Thomas Patzke
65444f7a77
Release 0.16.0
2020-02-25 22:19:52 +01:00
Thomas Patzke
4e42bebb34
Merge branch 'socprime-master'
2020-02-25 21:32:59 +01:00
Florian Roth
a152853ac3
Merge pull request #624 from Antonlovesdnb/master
...
New rules for Macro Detections
2020-02-25 15:44:31 +01:00
Antonlovesdnb
e8b861bff4
Update sysmon_susp_winword_vbadll_load.yml
2020-02-25 09:24:29 -05:00
Antonlovesdnb
4c5d489428
Update sysmon_susp_office_kerberos_dll_load.yml
2020-02-25 09:23:52 -05:00
Antonlovesdnb
f92e2f2b18
Update sysmon_susp_office_dotnet_assembly_dll_load.yml
2020-02-25 09:23:22 -05:00
Antonlovesdnb
8141b1ae90
Update sysmon_susp_office_dsparse_dll_load.yml
2020-02-25 09:22:56 -05:00
Antonlovesdnb
45e4a585bf
Update sysmon_susp_office_dotnet_gac_dll_load.yml
2020-02-25 09:22:37 -05:00
Antonlovesdnb
c5b42aeaed
Update sysmon_susp_office_dotnet_clr_dll_load.yml
2020-02-25 09:19:03 -05:00
Antonlovesdnb
bb1eecfe14
Update sysmon_susp_office_dotnet_assembly_dll_load.yml
2020-02-25 09:17:33 -05:00
Florian Roth
dd1a0e764c
docs: more false positive conditions
2020-02-25 11:13:58 +01:00
Florian Roth
950fa18418
fix: changed titles to avoid duplicates
2020-02-25 11:12:47 +01:00
Florian Roth
5d96f81a84
fix: lowered level due to false positives
2020-02-25 11:12:11 +01:00
Thomas Patzke
5a2ccbd040
Fixed ArcSight backend visibility
2020-02-24 23:27:22 +01:00
Thomas Patzke
6236429f3d
Added/changed CI tests
2020-02-24 23:21:11 +01:00
Thomas Patzke
5b42135935
Added es-rule backend to all ES configurations
2020-02-24 23:20:48 +01:00
Thomas Patzke
d9b48ea747
Fixes in es-rule backend
2020-02-24 23:20:19 +01:00
Thomas Patzke
4ee2c2762e
Sorting of backend and configuration lists
2020-02-24 22:59:59 +01:00
Thomas Patzke
4ac6ddc8ef
Merge branch 'changelog'
2020-02-24 22:35:41 +01:00
Thomas Patzke
fa717233a9
Updated changelog
2020-02-24 22:30:36 +01:00
vh
5dc30bd388
Carbonblack, Arcsight ESM, Elastic Rule
2020-02-24 19:29:45 +02:00
vh
516e61fdb0
t
2020-02-24 19:23:11 +02:00
Florian Roth
91d1586b97
Merge pull request #633 from EccoTheFlintstone/fix_fp
...
rule local account discovery: fix FP on rmdir matching dir
2020-02-24 13:41:39 +01:00
ecco
aa1eff5419
fix FP on rmdir matching dir
2020-02-24 05:23:23 -05:00
Florian Roth
bfab143c7c
Merge pull request #632 from EccoTheFlintstone/fp_fix
...
fix false positive on taskkill.exe not related to service stop at all
2020-02-24 09:58:33 +01:00
Florian Roth
53ca71e7ae
Merge pull request #631 from EccoTheFlintstone/ascii_fix
...
fix non ascii character in rule (probably a typo)
2020-02-24 09:58:13 +01:00
ecco
f807dae69a
fix false positive on taskkill.exe not related to service stop at all
2020-02-24 03:03:46 -05:00
ecco
1703b725d3
fix non ascii character in rule
2020-02-24 02:58:34 -05:00
Thomas Patzke
12be884aa5
Merge branch 'sql-backend'
2020-02-21 22:41:53 +01:00
Thomas Patzke
776b58b594
Improved Splunk Zeek configuration
2020-02-21 22:31:14 +01:00
Thomas Patzke
fa4c76871f
Added CI test for sql backend
2020-02-21 22:27:55 +01:00
Thomas Patzke
746f957a63
Merge branch 'patch-1' of https://github.com/fuseyjz/sigma into fuseyjz-patch-1
2020-02-21 22:24:44 +01:00
Thomas Patzke
3047571132
Merge pull request #625 from ninoseki/fix-sigma2misp
...
Update sigma2misp
2020-02-21 22:22:54 +01:00
Thomas Patzke
61d31c3f3a
Fixed tagging
2020-02-20 23:51:12 +01:00
Thomas Patzke
48d95f027c
Merge branch 'oscd'
2020-02-20 23:11:57 +01:00
Thomas Patzke
373424f145
Rule fixes
...
Made tests pass the new CI tests. Added further allowed lower case words
in rule test.
2020-02-20 23:00:16 +01:00
Manabu Niseki
c6eb3bfbf2
Update sigma2misp
...
