Commit Graph

5864 Commits

Author SHA1 Message Date
Austin Songer 360b936357 Update microsoft365_potential_ransomware_activity.yml 2021-08-20 08:17:09 -05:00
Austin Songer ae36804935 Update microsoft365_user_restricted_from_sending_email.yml 2021-08-20 08:16:48 -05:00
Rachel Rice f09b3ea4b1 Update AWS CloudTrail rules
aws_ec2_disable_encryption.yml
Remove `status: success` from selection criteria, not required

aws_ec2_vm_export_failure.yml
Remove filter3:
```
eventName: 'ConsoleLogin'
responseElements|contains: 'Failure'
```
Incompatible with selection criteria `eventName: 'CreateInstanceExportTask'`

aws_ec2_download_userdata.yml, aws_iam_backdoor_users_keys.yml, aws_rds_change_master_password.yml, aws_rds_public_db_restore.yml
Update reference

aws_sts_assumedrole_misuse.yml
Rename to aws_sts_assumerole_misuse.yml
Update references to "AssumedRole" to "AssumeRole"
Update selection criteria of `userIdentity.sessionContext: Role` to `userIdentity.sessionContext.sessionIssuer.type: Role`
2021-08-20 13:43:00 +01:00
frack113 7ebd411190 update ref from conti_leak 2021-08-20 14:22:17 +02:00
frack113 4e29dc9c45 fix title 2021-08-20 09:06:16 +02:00
frack113 9b106dcc7d Merge pull request #1880 from austinsonger/azure_suppression_rule_created.yml
azure_suppression_rule_created.yml
2021-08-20 09:04:48 +02:00
frack113 d58b1e8e40 Merge pull request #1879 from austinsonger/azure_application_gateway_modified_or_deleted.yml
azure_application_gateway_modified_or_deleted.yml
2021-08-20 09:03:57 +02:00
frack113 4b08aac47f Merge pull request #1878 from austinsonger/azure_application_security_group_modified_or_deleted.yml
azure_application_security_group_modified_or_deleted.yml
2021-08-20 09:01:39 +02:00
Austin Songer 853c2eb41d Update microsoft365_potential_ransomware_activity.yml 2021-08-20 01:19:01 -05:00
Austin Songer f745593e80 Update microsoft365_potential_ransomware_activity.yml 2021-08-20 00:33:42 -05:00
Austin Songer 42fbc0cbfc Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 23:13:35 -05:00
Austin Songer bcb43cf728 Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 23:13:06 -05:00
Austin Songer b89910a38a Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 23:09:38 -05:00
frack113 f882ebda35 fix status 2021-08-20 06:08:28 +02:00
Austin Songer 54bda90685 Create microsoft365_user_restricted_from_sending_email.yml 2021-08-19 23:08:25 -05:00
Austin Songer 9b19190ea7 Create microsoft365_potential_ransomware_activity.yml 2021-08-19 23:05:05 -05:00
Austin Songer 99fbd4ef44 Create microsoft365_unusual_volume_of_file_deletion.yml 2021-08-19 23:00:23 -05:00
Austin Songer fe0e1353e0 Update win_susp_bitstransfer.yml 2021-08-19 22:24:23 -05:00
Austin Songer 810aae5ddd Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 21:58:36 -05:00
Austin Songer 8d57ae5ffd Create win_susp_bitstransfer.yml 2021-08-19 21:57:37 -05:00
Austin Songer 0a3e57cc12 Update 2021-08-20 02:10:32 +00:00
Austin Songer 842ade16be Forgot to add my username to some of the rules. 2021-08-20 02:09:31 +00:00
Austin Songer 9a83836070 Update aws_eks_cluster_created_or_deleted.yml 2021-08-19 21:00:36 -05:00
Austin Songer 6ae62488b3 Merge branch 'SigmaHQ:master' into azure_application_gateway_modified_or_deleted.yml 2021-08-19 20:32:35 -05:00
Austin Songer d2f87feb7b Merge branch 'SigmaHQ:master' into azure_application_security_group_modified_or_deleted.yml 2021-08-19 20:31:48 -05:00
frack113 0103b148f7 Merge pull request #1876 from rachelrice/update_cloudtrail_rules
Update AWS CloudTrail rules
2021-08-19 18:33:07 +02:00
frack113 23ad8cd14e remove bad rules 2021-08-19 18:30:32 +02:00
frack113 3283664154 Update remove useless rules 2021-08-19 18:28:44 +02:00
frack113 f1a84536c3 update fix 2021-08-19 17:55:41 +02:00
frack113 39617c9807 Merge pull request #1865 from austinsonger/azure_keyvault_secrets_modified_or_deleted.yml
add azure_keyvault_secrets_modified_or_deleted.yml
2021-08-19 17:06:28 +02:00
frack113 600c6233c2 Merge pull request #1874 from gs3cl/patch-1
Update win_nltest_query.yml
2021-08-19 16:18:20 +02:00
frack113 78212546a7 Merge pull request #1869 from frack113/redcanary_T1546.013
powershell_trigger_profiles T1546.013
2021-08-19 16:17:53 +02:00
frack113 90c9c08743 fix title 2021-08-19 16:09:31 +02:00
Austin Songer cc51e054e3 Update azure_keyvault_secrets_modified_or_deleted.yml 2021-08-19 09:04:22 -05:00
frack113 89b6e1108b powershell_wmi_persistence fix errors 2021-08-19 15:42:19 +02:00
frack113 1266a66a8d add powershell_wmi_persistence.yml 2021-08-19 15:37:28 +02:00
Rachel Rice 67020bb0ff Update AWS CloudTrail rules
aws_elasticache_security_group_created.yml
aws_elasticache_security_group_modified_or_deleted.yml
Removed spaces from eventNames

