root
5bb5938e86
add win_susp_bginfo.yml
2019-10-26 08:16:08 +02:00
root
01c4c7cdbd
modifed win_susp_msoffice.yml
2019-10-26 08:11:09 +02:00
root
bea2daac45
modifed win_susp_msoffice.yml
2019-10-26 07:55:44 +02:00
root
fc7f8ecea3
add win_susp_msoffice.yml
2019-10-26 07:48:38 +02:00
root
611c193826
modifed win_susp_odbcconf.yml
2019-10-26 07:45:53 +02:00
root
aa9a22e662
add win_susp_odbcconf.yml
2019-10-25 19:02:17 +02:00
alexpetrov12
8c2b7e9f85
fix
2019-10-25 18:30:40 +03:00
alexpetrov12
7aa804fe90
added new rules
...
Packet capture Windows command prompt, ODBCCONF execution dll, Windows Registry Persistence - COM key linking
2019-10-25 18:01:36 +03:00
zinint
6e94e798be
t1010
2019-10-25 16:12:51 +03:00
stvetro
dcaacd07bf
4 rules to cover ART
2019-10-25 15:38:47 +04:00
yugoslavskiy
5eb484a062
add tieto dns exfiltration rules
2019-10-25 04:30:55 +02:00
4A616D6573
5678357f4e
Update win_susp_net_execution.yml
...
Added tag for:
References:
https://attack.mitre.org/techniques/T1077/
https://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html
2019-10-25 12:20:47 +11:00
4A616D6573
a7a753862c
Update win_susp_net_execution.yml
...
Added:
1. Additional tags for techniques as defined by Atomic Blue.
2. Detection for OriginalFileName as net.exe can easily be renamed.
Part of oscd.community effort.
2019-10-25 12:06:32 +11:00
Florian Roth
a5ec6722a1
rule: the actual changes to hwp rule
2019-10-24 15:35:13 +02:00
zinint
7c5dc0ca01
Update win_data_compressed.yml
2019-10-24 15:34:13 +03:00
Florian Roth
86c1b4ae4b
rule: hwp exploits
2019-10-24 11:46:56 +02:00
alexpetrov12
cc998aa667
fix
2019-10-24 00:48:43 +03:00
mrblacyk
499627edf3
File permissions modification (T1222)
2019-10-23 11:24:13 -07:00
mrblacyk
4979b56296
Domain Trust Discovery rule (T1482)
2019-10-23 11:23:12 -07:00
mrblacyk
262514c782
Windows Service stop rule (T1489)
2019-10-23 11:22:09 -07:00
alexpetrov12
4c84412944
added new rule
...
silenttrinity_stage_ use, sysmon_mimikatz_сreds_dump, sysmon_registry_persistence_key_linking, sysmon_сreds_dump
2019-10-23 18:08:30 +03:00
alexpetrov12
bc943343df
update win_sysmon_driver_unload
2019-10-23 15:41:14 +03:00
alexpetrov12
215e500894
fix
2019-10-23 14:43:01 +03:00
alexpetrov12
193c95a11a
add new rule1
2019-10-23 14:27:52 +03:00
root
edcbc49ce8
add rule win_susp_open with_execution.yml win_susp_devt oolslauncher_execution.yml
2019-10-23 13:00:21 +02:00
alexpetrov12
043e3f7ca6
fix
2019-10-23 13:48:44 +03:00
alexpetrov12
e38540a37f
fix
2019-10-23 13:28:04 +03:00
alexpetrov12
c1cfbacd24
fix
2019-10-23 13:18:57 +03:00
alexpetrov12
ad9b98541c
fix
2019-10-23 13:05:38 +03:00
alexpetrov12
fa4a8c974d
fix
2019-10-23 12:45:06 +03:00
alexpetrov12
f4ea01217e
fix
2019-10-23 02:47:04 +03:00
alexpetrov12
ebe4fe0377
fix
2019-10-23 02:42:37 +03:00
alexpetrov12
29cd7fed3e
fix
2019-10-23 02:39:40 +03:00
alexpetrov12
5a260db459
fix
2019-10-23 02:27:14 +03:00
alexpetrov12
6c4f4ce309
fix
2019-10-23 02:25:04 +03:00
alexpetrov12
8d0c89b598
added new rules
...
add rule MiniDumpWriteDump via COM+, renamed_binary_description, cobalt_execute_assembly, win_sysmon_driver_onload
2019-10-23 01:55:03 +03:00
Florian Roth
3d4ce9d175
rule: another reference link for 'execution by ordinal'
2019-10-22 15:18:19 +02:00
zinint
a8bd2c8e78
Update win_data_compressed.yml
2019-10-22 14:57:53 +03:00
zinint
74d1fef8b8
Update win_data_compressed.yml
2019-10-22 14:53:43 +03:00
zinint
cc6d4b05ac
OSCD Task 7 : ART T1002 Exfiltration With Rar
...
OSCD Task 7 : ART T1002 Compress Data for Exfiltration With Rar
2019-10-22 14:00:52 +03:00
Florian Roth
b3654947bc
rule: suspicious call by ordinal (rundll32)
2019-10-22 12:40:26 +02:00
Florian Roth
0f02f2bdfc
rule: adjusted very noisy rule on AppLocker whitelist bypass
2019-10-22 12:32:37 +02:00
root
00a757959e
add rule win_susp_capture_screenshots.yml
2019-10-22 06:06:07 +02:00
zinint
daf1034621
Update win_possible_applocker_bypass.yml
2019-10-22 00:54:29 +03:00
Florian Roth
ab292a4029
rule: simplified Emotet rule
2019-10-16 15:29:42 +02:00
Florian Roth
5d143f4f22
rule: emotet rule references extended
2019-10-16 13:18:44 +02:00
Florian Roth
d46154da5c
rule: extending Emotet rule
2019-10-16 10:22:48 +02:00
Florian Roth
4ea469d138
rule: suspicious compression tool parameters
2019-10-15 16:38:53 +02:00
Florian Roth
52fef7ae10
Merge pull request #468 from 2d4d/lsass_without_exe
...
remove .exe from lsass
2019-10-14 18:03:13 +02:00
Florian Roth
8db1cac910
fix: made rule compatible with event id 4688
2019-10-14 18:01:24 +02:00