Commit Graph

7892 Commits

Author SHA1 Message Date
frack113 600c6233c2 Merge pull request #1874 from gs3cl/patch-1
Update win_nltest_query.yml
2021-08-19 16:18:20 +02:00
frack113 78212546a7 Merge pull request #1869 from frack113/redcanary_T1546.013
powershell_trigger_profiles T1546.013
2021-08-19 16:17:53 +02:00
frack113 90c9c08743 fix title 2021-08-19 16:09:31 +02:00
Austin Songer cc51e054e3 Update azure_keyvault_secrets_modified_or_deleted.yml 2021-08-19 09:04:22 -05:00
frack113 89b6e1108b powershell_wmi_persistence fix errors 2021-08-19 15:42:19 +02:00
frack113 1266a66a8d add powershell_wmi_persistence.yml 2021-08-19 15:37:28 +02:00
Rachel Rice 67020bb0ff Update AWS CloudTrail rules
aws_elasticache_security_group_created.yml
aws_elasticache_security_group_modified_or_deleted.yml
Removed spaces from eventNames

aws_s3_data_management_tampering.yml
Fix typo in title, use s3 as eventSource

aws_snapshot_backup_exfiltration.yml
Use ec2 as eventSource
2021-08-19 14:24:43 +01:00
frack113 08af3a9429 Cleanup errors 2021-08-19 15:20:04 +02:00
frack113 60931d09b9 fix title error 2021-08-19 14:24:54 +02:00
frack113 08324a5a56 Merge pull request #1875 from frack113/fix_sigma_similarity
sigma_similarity fix start errors
2021-08-19 14:16:52 +02:00
gs3cl bf9ac21ebc Update win_nltest_recon.yml
change "startswith" to "contains"
2021-08-19 14:12:00 +02:00
frack113 b4a029ac3c Add win_susp_screensaver_reg.yml 2021-08-19 13:55:09 +02:00
frack113 2cdab46ee4 fix start errors 2021-08-19 09:37:00 +02:00
Florian Roth 0c6db48ceb Update web_fortinet_cve_2021_22123_exploit.yml 2021-08-19 08:27:15 +02:00
gs3cl df829f0d45 Update and rename win_nltest_query.yml to win_nltest_recon.yml
changes based on feedback added

Update and rename win_nltest_query.yml to win_nltest_recon.yml
2021-08-19 08:26:33 +02:00
Florian Roth 459a0bdca1 Merge pull request #1870 from frack113/fix_fp_Renamed_Powershell
Fix some false positives in  renamed powershell
2021-08-19 08:23:51 +02:00
frack113 7bca85e406 Merge pull request #1873 from austinsonger/spelling
Spelling Fixes
2021-08-19 06:15:45 +02:00
gs3cl 92b72ffdc1 Update win_nltest_query.yml
modification based on new reports