aws_s3_data_management_tampering.yml
Fix typo in title, use s3 as eventSource

aws_snapshot_backup_exfiltration.yml
Use ec2 as eventSource
2021-08-19 14:24:43 +01:00
frack113 08af3a9429 Cleanup errors 2021-08-19 15:20:04 +02:00
frack113 60931d09b9 fix title error 2021-08-19 14:24:54 +02:00
gs3cl bf9ac21ebc Update win_nltest_recon.yml
change "startswith" to "contains"
2021-08-19 14:12:00 +02:00
frack113 b4a029ac3c Add win_susp_screensaver_reg.yml 2021-08-19 13:55:09 +02:00
Florian Roth 0c6db48ceb Update web_fortinet_cve_2021_22123_exploit.yml 2021-08-19 08:27:15 +02:00
gs3cl df829f0d45 Update and rename win_nltest_query.yml to win_nltest_recon.yml
changes based on feedback added

Update and rename win_nltest_query.yml to win_nltest_recon.yml
2021-08-19 08:26:33 +02:00
Florian Roth 459a0bdca1 Merge pull request #1870 from frack113/fix_fp_Renamed_Powershell
Fix some false positives in  renamed powershell
2021-08-19 08:23:51 +02:00
gs3cl 92b72ffdc1 Update win_nltest_query.yml
modification based on new reports

1.https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11) 
-> for (selection_recon1 and seletion_recon2")
2.https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters -> nltest example
3.MITRE reference just for reference to MITRE to gain more insights
4.https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/ 
-> new Report about Trickbot with reference and usage of "nltest" therefore I included the option in this rule
2021-08-18 20:45:18 +00:00
Austin Songer c9128687ee Spelling Errors on Rules 2021-08-18 18:58:20 +00:00
Austin Songer 36406d5781 Fixed Spelling 2021-08-18 18:53:28 +00:00
Florian Roth 39ef3e0df9 Merge pull request #1872 from SigmaHQ/rule-devel
fix: FPs with WMIADAP.exe
2021-08-18 19:26:17 +02:00
frack113 c7d697e720 Merge pull request #1864 from austinsonger/azure_key_vault_modified_or_deleted.yml
azure_keyvault_modified_or_deleted.yml
2021-08-18 18:30:20 +02:00
frack113 e7132a8498 Merge pull request #1863 from austinsonger/azure_vault_key_modified_or_deleted.yml
azure_keyvault_key_modified_or_deleted.yml
2021-08-18 18:28:46 +02:00