Make enable to use with modern PyMISP
2020-02-20 18:55:10 +09:00
Antonlovesdnb
9625a94d0b
Update sysmon_susp_office_dotnet_assembly_dll_load.yml
2020-02-19 14:52:31 -05:00
Antonlovesdnb
6234f72a6c
Update sysmon_susp_office_dotnet_clr_dll_load.yml
2020-02-19 14:52:09 -05:00
Antonlovesdnb
328858279f
Update sysmon_susp_office_kerberos_dll_load.yml
2020-02-19 14:51:50 -05:00
Antonlovesdnb
1f01fe446f
Update sysmon_susp_office_dsparse_dll_load.yml
2020-02-19 14:51:22 -05:00
Antonlovesdnb
6d0805ac13
Update sysmon_susp_winword_vbadll_load.yml
2020-02-19 14:51:00 -05:00
Antonlovesdnb
1e461cb2d1
Update sysmon_susp_office_dotnet_gac_dll_load.yml
2020-02-19 14:50:31 -05:00
Antonlovesdnb
56ffa9ec0e
Update sysmon_registry_trust_record_modification.yml
2020-02-19 14:50:09 -05:00
Antonlovesdnb
397cdecb94
5 Rules covering various macro techniques
...
- Rule to look for GAC DLL loaded by an Office Product
- Rule to look for any DLL in C:\Windows\assembly loaded by an Office Product
- Rule to look for clr.dll loaded by an Office Product
- Rule to look for directory services parsing dll loaded by an Office Product
- Rule to look for kerberos dll loaded by an Office Product
2020-02-19 14:43:13 -05:00
Antonlovesdnb
f8be92dae0
Add files via upload
2020-02-19 10:13:44 -05:00
Florian Roth
a9403b70d5
Merge pull request #623 from Neo23x0/devel
...
fix: fixing too restrictive rule
2020-02-18 11:14:51 +01:00
Florian Roth
6413730810
fix: fixing too restrictive rule
...
https://twitter.com/Hexacorn/status/1229702521679118336
2020-02-18 10:43:22 +01:00
Florian Roth
f7a6ffa121
Merge pull request #622 from Neo23x0/devel
...
Minor changes, process dump via rundll32 comsvcs.dll
2020-02-18 10:26:28 +01:00
Florian Roth
04b97bd84c
fix: character in filename
2020-02-18 10:19:48 +01:00
Florian Roth
5a4095f13f
fix: restored GPL
2020-02-18 10:06:00 +01:00
Florian Roth
cd607d4fed
rule: process dump via rundll32 and comsvcs.dll's MiniDumpW
2020-02-18 10:04:55 +01:00
Florian Roth
73dfc847fc
rule: changed lsass process dump to level high
2020-02-18 10:03:25 +01:00
yugoslavskiy
7f3f1944d9
fix redundancy
2020-02-18 01:10:56 +03:00
Florian Roth
2363213fc9
add TimeSketch to list of products that use Sigma
2020-02-17 08:41:23 +01:00
Thomas Patzke
01d6c3b58d
Fixes
2020-02-16 23:24:00 +01:00
yugoslavskiy
d0e284ae18
fix typo (duplicates)
2020-02-16 18:19:25 +03:00
yugoslavskiy
168ab7c620
Merge branch 'oscd' of https://github.com/Neo23x0/sigma into oscd
2020-02-16 17:57:48 +03:00
Thomas Patzke
f118839664
Further fixes and deduplications
...
From suggestions of @yugoslavskiy in issue #554 .
2020-02-16 14:03:07 +01:00
Thomas Patzke
77c927bc14
Revert "Moved rules with enrichments into unsupported"
...
This reverts commit ba83b8862a .
2020-02-15 22:52:06 +01:00
Florian Roth
eb36150e6b
rule: UserAgent used by PowerTon malware
2020-02-15 19:06:49 +01:00
Florian Roth
d909fefa82
Merge pull request #620 from james0d0a/master
...
rule: Zeek Suspicious kerberos network traffic RC4
2020-02-13 09:34:06 +01:00
Florian Roth
94bb7dd77f
fix: issues
2020-02-13 09:17:21 +01:00
Florian Roth
983f7fcd39
Merge pull request #618 from faloker/master
...
More rules for AWS events
2020-02-13 09:15:04 +01:00
james dickenson
21e4aa33dc
rule modification: fixed filter condition on zeek suspicious rc4 traffic
2020-02-12 21:27:36 -08:00
james dickenson
1347e5060f
logsource config for zeek events in splunk
2020-02-12 21:24:03 -08:00
james dickenson
93367d725d
rule: zeek suspicious kerberos RC4 traffic
2020-02-12 21:21:46 -08:00
faloker
6d9c8e44d7
Update rules titles
2020-02-12 23:09:16 +02:00
faloker
1b15dba712
Correct the indentation
2020-02-12 22:48:46 +02:00
faloker
f387cf0c37
Add the rule to detect changes to startup scripts
2020-02-12 22:23:18 +02:00
faloker
01d2f9f99d
Add the rule to detect backdooring of users keys
2020-02-12 22:22:38 +02:00
faloker
b26c5d8c51
Add rules to detect AWS RDS exfiltration
2020-02-12 22:21:52 +02:00
faloker
ddf5f8ec23
Update conditions
2020-02-12 22:20:15 +02:00
faloker
aacab37f84
Add a rule for guardduty trusted IPs manipulation
2020-02-11 23:28:23 +02:00
faloker
b6c834195e
Add a rule for ec2 userdata exfil
2020-02-11 23:25:54 +02:00
Florian Roth
7a5587f14d
Merge pull request #616 from Neo23x0/devel
...