1.https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11) 
-> for (selection_recon1 and seletion_recon2")
2.https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters -> nltest example
3.MITRE reference just for reference to MITRE to gain more insights
4.https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/ 
-> new Report about Trickbot with reference and usage of "nltest" therefore I included the option in this rule
2021-08-18 20:45:18 +00:00
Austin Songer 5553534d7c Update README.md 2021-08-18 14:29:02 -05:00
Austin Songer e039f91272 Spelling 2021-08-18 19:00:57 +00:00
Austin Songer c9128687ee Spelling Errors on Rules 2021-08-18 18:58:20 +00:00
Austin Songer 36406d5781 Fixed Spelling 2021-08-18 18:53:28 +00:00
Austin Songer 112a08a54a Merge branch 'SigmaHQ:master' into master 2021-08-18 13:42:45 -05:00
Florian Roth 39ef3e0df9 Merge pull request #1872 from SigmaHQ/rule-devel
fix: FPs with WMIADAP.exe
2021-08-18 19:26:17 +02:00
frack113 c7d697e720 Merge pull request #1864 from austinsonger/azure_key_vault_modified_or_deleted.yml
azure_keyvault_modified_or_deleted.yml
2021-08-18 18:30:20 +02:00
frack113 e7132a8498 Merge pull request #1863 from austinsonger/azure_vault_key_modified_or_deleted.yml
azure_keyvault_key_modified_or_deleted.yml
2021-08-18 18:28:46 +02:00
frack113 768855e6d6 update modified after FP fix 2021-08-18 18:17:53 +02:00
Florian Roth 44013e25c8 fix: FPs with WMIADAP.exe 2021-08-18 17:26:57 +02:00
frack113 2d05eda1be fix ContextInfo FP 2021-08-18 15:18:29 +02:00
frack113 48d0846b53 add powershell_trigger_profiles 2021-08-18 14:29:50 +02:00
frack113 6a282ad24a fix many FP 2021-08-18 13:56:14 +02:00
Bhabesh Rai 8d9f2e059a Added rule for zero day CVE-2021-22123 in Fortinet WAFs 2021-08-18 17:28:57 +05:45
Florian Roth efcf1d9019 Merge pull request #1867 from SigmaHQ/rule-devel
fix: FPs with [reflection.assembly]::Load
2021-08-18 11:42:47 +02:00
Florian Roth a2e45353aa Merge pull request #1825 from frack113/iis_ProxyLogon
rule: ProxyLogon web_cve_2021_26858_iis_rce.yml
2021-08-18 09:54:15 +02:00
Florian Roth 66c674e8e8 Merge pull request #1837 from phantinuss/master
generalise amsi bypass rule to CobaltStrike BOF injection pattern
2021-08-18 09:53:21 +02:00
Florian Roth 5fa5a412d5 fix: FPs with [reflection.assembly]::Load 2021-08-18 09:49:34 +02:00
frack113 136c53190a Merge pull request #1860 from frack113/duplicate_uuid
Update test_missing_id message
2021-08-17 17:13:00 +02:00
Austin Songer 309e71491b Update azure_keyvault_key_modified_or_deleted.yml 2021-08-17 08:44:39 -05:00
Austin Songer 23d0477120 Update azure_keyvault_secrets_modified_or_deleted.yml 2021-08-17 08:42:41 -05:00
Austin Songer 16e0def41d Update and rename azure_vault_key_modified_or_deleted.yml to azure_keyvault_key_modified_or_deleted.yml 2021-08-17 08:31:22 -05:00
Austin Songer ecdcd8f843 Rename azure_key_vault_modified_or_deleted.yml to azure_keyvault_modified_or_deleted.yml 2021-08-17 08:30:10 -05:00
Austin Songer 49ab7d7bb6 Merge branch 'SigmaHQ:master' into azure_application_gateway_modified_or_deleted.yml 2021-08-17 08:29:18 -05:00
Austin Songer 8a7d9d23f5 Merge branch 'SigmaHQ:master' into azure_application_security_group_modified_or_deleted.yml 2021-08-17 08:29:15 -05:00
Austin Songer f0ef01ae09 Merge branch 'SigmaHQ:master' into azure_key_vault_modified_or_deleted.yml 2021-08-17 08:29:12 -05:00
Austin Songer a01d8cc2fe Merge branch 'SigmaHQ:master' into azure_keyvault_secrets_modified_or_deleted.yml 2021-08-17 08:29:09 -05:00
Austin Songer b6922e43e5 Merge branch 'SigmaHQ:master' into master 2021-08-17 08:27:53 -05:00
Florian Roth f36b1cbd2a Merge pull request #1854 from SigmaHQ/rule-devel
rule: Antivirus hacktool events, Procdump rules refactoring
2021-08-17 13:45:07 +02:00
Florian Roth a0625ad074 Merge branch 'master' into rule-devel 2021-08-17 12:29:55 +02:00
Florian Roth 9684c4e55f Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-08-17 12:03:54 +02:00
Florian Roth 80b3acfce9 fix: false positive with Xen / Oracle scripts 2021-08-17 12:03:49 +02:00