Evan Yu
|
8bdd3e3987
|
Simplify Pass the Pash rule
|
2021-08-27 11:53:28 -04:00 |
|
frack113
|
ff37a49dc0
|
Merge pull request #1930 from SigmaHQ/rule-devel
fix: FPs with whoami rule and 4688 event IDs without parent info
|
2021-08-27 06:27:30 +02:00 |
|
frack113
|
0de795b0a2
|
Merge pull request #1936 from austinsonger/gworkspace_application_remove.yml
add gworkspace_application_remove.yml
|
2021-08-27 06:25:15 +02:00 |
|
frack113
|
00cceb7be8
|
Merge pull request #1935 from austinsonger/gworkspace_mfa_disabled.yml
add gworkspace_mfa_disabled.yml
|
2021-08-27 06:24:26 +02:00 |
|
Austin Songer
|
72485a5619
|
Update gworkspace_application_removed.yml
|
2021-08-26 21:16:21 -05:00 |
|
Austin Songer
|
62cefcc028
|
Rename gworkspace_application_remove.dyml to gworkspace_application_removed.yml
|
2021-08-26 21:15:56 -05:00 |
|
Austin Songer
|
bc246ff59d
|
Rename gworkspace_application_remove.yml to gworkspace_application_remove.dyml
|
2021-08-26 20:58:22 -05:00 |
|
Austin Songer
|
55f5ff3d89
|
Application Removed
|
2021-08-26 20:55:07 -05:00 |
|
Austin Songer
|
1fffb7a3f5
|
Gworkspace MFA disabled.
|
2021-08-26 20:28:35 -05:00 |
|
Roberto Rodriguez
|
f05cf20b12
|
Merge branch 'master' into feature/AADHealth-Agent-HybridADFSServices
|
2021-08-26 16:12:38 -04:00 |
|
Roberto Rodriguez
|
f98970ef06
|
adding basic rules to detect behavior around AAD health agents and AAD Hybrid Health AD FS services in Azure
|
2021-08-26 16:10:42 -04:00 |
|
frack113
|
a6149462d8
|
Merge pull request #1931 from phantinuss/master
More malleable CobaltStrike C2 profiles from new source/reference
|
2021-08-26 17:18:19 +02:00 |
|
frack113
|
59000b993d
|
Merge pull request #1932 from mlp1515/french_user
Add French user
|
2021-08-26 17:12:39 +02:00 |
|
phantinuss
|
e59b8e1e3e
|
add applicable pipe names from regex rule
|
2021-08-26 14:53:20 +02:00 |
|
mlp1515
|
cce7cfc79a
|
Update win_tool_psexec.yml
French language settings
|
2021-08-26 12:51:45 +00:00 |
|
mlp1515
|
e1aa82b412
|
Update win_susp_tscon_localsystem.yml
French language settings
|
2021-08-26 12:50:24 +00:00 |
|
mlp1515
|
e9ed5f592c
|
Update sysmon_always_install_elevated_windows_installer.yml
French language settings
|
2021-08-26 12:48:59 +00:00 |
|
mlp1515
|
4f49f03460
|
Update sysmon_abusing_debug_privilege.yml
French language settings
|
2021-08-26 12:46:15 +00:00 |
|
mlp1515
|
a31422db74
|
Update win_susp_schtask_creation.yml
French language settings
|
2021-08-26 12:45:24 +00:00 |
|
mlp1515
|
5f419d6f35
|
Update win_susp_taskmgr_localsystem.yml
French language settings
|
2021-08-26 12:44:35 +00:00 |
|
mlp1515
|
5545403a9b
|
Update win_whoami_as_system.yml
French language settings
|
2021-08-26 12:43:33 +00:00 |
|
mlp1515
|
7ad927f28e
|
Update win_wmiprvse_spawning_process.yml
French language settings
|
2021-08-26 12:42:47 +00:00 |
|
mlp1515
|
644397e65c
|
Update win_exploit_cve_2019_1388.yml
French language settings
|
2021-08-26 12:41:36 +00:00 |
|
phantinuss
|
dc19268583
