nasreddine.bencherchali@nextron-systems.com
|
faad0209de
|
Rename Plink Port Forward Rule
|
2022-10-12 11:24:28 +02:00 |
|
Nasreddine Bencherchali
|
f55f4ca2d6
|
Update Rules
|
2022-10-12 10:04:15 +02:00 |
|
Nasreddine Bencherchali
|
d42e5b5435
|
New Rules
|
2022-10-12 10:04:04 +02:00 |
|
Florian Roth
|
a55cea92e0
|
Merge pull request #3572 from nasbench/nasbench-rule-devel
Rule Dev - Small Updates
|
2022-10-11 00:40:35 +02:00 |
|
Florian Roth
|
41d2ece9f4
|
Merge pull request #3573 from SigmaHQ/rule-devel
rule: Process Hacker, PCHunter; ZINC APT UA
|
2022-10-11 00:40:21 +02:00 |
|
Florian Roth
|
0df87d76f2
|
fix: duplicate, list with one entry
|
2022-10-10 22:49:34 +02:00 |
|
Nasreddine Bencherchali
|
bf28e42f01
|
Fix FP Found In Testing
|
2022-10-10 17:33:14 +02:00 |
|
Florian Roth
|
b2c012146e
|
rules: pchunter, process hacker
|
2022-10-10 17:21:17 +02:00 |
|
Nasreddine Bencherchali
|
be0a3ad863
|
Add missing definition section for EID 4697
|
2022-10-10 10:22:46 +02:00 |
|
Florian Roth
|
cb73e9725a
|
Merge pull request #3570 from SigmaHQ/rule-devel
IOX and NPS tunneling tools
|
2022-10-10 00:26:48 +02:00 |
|
frack113
|
cf7a348028
|
Fix related
|
2022-10-09 17:28:05 +02:00 |
|
frack113
|
931fb30853
|
old experimental rule promotion
|
2022-10-09 16:54:04 +02:00 |
|
Florian Roth
|
e009ba937e
|
rule: NPS tunneling tool
|
2022-10-08 09:49:51 +02:00 |
|
Florian Roth
|
deb5540816
|
rules: refactored FRP, new IOX
|
2022-10-08 09:32:36 +02:00 |
|
Nasreddine Bencherchali
|
8dbd03ff32
|
Fix FP In Testing
|
2022-10-07 13:26:33 +02:00 |
|
Florian Roth
|
6623778a61
|
fix: wrong log source
|
2022-10-07 10:44:35 +02:00 |
|
Florian Roth
|
c073388472
|
rule: lpe - tabtip indicator
|
2022-10-07 10:41:04 +02:00 |
|
Florian Roth
|
b634e1a3f9
|
Merge pull request #3562 from nasbench/pysigma-fix
PySigma Issues Fix
|
2022-10-07 09:21:15 +02:00 |
|
frack113
|
7539d29e8b
|
Merge pull request #3559 from nasbench/nasbench-rule-devel
Rule Dev
|
2022-10-07 06:07:43 +02:00 |
|
Florian Roth
|
d5e2991a4c
|
Merge pull request #3551 from frack113/redcannary_20221002
Redcannary rules
|
2022-10-06 13:02:46 +02:00 |
|
Florian Roth
|
8a0cf2e7e6
|
Update proc_creation_win_hh_chm_http.yml
|
2022-10-06 09:28:17 +02:00 |
|
Florian Roth
|
c0ff746d99
|
change: make uppercase in Sysmon version
|
2022-10-06 09:27:26 +02:00 |
|
Florian Roth
|
f0196039ba
|
Update proc_creation_win_susp_logoff.yml
|
2022-10-06 09:24:15 +02:00 |
|
Florian Roth
|
f1435ea16b
|
Update proc_creation_win_susp_logoff.yml
|
2022-10-06 09:23:37 +02:00 |
|
Florian Roth
|
881dd0c6d0
|
Update proc_creation_win_pdq_deploy.yml
|
2022-10-06 09:22:44 +02:00 |
|
Florian Roth
|
15232621b1
|
refactor: another JuicyPotatoNG pattern
|
2022-10-06 08:47:23 +02:00 |
|