rule: remove keywords in powershell rule prone to FPs
2020-02-11 16:43:01 +01:00
Florian Roth
a4c210ed16
rule: remove keywords in powershell rule prone to FPs
2020-02-11 16:26:17 +01:00
Florian Roth
bf98d286f9
Merge pull request #615 from Neo23x0/devel
...
fix: dumpert rule with wrong sysmon event id
2020-02-08 20:03:28 +01:00
Florian Roth
d9645af840
rule: added Emotet UA
...
https://twitter.com/webbthewombat/status/1225827092132179968
2020-02-08 10:37:56 +01:00
Florian Roth
880a0b5593
Merge pull request #614 from timbMSFT/gallium_vpn
...
additional gallium ttp
2020-02-07 17:56:09 +01:00
Florian Roth
080532d20c
logsource change
...
I've swapped the lines in the logsource section to make it clearer that the category "process_creation" covers all sources that generate process creation logs on the windows platform.
2020-02-07 15:47:27 +01:00
Tim Burrell (MSTIC)
f70f847524
additional gallium ttp
...
sha1 process creation only makes sense for sysmon
2020-02-07 14:08:40 +00:00
Florian Roth
be9b80d6ab
fix: dumpert rule with wrong sysmon event id
2020-02-07 13:14:18 +01:00
Thomas Patzke
7fdd6f7bce
Swapped accidental deletion of older rule duplicate
2020-02-06 23:41:05 +01:00
Florian Roth
1a80b180fd
Merge pull request #613 from Neo23x0/devel
...
rule: dumpert process dump tool
2020-02-04 23:07:07 +01:00
Florian Roth
10490a6cee
rule: reworked dumpert rule
2020-02-04 22:56:04 +01:00
Florian Roth
1f44969afd
rule: avoiding build issues with sysmon event id 1
2020-02-04 22:50:46 +01:00
Florian Roth
535e2d149b
rule: improved dumpert rule
2020-02-04 22:46:16 +01:00
Florian Roth
8f8b977c85
rule: dumpert process dump tool
2020-02-04 22:38:06 +01:00
Thomas Patzke
d7bd90cb24
Merge branch 'master' into oscd
2020-02-03 23:13:16 +01:00
Thomas Patzke
f7394d09e0
Deduplication
2020-02-03 22:41:55 +01:00
Thomas Patzke
1bc2c0b930
Deduplication of backend list
...
Fixes issue #609 . Added backend list debug output (class name).
2020-02-03 22:16:00 +01:00
Thomas Patzke
666542ae7f
Added colorama to Pipfile
2020-02-03 22:15:27 +01:00
Thomas Patzke
815c562a17
Merge branch 'master' into oscd
2020-02-02 13:40:08 +01:00
Thomas Patzke
f59b36d891
Fixed rule
2020-02-02 12:54:56 +01:00
Thomas Patzke
ba83b8862a
Moved rules with enrichments into unsupported
2020-02-02 12:46:03 +01:00
Thomas Patzke
593abb1cce
OSCD QA wave 3
2020-02-02 12:41:12 +01:00
Florian Roth
016d726d4e
fix: bug in formatting
2020-02-02 11:31:39 +01:00
Florian Roth
dcc7d03c37
docs: better description
2020-02-02 11:31:22 +01:00
Florian Roth
296cf6aa08
fix: fixed examples and added a new one
2020-02-02 09:27:56 +01:00
Florian Roth
68b34467a8
Merge pull request #608 from yt0ng/development
...
additional execution observed
2020-02-02 08:37:59 +01:00
Neis Markus
0d7f55948c
additional execution observed
2020-02-02 08:07:00 +01:00
Florian Roth
aa8a0f5e1f
Merge pull request #606 from Neo23x0/devel
...
refactor: moved rues from 'apt' folder in respective folders
2020-02-01 18:25:19 +01:00
Florian Roth
03ecb3b8dc
refactor: moved rues from 'apt' folder in respective folders
2020-02-01 17:59:26 +01:00
Florian Roth
6ea861da53
Merge pull request #605 from Neo23x0/devel
...
Winnti rule and helpful message in test script
2020-02-01 15:51:16 +01:00
Florian Roth
a752e6c95f
rule: winnti group campaign against HK universities
2020-02-01 15:43:30 +01:00
Florian Roth
9876623710
doc: helpful link in error message
2020-02-01 15:43:11 +01:00
vh
dc5a31aebc
Updated Azure Sentinel backend
2020-01-31 17:17:24 +02:00
Florian Roth
5b157efd7e
Merge pull request #340 from virtuallaik/master
...
Create powershell_nishang_malicious_commandlets.yml + edits
2020-01-31 15:37:59 +01:00
Florian Roth
7a222920df
added 'date'
2020-01-31 15:27:30 +01:00
Florian Roth
913c839780
added 'id'
2020-01-31 15:26:43 +01:00
Florian Roth
848e0c90e4
Merge branch 'master' into master
2020-01-31 14:45:29 +01:00
Florian Roth
aba4f37517
Merge pull request #366 from dvas0004/patch-1
...
