Commit Graph

8 Commits

Author SHA1 Message Date
Florian Roth c8b3036949 Merge pull request #1968 from SigmaHQ/rule-devel
docs: note to improved sysmon config
2021-09-01 13:21:28 +02:00
Florian Roth f102b2d9a1 docs: note to improved sysmon config 2021-09-01 13:07:18 +02:00
phantinuss e59b8e1e3e add applicable pipe names from regex rule 2021-08-26 14:53:20 +02:00
phantinuss dc19268583 remove becasue of possible conflict
with a legitimate tool (https://labs.nettitude.com/blog/cve-2017-16245-cve-2017-16246-avecto-defendpoint-multiple-vulnerabilities/)
2021-08-26 14:25:12 +02:00
Florian Roth 6c7d355ef5 Try to add more pipe names to this non-regex rule 2021-08-26 14:00:57 +02:00
phantinuss 217dbc768a More malleable CobaltStrike C2 profiles from new source/reference 2021-08-26 12:53:43 +02:00
Florian Roth 096395a49a fix: one condition style error 2021-07-30 07:19:42 +02:00
Florian Roth 0cbb6f82ad CobaltStrike NamedPipe Patterns
https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
2021-07-30 07:11:11 +02:00