yml
Made corrections frack presented
2022-08-29 15:23:17 -04:00
Wagga 691aae2638 Update proc_creation_win_ntfs_short_name_path_use_image.yml 2022-08-29 20:13:14 +02:00
Wagga 8a9d63bba1 Update proc_creation_win_wmic_remote_service.yml 2022-08-29 18:50:04 +02:00
Wagga 86b448b715 Update proc_creation_win_lolbin_register_app.yml 2022-08-29 18:49:17 +02:00
Wagga 351d8bcc40 Update proc_creation_win_wmic_unquoted_service_search.yml 2022-08-29 18:48:29 +02:00
Wagga 7c0bd62e9f Update proc_creation_win_cmd_redirection_susp_folder.yml 2022-08-29 18:47:44 +02:00
Wagga eb572e8b0c Update proc_creation_win_wpbbin_persistence.yml 2022-08-29 18:45:49 +02:00
Wagga 86876adad4 Update proc_creation_win_cmd_dosfuscation.yml 2022-08-29 18:45:00 +02:00
Wagga 7b0eb71563 Update proc_creation_win_vmtoolsd_susp_child_process.yml 2022-08-29 18:44:19 +02:00
Gott 4f2205d4f2 Update proc_creation_win_deviceenroller_evasion.yml
correction to falsepositive
2022-08-29 11:55:36 -04:00
Gott 0f75a16ea3 Update proc_creation_win_deviceenroller_evasion.yml
correction to mitre tag
2022-08-29 11:46:25 -04:00
Gott 2a6c27b7b5 Create proc_creation_win_deviceenroller_evasion.yml 2022-08-29 11:35:54 -04:00
Wagga 0d92b047ff Update proc_creation_win_susp_powershell_webclient_casing.yml 2022-08-29 12:11:33 +02:00
Wagga 7c6bf47757 Update proc_creation_win_susp_rundll32_user32_dll.yml 2022-08-29 07:59:45 +02:00
Wagga 39edfddce4 Update proc_creation_win_lolbin_diantz_ads.yml 2022-08-29 07:58:05 +02:00
Wagga 9d3d718c27 Update proc_creation_win_icacls_deny.yml 2022-08-29 07:57:34 +02:00
Wagga d5724fb583 Update proc_creation_win_susp_advancedrun.yml 2022-08-29 07:56:59 +02:00
Wagga 11e24a6e66 Update proc_creation_win_susp_advancedrun_priv_user.yml 2022-08-29 07:56:27 +02:00
Wagga cffc6fa947 Update proc_creation_win_susp_nmap.yml 2022-08-29 07:55:38 +02:00
Wagga 5515dc7397 Update proc_creation_win_fsutil_drive_enumeration.yml 2022-08-29 07:54:56 +02:00
Wagga da82c739c5 Update proc_creation_win_attrib_system_susp_paths.yml 2022-08-29 07:54:18 +02:00
Wagga c0b3cd847f Update proc_creation_win_lolbin_cl_mutexverifiers.yml 2022-08-29 07:53:15 +02:00
Wagga 37230eabee Update proc_creation_win_lolbin_cl_loadassembly.yml 2022-08-29 07:52:56 +02:00
Wagga 762ac06eea Update proc_creation_win_lolbin_wlrmdr.yml 2022-08-29 07:52:12 +02:00
Wagga b0af5fbc8f Update proc_creation_win_lolbin_squirrel.yml 2022-08-29 07:50:55 +02:00
Wagga 3f3705164f Update proc_creation_win_net_user_add_never_expire.yml 2022-08-29 07:47:56 +02:00
Wagga 1a26c174f2 Update proc_creation_win_inline_base64_mz_header.yml 2022-08-29 07:47:27 +02:00