Update win_alert_ad_user_backdoors.yml
2020-01-31 14:41:50 +01:00
Florian Roth
1213712978
Merge branch 'master' into patch-1
2020-01-31 14:32:27 +01:00
Florian Roth
afecca3c13
Merge pull request #511 from 4A616D6573/patch-3
...
Created win_susp_local_anon_logon_created.yml
2020-01-31 14:30:54 +01:00
Florian Roth
70034bd793
Merge pull request #388 from yt0ng/Renamed_Files
...
Renamed Jusched
2020-01-31 14:18:28 +01:00
Florian Roth
8c4aadb423
Merge branch 'master' into Renamed_Files
2020-01-31 08:49:10 +01:00
Florian Roth
190afcac88
Missing ID, wrong tag
2020-01-31 07:32:28 +01:00
Florian Roth
e3d61d5579
Missing ID
2020-01-31 07:31:56 +01:00
Florian Roth
033ab26d5e
Added date
2020-01-31 07:21:02 +01:00
Florian Roth
82cae6d63c
Merge pull request #604 from Neo23x0/devel
...
New tests, colorized test output and rule cleanup
2020-01-31 07:07:13 +01:00
Florian Roth
ae2c186872
rule: wsreset.exe UAC bypass
2020-01-30 18:05:47 +01:00
Florian Roth
1735614747
feat: rule title tests
2020-01-30 17:26:21 +01:00
Florian Roth
d42e87edd7
fix: fixed casing and long rule titles
2020-01-30 17:26:09 +01:00
Florian Roth
43af93a678
feat: detect missing date
2020-01-30 16:08:34 +01:00
Florian Roth
14e7b17eb9
feat: detect missing id
2020-01-30 16:08:24 +01:00
Florian Roth
93e1299010
style: PEP8 in test_rules.py
2020-01-30 16:08:10 +01:00
Florian Roth
e79e99c4aa
fix: fixed missing date fields in remaining files
2020-01-30 16:07:37 +01:00
Thomas Patzke
4fa0ae7259
Merge branch 'ruleid'
2020-01-30 16:03:10 +01:00
Florian Roth
efd3af0812
fix: fixed missing date fields in other files
2020-01-30 15:32:39 +01:00
Florian Roth
617ece1aa2
fix: fixed missing date fields in proxy rules
2020-01-30 15:20:52 +01:00
Florian Roth
4ad71c44bc
chore: moved network device rules to the 'network' folder
2020-01-30 14:30:26 +01:00
Florian Roth
5130072b04
Merge pull request #529 from c2defense/master
...
Network Device Analytics
2020-01-30 14:28:44 +01:00
Florian Roth
30d872f98f
Merge pull request #492 from booberry46/master
...
Bypass Windows Defender
2020-01-30 14:27:30 +01:00
Thomas Patzke
7b4ec734a8
Using rule ids as Kibana object id
2020-01-30 11:30:01 +01:00
Florian Roth
598b750f48
Minor change
2020-01-30 10:31:16 +01:00
Florian Roth
8cef4b2941
fix: missing id
2020-01-30 10:14:18 +01:00
Florian Roth
bf81ff90a8
fix: using a specific field
2020-01-30 10:13:33 +01:00
Florian Roth
0207eeece4
fix: hyphen
2020-01-30 10:10:03 +01:00
Florian Roth
2f1890b5e8
Update win_rdp_reverse_tunnel.yml
2020-01-30 10:09:41 +01:00
Florian Roth
8ec0060938
fix: fixing bug
2020-01-30 10:09:22 +01:00
Florian Roth
6ca100cabf
reverted changes
2020-01-30 10:08:25 +01:00
Florian Roth
0a4d32c7c7
fix: fixing issues
2020-01-30 10:07:24 +01:00
Florian Roth
9828d7f81d
re-added old reference
2020-01-30 10:03:09 +01:00
Florian Roth
d90ea6d267
improved rule
2020-01-30 09:58:32 +01:00
Florian Roth
f8e022a709
Fixed indentation
2020-01-30 09:54:41 +01:00
Florian Roth
d2122b6b83
Merge pull request #594 from sreemanshanker/master
...
Sigma rule to Monitor for writing of malicious files to system32 and syswow64 folders
2020-01-30 09:14:58 +01:00
Florian Roth
6adc732d79
Merge pull request #603 from Neo23x0/devel
...
Colorized Testing
2020-01-30 09:14:25 +01:00
Florian Roth
f84b3abf2d
fix: missing commas in list
2020-01-30 08:56:13 +01:00
Florian Roth
aa5ce18abc
feat: support of new MITRE ATT&CK tags
2020-01-30 08:55:44 +01:00
Florian Roth
2c38c53829
fix: removed test rule
2020-01-30 08:52:33 +01:00
Florian Roth
7bf472834b
feat: colorized error messages
2020-01-30 08:50:22 +01:00
Florian Roth
9d96b7c1a3
fix: print_error function not global
2020-01-30 08:39:58 +01:00
Florian Roth
fe6c30fa59
feat: colorized output in test
2020-01-30 08:37:47 +01:00
Florian Roth
a01773681a
fix: filename
2020-01-30 08:18:29 +01:00
Florian Roth
529e95e3a5
Fixed everything
...