Florian Roth
|
b6270dfcf0
|
Merge branch 'master' into rule-devel
|
2022-10-06 08:43:02 +02:00 |
|
Florian Roth
|
e92f2475b6
|
refactor: JuicyPotatoNG imphashes
|
2022-10-06 08:30:48 +02:00 |
|
frack113
|
32406c1915
|
Issue 3552
|
2022-10-06 06:50:54 +02:00 |
|
frack113
|
b1b7428a30
|
Merge pull request #3560 from redsand/fp_ec2_windows
FP: ignore amazon aws ec2 scripts
|
2022-10-06 06:41:22 +02:00 |
|
Nasreddine Bencherchali
|
dadec8b9f0
|
Update incorrect mitre tags
|
2022-10-06 00:35:40 +02:00 |
|
Florian Roth
|
adfb7d58e8
|
Merge pull request #3563 from SigmaHQ/rule-devel
refactor: JuicyPotatoNG pattern
|
2022-10-06 00:10:32 +02:00 |
|
Florian Roth
|
d2777f4d02
|
refactor: JuicyPotatoNG pattern
|
2022-10-06 00:00:46 +02:00 |
|
Nasreddine Bencherchali
|
2c26614ce4
|
Update Wildcard + Int to Str fields
|
2022-10-05 23:15:20 +02:00 |
|
Tim Shelton
|
f65e795e22
|
FP: ignore amazon aws ec2 scripts
|
2022-10-05 19:40:37 +00:00 |
|
Nasreddine Bencherchali
|
68937161a0
|
Add GMER + PCHunter
|
2022-10-05 12:04:11 +02:00 |
|
Nasreddine Bencherchali
|
40dcb9a4c9
|
Update + Rename
|
2022-10-05 10:42:29 +02:00 |
|
Nasreddine Bencherchali
|
2ecf9ec7e1
|
Updates
|
2022-10-04 20:57:11 +02:00 |
|
Florian Roth
|
ef0e5c76a5
|
Merge pull request #3557 from SigmaHQ/rule-devel
fix: wrong condition in whoami rule
|
2022-10-04 16:23:04 +02:00 |
|
Florian Roth
|
eee1d2c1cb
|
fix: wrong condition in whoami rule
https://github.com/SigmaHQ/sigma/issues/3556
|
2022-10-04 16:11:03 +02:00 |
|
Florian Roth
|
029900c284
|
Merge pull request #3548 from aaronherman/patch-1
Update description typo on "Phishing Pattern ISO in Archive"
|
2022-10-03 19:55:13 +02:00 |
|
securepeacock
|
161c8e6c2c
|
Update proc_creation_win_lolbins_by_office_applications.yml
Adding msidb.exe references are below.
https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
|
2022-10-03 11:56:06 -04:00 |
|
frack113
|
5bd9dd76aa
|
Redcannary rules
|
2022-10-02 11:34:33 +02:00 |
|
Florian Roth
|
93004a3fd5
|
Update proc_creation_win_archiver_iso_phishing.yml
|
2022-10-02 10:21:04 +02:00 |
|
Aaron Herman
|
580360b540
|
Update description typo
|
2022-10-01 10:52:35 -05:00 |
|
Florian Roth
|
65f531fb30
|
rule: Exchange Exploitation
|
2022-10-01 16:08:27 +02:00 |
|
Nasreddine Bencherchali
|
7880e3a2b6
|
Fix FP
Make the FP fix more broad to cover more future cases
|
2022-09-29 22:29:47 +02:00 |
|
Nasreddine Bencherchali
|
bfc1d6a5b7
|
Create proc_creation_win_hh_chm_http.yml
|
2022-09-29 22:06:11 +02:00 |
|
Nasreddine Bencherchali
|
47dbe6081d
|
Update proc_creation_win_susp_conhost.yml
|
2022-09-29 12:15:10 +02:00 |
|
Florian Roth
|
a888ecb8b8
|
Merge pull request #3535 from nasbench/nasbench-rule-devel
New rules + update
|
2022-09-29 11:01:29 +02:00 |
|