frack113
|
a04fbe2a99
|
Merge pull request #1901 from frack113/redcanary
Redcanary Powershell Suspicious Win32_PnPEntity T1120
|
2021-08-23 19:44:16 +02:00 |
|
frack113
|
07c808d35c
|
Merge pull request #1902 from neu5ron/patch-2
Create zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
|
2021-08-23 19:43:58 +02:00 |
|
Austin Songer
|
1834324a16
|
Update
|
2021-08-23 17:33:57 +00:00 |
|
Austin Songer
|
7d211f2487
|
Data exfiltration to unsanctioned apps
|
2021-08-23 17:33:00 +00:00 |
|
Austin Songer
|
f5286905ff
|
Merge branch 'SigmaHQ:master' into microsoft365
|
2021-08-23 12:22:58 -05:00 |
|
Austin Songer
|
b52f4ba1c3
|
Merge branch 'master' of https://github.com/austinsonger/sigma
|
2021-08-23 17:22:08 +00:00 |
|
Austin Songer
|
3a4c61f44d
|
M365 - Inbox Manipulation Rules
|
2021-08-23 17:21:27 +00:00 |
|
Austin Songer
|
ae84559488
|
M365 - Risky IP Addresses
|
2021-08-23 17:18:16 +00:00 |
|
frack113
|
9d3a13b13e
|
cleanup
|
2021-08-23 19:04:01 +02:00 |
|
Florian Roth
|
998ebbe1f3
|
fix: typo in name
|
2021-08-23 18:46:05 +02:00 |
|
Florian Roth
|
6b86dacc9e
|
rule: razor installer
|
2021-08-23 18:44:15 +02:00 |
|
frack113
|
be316db84d
|
Merge pull request #1899 from secDre4mer/master
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 17:26:16 +02:00 |
|
Nate Guagenti
|
4f8bd4a5a2
|
Update zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
try new uuid to pass check...
|
2021-08-23 11:24:22 -04:00 |
|
Nate Guagenti
|
6aea58b4d2
|
Update zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
|
2021-08-23 11:18:51 -04:00 |
|
frack113
|
cac40065b0
|
Merge pull request #1900 from ZikyHD/add_fields
Add fields to event log cleared
|
2021-08-23 17:15:32 +02:00 |
|
Nate Guagenti
|
78c667fda1
|
Update zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
shorten title
|
2021-08-23 11:15:30 -04:00 |
|
Nate Guagenti
|
96e77eb8db
|
Create zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
|
2021-08-23 11:06:44 -04:00 |
|
SomeOne
|
037f33b5e2
|
Replace by default windows fieldnames
|
2021-08-23 15:24:48 +02:00 |
|
Florian Roth
|
91b42f9077
|
fix: indentation
|
2021-08-23 15:03:59 +02:00 |
|
SomeOne
|
45f30cb2b4
|
Add fields to event log cleared
|
2021-08-23 15:00:07 +02:00 |
|
frack113
|
25072e37b3
|
update references
|
2021-08-23 13:30:46 +02:00 |
|
frack113
|
33c6ff6b5f
|
add powershell_suspicious_win32_pnpentity
|
2021-08-23 13:17:35 +02:00 |
|
Max Altgelt
|
82dde594d1
|
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 11:20:30 +02:00 |
|
frack113
|
52595de85e
|
Merge pull request #1889 from rachelrice/update_aws_rules
Update AWS CloudTrail rules
|
2021-08-23 11:14:31 +02:00 |
|
Florian Roth
|
a0f72e5f6f
|
rule: suspicious splwow64 process starts
|
2021-08-23 10:41:42 +02:00 |
|
Florian Roth
|
dc3ed771b5
|
rule: EfsPotato Named Pipe
|
2021-08-23 08:32:50 +02:00 |
|
frack113
|
8f29075129
|
Merge pull request #1897 from yugoslavskiy/master
add ATC to the "Projects or Products that use Sigma" section
|
2021-08-23 06:30:16 +02:00 |
|
Yugoslavskiy Daniil
|
9b30b487c3
|
add ATC to the Projects or Products that use Sigma section
|
2021-08-23 04:25:29 +02:00 |
|
frack113
|
fc9666fb4e
|
Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
|
2021-08-22 18:56:08 +02:00 |
|
frack113
|
0a410010a2
|
Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
|
2021-08-22 18:50:58 +02:00 |
|
SomeOne
|
295054dcbe
|
Replace old mitre techniques by new one
|
2021-08-22 13:57:56 +02:00 |
|
Thomas Patzke
|
3396d72d81
|
Merge pull request #1887 from frack113/fix_NodeSubexpression_len
fix sigmac error "has no len()"
|
2021-08-22 12:11:16 +02:00 |
|
Thomas Patzke
|
cbf1fd213b
|
Merge pull request #1856 from theoguidoux/sql-sqlite-fields-selection
[Ready] SQL & SQLite rule fields selection
|
2021-08-22 12:09:07 +02:00 |
|
Thomas Patzke
|
b97a47c32a
|
Merge pull request #1895 from frack113/fix_sigma2attack.py
sigma2attack.py fix yaml error
|
2021-08-22 12:05:54 +02:00 |
|
Thomas Patzke
|
ac8cf2b2c7
|
Merge pull request #1783 from iChenLei/update-ci-badge
chore: update sigma ci badge
|
2021-08-22 12:05:23 +02:00 |
|
frack113
|
7cd71b2240
|
fix yaml error
|
2021-08-22 08:57:07 +02:00 |
|
frack113
|
b84b301add
|
Merge pull request #1894 from austinsonger/master
Update m365.yml
|
2021-08-22 07:52:58 +02:00 |
|
Austin Songer
|
579a80411d
|
Update m365.yml
|
2021-08-21 15:03:31 -05:00 |
|
Austin Songer
|
645492cef5
|
Update m365.yml
just working on expanding this.
|
2021-08-21 14:57:38 -05:00 |
|
frack113
|
064c65cb1f
|
Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
|
2021-08-21 18:04:52 +02:00 |
|
frack113
|
07a87aa7f8
|
Merge pull request #1858 from frack113/fix_pr718
Replace pr718
|
2021-08-21 18:02:30 +02:00 |
|
frack113
|
16347e77e4
|
Merge pull request #1893 from pbssubhash/master
Adding a rule to detect WriteHijack DLL exploitation by PowerUp
|
2021-08-21 18:00:40 +02:00 |
|
frack113
|
a44206bfa0
|
Some cleanup
|
2021-08-21 17:33:39 +02:00 |
|
pbssubhash
|
7bcb6494b7
|
Merge branch 'master' of https://github.com/pbssubhash/sigma
|
2021-08-21 20:04:15 +05:30 |
|
pbssubhash
|
eee497f656
|
Title modification
|
2021-08-21 20:04:03 +05:30 |
|
frack113
|
73c953d633
|
Fix title
|
2021-08-21 16:18:16 +02:00 |
|
pbssubhash
|
a415463f5b
|
Modified rule
|
2021-08-21 19:37:28 +05:30 |
|
pbssubhash
|
fba54b8d69
|
First Rule commit
|
2021-08-21 17:47:56 +05:30 |
|
frack113
|
42c90b9d20
|
fix powershell_psattack error
|
2021-08-21 10:05:47 +02:00 |
|
frack113
|
2f683b9ab7
|
fix powershell_clear_powershell_history error
|
2021-08-21 10:00:48 +02:00 |
|