This rule had a lot of errors and problems.
- title
- file name
- status stable > experimental
- field order
- indentation
- unnecessary use of regular expressions
- interesting fields incomplete
- missing date
- missing id
- reference not as list
2020-01-30 08:17:46 +01:00
Florian Roth
4c90e636b1
changed file name
2020-01-30 08:07:56 +01:00
Florian Roth
a935cea665
fix: condition
2020-01-30 08:06:53 +01:00
sreemanshanker
d5c7b4795d
Add files via upload
2020-01-30 11:29:01 +08:00
Florian Roth
647d98ac71
Merge pull request #599 from vitaliy0x1/master
...
Detection Rules for AWS events
2020-01-29 21:01:20 +01:00
Florian Roth
376092cfd3
Merge pull request #565 from RiccardoAncarani/master
...
Add Covenant default named pipe
2020-01-29 20:28:00 +01:00
Florian Roth
05d7448a9a
Minor Changes
2020-01-29 20:25:46 +01:00
Florian Roth
d1357ddc50
Minor changes
2020-01-29 20:25:14 +01:00
Florian Roth
8a4f9ad7f8
Minor changes
2020-01-29 20:24:31 +01:00
Florian Roth
a6d7af270d
Added date
2020-01-29 20:23:40 +01:00
Florian Roth
56e1e6b13d
Lower case service name
2020-01-29 20:23:12 +01:00
Florian Roth
f1ce6ba6ad
Lowering level
...
Lowering level to medium for events that can have a legitimate cause
2020-01-29 20:22:34 +01:00
Florian Roth
eac484092c
fix: changed hashes field to sha1 for better consistency
2020-01-29 19:52:24 +01:00
Florian Roth
56576b539f
Merge pull request #602 from Neo23x0/devel
...
rule: FromBase64String command line
2020-01-29 16:12:29 +01:00
Florian Roth
a816f4775f
rule: FromBase64String command line
2020-01-29 16:05:12 +01:00
Florian Roth
1948fd94bd
Merge pull request #601 from Neo23x0/devel
...
Devel
2020-01-28 11:35:57 +01:00
Florian Roth
7786edac29
rule: dctask64.exe evasion techniques
...
https://twitter.com/gN3mes1s/status/1222088214581825540
2020-01-28 11:29:24 +01:00
Florian Roth
d48fc9d1ff
fix: multiple false positive conditions
2020-01-28 10:11:09 +01:00
Florian Roth
240b764660
rule: reduced level of system time mod rule
2020-01-27 14:30:09 +01:00
Florian Roth
60f55cbd2b
Merge pull request #590 from Neo23x0/devel
...
Devel
2020-01-24 16:29:19 +01:00
Florian Roth
df324a59c5
Merge branch 'master' into devel
2020-01-24 16:21:53 +01:00
Florian Roth
5f0589b787
rule: mstsc shadowing
2020-01-24 16:18:19 +01:00
Florian Roth
e24ea159f3
rule: split up renamed binary rule
2020-01-24 15:31:07 +01:00
2d4d
bace799f07
complete_cve_2019-19781
2020-01-24 15:31:06 +01:00
Florian Roth
4066ae6371
rule: added a reference
2020-01-24 15:31:06 +01:00
Florian Roth
11607a8621
rule: windows audit cve
2020-01-24 15:31:06 +01:00
Florian Roth
f40a7aab3d
rule: changes at Shitrix rule
2020-01-24 15:31:06 +01:00
Thomas Patzke
d408c0fd34
Added ala-rule backend to CI testing
2020-01-24 15:31:06 +01:00
Thomas Patzke
8525e9e961
Moved ala-rule backend code into ala backend module
2020-01-24 15:31:06 +01:00
sbousseaden
a4e62fcb1b
Update win_lm_namedpipe.yml
2020-01-24 15:31:06 +01:00
neu5ron
ee1ae805d3
fix name of network_initiated
2020-01-24 15:31:06 +01:00
2d4d
341ed340a3
add newbm.pl
2020-01-24 15:31:06 +01:00
Florian Roth
4e07a786a7
rule: updated netscaler rule
2020-01-24 15:31:06 +01:00
Florian Roth
c22f7b0b65
fix: shortened path in Citrix Netscaler rule
2020-01-24 15:31:06 +01:00
2d4d
d0230f0024
add rule for Citrix Netscaler CVE-2019-19781
2020-01-24 15:31:06 +01:00
2d4d
0bde8b5f00
add rule for Citrix Netscaler CVE-2019-19781
2020-01-24 15:31:06 +01:00
Tim Burrell (MSTIC)
a371cf1057
fixup - unique rule id; use process_creation instead of sysmon EventID:1
2020-01-24 15:31:06 +01:00
Tim Burrell (MSTIC)
c24bbdcf81
Sigma queries for
...
