Commit Graph

2658 Commits

Author SHA1 Message Date
Florian Roth f647e45e69 Merge pull request #2749 from redsand/fp_msiexec
Filters false positive from msiexec.exe
2022-02-25 19:03:45 +01:00
Tim Shelton 6d29b4c4a5 oof, misspelled detection type 2 2022-02-25 16:34:32 +00:00
Tim Shelton f6caaf795a oof, misspelled detection type 2022-02-25 16:32:33 +00:00
Tim Shelton 9d06c3cfe7 Filters false positive from msiexec.exe 2022-02-25 16:17:01 +00:00
Florian Roth b0b675b004 rule: CrackMapExec flags rule 2022-02-25 11:39:19 +01:00
Florian Roth 98c1c60758 Merge branch 'master' into rule-devel 2022-02-25 10:38:58 +01:00
Florian Roth 3d609cfdf3 rule: ScreenConnect anomaly
https://www.mandiant.com/resources/telegram-malware-iranian-espionage
2022-02-25 10:31:58 +01:00
Florian Roth 6f79d70532 Merge branch 'master' into rule-devel 2022-02-25 09:19:16 +01:00
frack113 beafcc7b4c Merge pull request #2740 from AndrewRathbun/master
Update proc_creation_win_susp_esentutl_params.yml - minor spelling error
2022-02-24 21:27:00 +01:00
Florian Roth 220344f477 Merge pull request #2735 from SigmaHQ/rule-devel
rules: suspicious schtasks creation
2022-02-24 18:19:45 +01:00
Andrew Rathbun b17f2b3840 Update proc_creation_win_susp_esentutl_params.yml 2022-02-24 11:52:21 -05:00
Florian Roth 536910f7d7 fix: FPs with new task scheduler rule 2022-02-24 08:41:53 +01:00
Florian Roth 1682bdb8a8 fix: condition section 2022-02-23 23:28:53 +01:00
Florian Roth 22fbf5bb0a fix: indentation of conditions 2022-02-23 23:28:22 +01:00
Florian Roth d455dec42c fix: wrong condition 2022-02-23 23:26:33 +01:00
Florian Roth 825bf41f51 rules: susp schtasks creation 2022-02-23 23:25:20 +01:00
Florian Roth 9561e155ed docs: changed title 2022-02-23 23:25:06 +01:00
Florian Roth 0005509c11 Merge pull request #2733 from phantinuss/master
fix: FPs
2022-02-23 20:27:49 +01:00
Florian Roth f05f615b0d rule: explorer NOUACCHECK flag 2022-02-23 15:47:44 +01:00
Florian Roth d0c2aead9e refactor: improved ncat rule 2022-02-23 15:18:52 +01:00
phantinuss 329b5aa0eb fix: reduce level, many legitimate usages expected 2022-02-23 14:13:12 +01:00
Florian Roth 22e975334c refactor: extended powershell cmdline flag rule 2022-02-23 12:52:38 +01:00
Florian Roth 122b7029cb Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2022-02-23 11:19:21 +01:00
Florian Roth eefaa17599 fix: Office Shell rule - Outlook Print attachment 2022-02-23 11:19:17 +01:00
Florian Roth a5955730bd docs: title changed 2022-02-22 19:10:20 +01:00
Florian Roth 738e77e239 fix: issues with installer 2022-02-22 16:52:53 +01:00
Florian Roth 24ece0c60a Merge branch 'master' into rule-devel 2022-02-22 16:33:51 +01:00
frack113 8bb3379b68 Normalization of rule names 2022-02-22 11:16:31 +01:00
Florian Roth 8d9e16355b fix: FP in Office Shell rule with Outlook PhotoViewer 2022-02-22 09:17:33 +01:00
Florian Roth 06f6f6e7f0 Merge pull request #2720 from redsand/fp_backward_powershell
Filter fp when commands are base64 encoded
2022-02-22 08:59:49 +01:00
Tim Shelton 9461309687 Filter fp when commands are base64 encoded 2022-02-21 21:15:47 +00:00
Florian Roth cbe7abc16e Merge branch 'master' into aurora-false-positive-fixing 2022-02-21 18:49:45 +01:00
Florian Roth 921d46ca79 fix: FPs noticed with Aurora 2022-02-21 18:43:18 +01:00
Florian Roth f1d962d140 Merge pull request #2717 from phantinuss/checkbaseline
New workflow action: Check sigma rules against baseline evtx files
2022-02-21 15:14:35 +01:00
Florian Roth 29dacbe6b6 Merge pull request #2716 from SigmaHQ/aurora-false-positive-fixing
Aurora and THOR false positive fixing
2022-02-21 14:46:31 +01:00
phantinuss df21201783 fix: FP 2022-02-21 11:09:20 +01:00
Florian Roth cfd5847063 Schtasks creation rule 2022-02-21 11:01:27 +01:00
Florian Roth 6ce58d7201 refactor: removed unnecessary regex 2022-02-21 11:01:18 +01:00
frack113 dcf936bb6c Rename win_pc_tor_browser.yml to proc_creation_win_tor_browser.yml 2022-02-20 17:59:53 +01:00
Florian Roth e7bf14c6dc description and title 2022-02-20 12:14:57 +01:00
Florian Roth 505734730d increased level 2022-02-20 12:14:14 +01:00
frack113 82660bbaf2 Simple TOR rules 2022-02-20 11:26:13 +01:00
frack113 604600ac2f Merge pull request #2709 from frack113/fix_aurora_fp
Fix FP for win_pc_susp_run_folder
2022-02-20 09:05:17 +01:00
frack113 631a300236 Fix some FP 2022-02-19 10:25:26 +01:00
Florian Roth 1196387e90 fix: FPs noticed with Aurora 2022-02-18 12:53:17 +01:00
frack113 cabe5c5043 Merge pull request #2703 from frack113/lolbin
add win_pc_lolbin_wlrmdr
2022-02-17 19:26:19 +01:00
Florian Roth e0d8f59f42 Update win_pc_lolbin_wlrmdr.yml 2022-02-17 16:24:52 +01:00
frack113 1a76bb82d6 Merge pull request #2700 from frack113/DOSfuscation
add win_pc_cmd_dosfuscation
2022-02-17 06:32:45 +01:00
frack113 3b02967ffb add win_pc_lolbin_wlrmdr 2022-02-16 19:53:46 +01:00
Florian Roth 50efc894bc add common "set" expressions
add common caret obfuscated "set" expressions often found in Invoke-Obfuscation code
2022-02-16 17:33:33 +01:00