|
remove becasue of possible conflict
with a legitimate tool (https://labs.nettitude.com/blog/cve-2017-16245-cve-2017-16246-avecto-defendpoint-multiple-vulnerabilities/)
|
2021-08-26 14:25:12 +02:00 |
|
Florian Roth
|
6c7d355ef5
|
Try to add more pipe names to this non-regex rule
|
2021-08-26 14:00:57 +02:00 |
|
Florian Roth
|
2d36d62e88
|
Merge pull request #1928 from frack113/fix_name_case
fix file name case
|
2021-08-26 13:55:12 +02:00 |
|
Florian Roth
|
24d8701f15
|
fix: null cannot be used in a list with other values
|
2021-08-26 13:54:18 +02:00 |
|
Florian Roth
|
a231aa73b3
|
fix: FPs with whoami rule and 4688 event IDs without parent info
|
2021-08-26 13:33:25 +02:00 |
|
Florian Roth
|
54997553ba
|
Merge pull request #1929 from SigmaHQ/rule-devel
refactor: Mimikatz keyword rule refactoring
|
2021-08-26 13:33:02 +02:00 |
|
phantinuss
|
217dbc768a
|
More malleable CobaltStrike C2 profiles from new source/reference
|
2021-08-26 12:53:43 +02:00 |
|
Florian Roth
|
8b318b9273
|
refactor: Mimikatz keyword rule refactoring
|
2021-08-26 12:51:45 +02:00 |
|
f.hubaut
|
e66007a43d
|
fix file name case
|
2021-08-26 11:15:33 +02:00 |
|
frack113
|
f277ecbbeb
|
Merge pull request #1923 from frack113/fix_invalid_tags
Check invalid tags
|
2021-08-25 10:26:43 +02:00 |
|
frack113
|
a4021842de
|
Fix invalid tags
|
2021-08-25 09:15:57 +02:00 |
|
frack113
|
1d725e8519
|
add gworkspace_user_granted_admin_privileges.yml
|
2021-08-25 08:15:18 +02:00 |
|
frack113
|
061c093f3f
|
Merge pull request #1918 from d4rk-d4nph3/master
Added rule for Arcadyan Router Exploitations
|
2021-08-25 08:10:48 +02:00 |
|
Bhabesh Rai
|
df4180547e
|
Merged rules
|
2021-08-25 11:18:51 +05:45 |
|
Bhabesh Rai
|
a4d0e3453d
|
Fix for CVE tag
|
2021-08-25 10:24:15 +05:45 |
|
frack113
|
e849af9df0
|
Merge pull request #1915 from frack113/tags_cve
fix tags
|
2021-08-25 06:29:48 +02:00 |
|
frack113
|
7028aba3bd
|
Merge pull request #1919 from austinsonger/gworkspace-rules
Role-Based Rules
|
2021-08-24 21:46:15 +02:00 |
|
frack113
|
09a00232fb
|
update references
|
2021-08-24 21:14:59 +02:00 |
|
frack113
|
a5f858b63c
|
update references
|
2021-08-24 21:13:49 +02:00 |
|
Austin Songer
|
ab8cc52dc6
|
Role-Based Rules
|
2021-08-24 10:53:59 -05:00 |
|
Bhabesh Rai
|
ce6141e318
|
Added rule for Arcadyan Router Exploitations
|
2021-08-24 21:11:46 +05:45 |
|
Austin Songer
|
62f2affd03
|
Spelling fix
|
2021-08-24 14:15:50 +00:00 |
|
Florian Roth
|
9f69cead8a
|
Merge pull request #1916 from SigmaHQ/rule-devel
refactor: changed level of rule, refactored RazerInstaller rule
|
2021-08-24 15:42:26 +02:00 |
|
Florian Roth
|
46e312ff0d
|
fix: error in modifier
|
2021-08-24 15:03:23 +02:00 |
|
Florian Roth
|
cc519552aa
|
refactor: RazorInstaller integrity level system
|
2021-08-24 14:54:07 +02:00 |
|
frack113
|
7753f8c22e
|
fix tags
|
2021-08-24 12:36:31 +02:00 |
|
Florian Roth
|
6ca30619ac
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-08-24 12:30:42 +02:00 |
|