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-24 15:31:06 +01:00
Maxime Lamothe-Brassard
d1774f7735
Fixed actual event tag
2020-01-24 15:31:06 +01:00
Maxime Lamothe-Brassard
1bfb809b6f
Mapping OriginalFileName to event/INTERNAL_NAME now that it's available.
2020-01-24 15:31:06 +01:00
SOC Prime
2aae27f0a4
Update ala-rule.py
2020-01-24 15:31:06 +01:00
SOC Prime
85f09419fb
Update ala-rule.py
2020-01-24 15:31:06 +01:00
vh
8d30459532
Azure Sentinel backend (ala) - Fixed path in query
...
Added new backend Azure Sentinel Rule (ala-rule)
2020-01-24 15:31:06 +01:00
msec1203
4f29556a01
Update win_susp_winword_wmidll_load.yml
...
Update x2
2020-01-24 15:31:06 +01:00
msec1203
48a071ad4e
Update win_susp_winword_wmidll_load.yml
...
Fix to error on incorrect mitre tags used.
2020-01-24 15:31:06 +01:00
GelosSnake
8fbe08d5fa
Update win_system_exe_anomaly.yml
...
fixing to much original fork.
2020-01-24 15:31:06 +01:00
GelosSnake
9f3672fdc0
Update win_system_exe_anomaly.yml
...
Following sigma event I've noticed my twitter account was referenced:
https://twitter.com/GelosSnake/status/934900723426439170
Rule:
https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_system_exe_anomaly.yml
Seems like - '\SystemRoot\System32\\*' is missing and hence triggering an FP.
2020-01-24 15:31:06 +01:00
msec1203
4260d01ff0
Initial Upload
...
Submit Sigma Rule For Detecting Word Loading WMI DLL's.
2020-01-24 15:31:06 +01:00
Justin Schoenfeld
5f8b152166
Added new sticky key attack binary
2020-01-24 15:31:06 +01:00
david-burkett
5d04c76f68
svchost spawned without cli
2020-01-24 15:31:06 +01:00
Florian Roth
72341f08c5
Added MITRE ATT&CK Technique T1482
...
https://attack.mitre.org/techniques/T1482/
2020-01-24 15:31:06 +01:00
david-burkett
032c382184
corrected logic
2020-01-24 15:31:06 +01:00
David Burkett
991e3b8a51
Trickbot behavioral recon activity
2020-01-24 15:31:06 +01:00
Alessio Dalla Piazza
9f7eee8bb1
Add the ability to detect PowerUp - Invoke-AllChecks
...
PowerUp allow attackers to check if is possible to have a local privilege escalation attacks against Windows systems. The main function is called "Invoke-AllChecks" and check possible path of escalation.
2020-01-24 15:31:06 +01:00
Thomas Patzke
0f4aef1000
Added sigma2attack to CI testing
2020-01-24 15:31:06 +01:00
vitaliy0x1
5aa75a90fd
added aws_root_account_usage.yml
2020-01-21 15:07:32 +02:00
vitaliy0x1
0d6642abd6
added aws_config_disable_recording.yml
2020-01-21 15:07:10 +02:00
vitaliy0x1
17c00d8a11
added aws_cloudtrail_disable_logging.yml
2020-01-21 15:06:44 +02:00
Vitaliy
ffcc2dc049
Merge pull request #1 from Neo23x0/master (fetch upstream)
...
fetch upstream
2020-01-20 14:18:48 +02:00
Thomas Patzke
5f1e933b93
Merge pull request #588 from timbMSFT/timb
...
Sigma queries - defense evasion by tampering with svchost; recently released GALLIUM activity group IOCs
2020-01-20 10:06:06 +01:00
Thomas Patzke
9bb50f3d60
OSCD QA wave 2
...
* Improved rules
* Added filtering
* Adjusted severity
2020-01-17 15:46:28 +01:00
Florian Roth
e9012d57f7
Merge pull request #596 from 2d4d/master
...
complete_cve_2019-19781
2020-01-16 12:46:25 +01:00
2d4d
e35ebcc185
complete_cve_2019-19781
2020-01-15 21:59:33 +01:00
Florian Roth
41c4a499b4
rule: added a reference
2020-01-15 21:27:40 +01:00
Florian Roth
6db20d4bad
rule: windows audit cve
2020-01-15 21:23:32 +01:00
Florian Roth
5ef64e4e99
rule: changes at Shitrix rule
2020-01-13 20:15:08 +01:00
Florian Roth
a0bad54dbd
Merge pull request #592 from 2d4d/fix_web_citrix_cve_2019_19781_exploit.yml
...
add newbm.pl
2020-01-13 14:48:38 +01:00
Thomas Patzke
7216fe400f
Merge branch 'ala-rule'
2020-01-13 13:49:53 +01:00
Thomas Patzke
d95a2606f0
Merge branch 'socprime-master' into ala-rule
2020-01-13 13:48:19 +01:00
Thomas Patzke
638d461b16
Added ala-rule backend to CI testing
2020-01-13 13:47:11 +01:00
Thomas Patzke
7b62b931ce
Moved ala-rule backend code into ala backend module
2020-01-13 11:24:46 +01:00
Florian Roth
e89b4b1c1f
Merge pull request #595 from sbousseaden/patch-1
...
