Commit Graph

13931 Commits

Author SHA1 Message Date
frack113 fec24ddd0f Merge pull request #3806 from veramine/patch-10
Remove Windows 10 user experience false positive
2022-12-22 10:32:10 +01:00
Veramine 3bb741af66 Remove Windows 10 volume control false positive
https://superuser.com/questions/1175267/what-is-this-rundll32-instance-running
2022-12-21 23:41:39 -08:00
Nasreddine Bencherchali 9d4bbec633 Merge pull request #3805 from zakibro/master
Create lnx_privileged_user_creation.yml
2022-12-21 21:35:59 +01:00
Nasreddine Bencherchali 4c7db89847 fix: improve overall structure 2022-12-21 20:40:29 +01:00
Nasreddine Bencherchali b9ae5303f1 Merge pull request #2801 from tuanhxh1/master
add rules related to usage of "usermod"
2022-12-21 20:33:04 +01:00
zakibro a0c07b2fba Update rules/linux/builtin/lnx_privileged_user_creation.yml
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 19:31:34 +01:00
zakibro 14f006382a Update rules/linux/builtin/lnx_privileged_user_creation.yml
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 19:31:24 +01:00
Nasreddine Bencherchali d51ff694a4 fix: rule status 2022-12-21 19:23:23 +01:00
zakibro 0fa4f8a454 Create lnx_privileged_user_creation.yml
Adding new use case for tracking of Creation of privileged user in linux
2022-12-21 18:16:20 +01:00
Nasreddine Bencherchali c97463e774 fix: update linux rules 2022-12-21 17:59:46 +01:00
sai prashanth pulisetti 3b6100ccd9 Create Possible Manipulation Of Tokens on a Windows computers remotely Detected via impersonate (#3803)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-21 13:27:22 +01:00
Florian Roth b75c7d4bdb Merge pull request #3802 from nasbench/nasbench-rule-devel
feat: updates and enhancements
2022-12-21 10:02:23 +01:00
Florian Roth f9d1eb1f2d Update proc_creation_win_renamed_office_processes.yml 2022-12-21 09:18:06 +01:00
Florian Roth b157bef3de fix: link to correct issue 2022-12-21 08:59:24 +01:00
Florian Roth 9372987801 fix: missing upper tick
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-21 08:57:37 +01:00
Florian Roth 7e7cbe41c3 docs: change modified date 2022-12-21 08:57:05 +01:00
Florian Roth 7f4a84963c style: reordered fields 2022-12-21 08:56:26 +01:00
Nasreddine Bencherchali 4b6f5f143d feat: add more suspicious cases
Co-authored-by: Florian Roth <venom14@gmail.com>
2022-12-21 00:18:44 +01:00
Nasreddine Bencherchali 7c46e4c3c0 fix: fix #2479 2022-12-21 00:11:04 +01:00
Florian Roth 2580b84de3 fix: typo 2022-12-21 00:07:51 +01:00
Nasreddine Bencherchali beccf416da feat: add two new rules 2022-12-20 23:44:44 +01:00
Nasreddine Bencherchali 321e54a3c3 Merge pull request #3801 from zakibro/master
Modifying Creation Of An User Account
2022-12-20 22:59:41 +01:00
Nasreddine Bencherchali c36acb333f fix: typo in comment 2022-12-20 22:28:49 +01:00
Nasreddine Bencherchali 6679347fe3 fix: rename files to follow convention 2022-12-20 22:25:49 +01:00
Nasreddine Bencherchali 68f1ce8b9e Merge branch 'SigmaHQ:master' into nasbench-rule-devel 2022-12-20 22:24:56 +01:00
Nasreddine Bencherchali e72bc1dcaf fix: add reference 2022-12-20 22:14:46 +01:00
Nasreddine Bencherchali 592e0062a1 fix: update condition and add new ref 2022-12-20 22:14:14 +01:00
zakibro 1a117d38e7 Update rules/linux/auditd/lnx_auditd_create_account.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
2022-12-20 19:30:26 +01:00
zakibro 59e4dc3e1c Modifying Creation Of An User Account
Added additional test for record type of ADD_USER which should be generated whether you have created auditd rule or not.
2022-12-20 15:51:40 +01:00
Nasreddine Bencherchali 8a1c926ac2 Merge pull request #3800 from tropChaud/master
T1539 Steal Web Session Cookie rules
2022-12-20 14:48:14 +01:00
Nasreddine Bencherchali 7679d05706 fix: fp found in testing exchange server 2022-12-20 13:23:32 +01:00
Nasreddine Bencherchali 3f48eb4963 fix: selection name and add old path 2022-12-20 10:42:21 +01:00
Nasreddine Bencherchali de5345cfd2 fix: add permalink instead of master 2022-12-20 10:25:52 +01:00
Nasreddine Bencherchali 22761ec2c3 fix: add missing id 2022-12-20 10:25:03 +01:00
frack113 0bdf5df446 Merge pull request #3797 from nasbench/update-license
feat: update license
2022-12-20 09:01:52 +01:00
MetaOSINT ba52dc2aa8 T1539 Steal Web Session Cookie rules
Update existing rule and add one new rule related to Steal Web Session Cookie technique (T1539)
2022-12-19 23:20:13 -05:00
Nasreddine Bencherchali c6c8c27fbc Merge pull request #3799 from pbssubhash/master
DirCreate2System detection
2022-12-19 22:40:04 +01:00
Nasreddine Bencherchali 05bdb9af74 fix: rename files to fit logic 2022-12-19 19:28:23 +01:00
Nasreddine Bencherchali ff94bfee2b fix: update description to fit logic 2022-12-19 19:23:11 +01:00
Nasreddine Bencherchali 9c308642c7 fix: apply suggestions from code review
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2022-12-19 19:21:55 +01:00
Nasreddine Bencherchali c374413664 fix: change to permalink 2022-12-19 18:15:57 +01:00
Nasreddine Bencherchali 060174e2dd fix: small fixes
- Added modified date
- Updated DLL sideload version
2022-12-19 18:14:01 +01:00
pbssubhash 8a9f1ee273 Update file_event_win_wermgr_local_privilege_escalation.yml 2022-12-19 22:39:05 +05:30
pbssubhash ae974d8f15 Modifying existing rule instead of a new one 2022-12-19 22:35:36 +05:30
pbssubhash b763ddd7c7 Update file_event_win_dircreate2system_privesc.yml 2022-12-19 22:21:37 +05:30
pbssubhash 8d617d2587 Create file_event_win_dircreate2system_privesc.yml 2022-12-19 22:14:25 +05:30
Nasreddine Bencherchali ba3e985bed feat: multiple update and enhancements 2022-12-19 17:41:40 +01:00
Nasreddine Bencherchali 9238d20d65 feat: update readme for license and markdown warnings 2022-12-19 17:28:09 +01:00
Nasreddine Bencherchali 14cb2f32eb Merge pull request #3798 from qasimqlf/patch-17
fix: modify the detection and condition
2022-12-19 12:44:38 +01:00
Nasreddine Bencherchali 025c1a4aae fix: enhance logic and severity 2022-12-19 11:21:24 +01:00