Update win_lm_namedpipe.yml
2020-01-13 11:21:24 +01:00
Thomas Patzke
de690cbfbf
Merge branch 'master' of https://github.com/socprime/sigma into socprime-master
2020-01-13 11:19:39 +01:00
sbousseaden
b60671397d
Update win_lm_namedpipe.yml
2020-01-13 10:50:35 +01:00
Florian Roth
ba7c634f1a
More changes
2020-01-13 09:59:14 +01:00
Florian Roth
7bd820c151
Changes
2020-01-13 09:56:49 +01:00
Florian Roth
53d76a69c1
Merge pull request #593 from neu5ron/updates_to_sigma_master
...
HELK SIGMAC fix name of network_initiated
2020-01-13 09:51:13 +01:00
sreemanshanker
8833b43cea
Merge pull request #1 from sreemanshanker/sreemanshanker-patch-1
...
Add files via upload
2020-01-13 13:21:29 +08:00
sreemanshanker
ffcfcb70ad
Add files via upload
2020-01-13 13:21:06 +08:00
neu5ron
d8b703462d
fix name of network_initiated
2020-01-13 00:12:04 -05:00
2d4d
364e859a6b
add newbm.pl
2020-01-12 00:29:10 +01:00
Thomas Patzke
ae6fcefbcd
Removed ATT&CK technique ids from titles and added tags
2020-01-11 00:33:50 +01:00
Thomas Patzke
8d6a507ec4
OSCD QA wave 1
...
* Checked all rules against Mordor and EVTX samples datasets
* Added field names
* Some severity adjustments
* Fixes
2020-01-11 00:11:27 +01:00
Thomas Patzke
b34bf98c61
Fixed rule: added condition
2020-01-07 15:20:16 +01:00
Florian Roth
a29c832b6a
rule: updated netscaler rule
2020-01-07 14:42:16 +01:00
Florian Roth
c9a75a8371
fix: shortened path in Citrix Netscaler rule
2020-01-07 13:00:28 +01:00
Florian Roth
48f5f480fd
fix: SCCM false positives with whoami.exe rule
2020-01-07 12:13:47 +01:00
Florian Roth
b03a43ca1b
Merge pull request #589 from 2d4d/add_cve_2019-19781
...
add rule for Citrix Netscaler CVE-2019-19781
2020-01-06 14:15:46 +01:00
2d4d
35fbdd1248
add rule for Citrix Netscaler CVE-2019-19781
2020-01-03 01:48:29 +01:00
2d4d
b98e57603e
add rule for Citrix Netscaler CVE-2019-19781
2020-01-03 00:34:52 +01:00
Tim Burrell (MSTIC)
9bd0402681
fixup - unique rule id; use process_creation instead of sysmon EventID:1
2020-01-02 20:05:28 +00:00
Tim Burrell (MSTIC)
5051334e85
Sigma queries for
...
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-02 14:47:55 +00:00
Florian Roth
fd28a64591
rule: WCE
2019-12-31 09:27:38 +01:00
Florian Roth
ed5c77e1be
Merge pull request #587 from refractionPOINT/internal-name
...
Adding LimaCharlie support for OriginalFileName field.
2019-12-31 08:32:51 +01:00
Maxime Lamothe-Brassard
a3ad7cb1c5
Fixed actual event tag
2019-12-30 18:15:12 -08:00
Maxime Lamothe-Brassard
9b32086d92
Mapping OriginalFileName to event/INTERNAL_NAME now that it's available.
2019-12-30 15:58:18 -08:00
SOC Prime
92bc96a308
Update ala-rule.py
2019-12-30 16:26:30 +02:00
vh
f2117f798a
Fix ala-rule
2019-12-30 16:24:08 +02:00
SOC Prime
f015c97dff
Update ala-rule.py
2019-12-30 16:13:27 +02:00
vh
f9570a48cb
Azure Sentinel backend (ala) - Fixed path in query
...
Added new backend Azure Sentinel Rule (ala-rule)
2019-12-30 16:11:53 +02:00
vh
d42409372c
Azure Sentinel backend (ala) - Fixed path in query
...
Added new backend Azure Sentinel Rule (ala-rule)
2019-12-30 16:09:19 +02:00
Florian Roth
c007ecf90c
Merge pull request #585 from Neo23x0/devel
...
Devel
2019-12-30 15:08:43 +01:00
SOC Prime
9c18f20e7b
Merge pull request #3 from Neo23x0/master
...
latest sigmac
2019-12-30 16:02:46 +02:00
Florian Roth
5980cb8d0c
rule: copy from admin share - lateral movement
2019-12-30 14:25:43 +01:00
Florian Roth
86e6b92903
rule: SecurityXploded tool
2019-12-30 14:25:29 +01:00
Florian Roth
5ad793e04a
Merge pull request #582 from tvjust/patch-1
...
Added new sticky key attack binary
2019-12-30 14:14:20 +01:00
Florian Roth
948af2993b
Merge pull request #583 from msec1203/msec1203-submit-rule1
...
MS Office Doc Load WMI DLL Rule
2019-12-30 14:13:58 +01:00
msec1203
dbdf6680e0
Update win_susp_winword_wmidll_load.yml
...
Update x2
2019-12-30 18:49:39 +09:00
msec1203
a45f877712
Update win_susp_winword_wmidll_load.yml
...
Fix to error on incorrect mitre tags used.
2019-12-30 18:41:16 +09:00
Florian Roth
e043bc2193
Merge pull request #584 from GelosSnake/master
...
FP in win_system_exe_anomaly.yml
2019-12-29 18:52:43 +01:00
GelosSnake
f574c20432
Update win_system_exe_anomaly.yml
...
fixing to much original fork.
2019-12-29 18:02:49 +02:00
GelosSnake
7e7f6d1182
Update win_system_exe_anomaly.yml
...
Following sigma event I've noticed my twitter account was referenced:
https://twitter.com/GelosSnake/status/934900723426439170
Rule:
https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_system_exe_anomaly.yml
Seems like - '\SystemRoot\System32\\*' is missing and hence triggering an FP.
2019-12-29 18:01:19 +02:00
msec1203
845d67f1f3
Initial Upload
...
Submit Sigma Rule For Detecting Word Loading WMI DLL's.
2019-12-29 23:14:29 +09:00
Justin Schoenfeld
a1f07cdb4b
Added new sticky key attack binary
2019-12-29 08:32:23 -05:00
Florian Roth
042c58dfc1
Merge pull request #581 from david-burkett/master
...
Trickbot behavioral recon activity / svchost spawned without CLI
2019-12-28 18:11:34 +01:00
david-burkett
4a65a25070
svchost spawned without cli
2019-12-28 10:28:08 -05:00
Florian Roth
5e59bbb3c3
Added MITRE ATT&CK Technique T1482
...
https://attack.mitre.org/techniques/T1482/
2019-12-28 16:02:26 +01:00
david-burkett
35b4806104
corrected logic
2019-12-28 09:55:39 -05:00
David Burkett
474a8617e5
Trickbot behavioral recon activity
2019-12-27 21:25:53 -05:00
Yugoslavskiy Daniil
3a3cd5a830
Merge branch 'master' into oscd
2019-12-28 03:27:13 +03:00
fuseyjz
0b2f88d5df
Sigma converter for SQL format
...
Get the converted SQL query after the WHERE statement for any filtering on SQL platform.
Example:
https://github.com/fuseyjz/sigma-sql/blob/master/README.md
2019-12-24 10:42:25 +08:00
Florian Roth
62bd2cc3ab
Merge pull request #572 from alessiodallapiazza/master
...
Add the ability to detect PowerUp - Invoke-AllChecks
2019-12-23 12:57:55 +01:00
Alessio Dalla Piazza
0ff81cc693
Merge pull request #1 from alessiodallapiazza/alessiodallapiazza-patch-1
...
Add the ability to detect PowerUp - Invoke-AllChecks
2019-12-23 11:51:34 +01:00
Alessio Dalla Piazza
f45587074b
Add the ability to detect PowerUp - Invoke-AllChecks
...
PowerUp allow attackers to check if is possible to have a local privilege escalation attacks against Windows systems. The main function is called "Invoke-AllChecks" and check possible path of escalation.
2019-12-23 11:50:57 +01:00
Florian Roth
04afcccd2c
Merge pull request #571 from Neo23x0/devel
...
rule: whoami as local system
2019-12-22 19:23:50 +01:00
Florian Roth
fc8607bbea
rule: whoami as local system
2019-12-22 18:50:26 +01:00
Florian Roth
a7ca386a1b
Merge pull request #570 from Neo23x0/devel
...
CreateMiniDump
2019-12-22 08:40:45 +01:00
Florian Roth
fb76f2b9ac
rule: CreateMiniDump
2019-12-22 08:29:12 +01:00
Florian Roth
511229c0b6
rule: modified Bloodhound rule
2019-12-21 21:22:13 +01:00
Thomas Patzke
530ac854df
Added sigma2attack to CI testing
2019-12-20 22:53:22 +01:00
Thomas Patzke
781f53332b
Merge pull request #566 from christophetd/sigma2attack
...
Add sigma2attack
2019-12-20 21:57:02 +01:00
Florian Roth
1fd4c26005
Merge pull request #569 from Neo23x0/devel
...
rule: improved bloodhound rule
2019-12-20 17:32:21 +01:00
Florian Roth
0fa5ba925e
rule :improved bloodhound rule
2019-12-20 17:23:40 +01:00
Florian Roth
cbebaf637f
Merge pull request #568 from Neo23x0/devel
...
Devel
2019-12-20 16:22:29 +01:00
Florian Roth
0e82dce2a0
fix: fixed wrong condition
2019-12-20 16:11:39 +01:00
Florian Roth
0000257371
rule: improved bloodhound rule
2019-12-20 16:08:26 +01:00
Florian Roth
3a933c38f2
rule: changed level of BloodHound rule
2019-12-20 15:37:58 +01:00
Florian Roth
68efeb909d
rule: false positive condition for BloodHound rule
2019-12-20 15:35:13 +01:00
Florian Roth
825b1edb0f
Merge pull request #567 from Neo23x0/devel
...
Devel
2019-12-20 15:32:56 +01:00
Florian Roth
5f061c15d0
fix: fixed missing condition
2019-12-20 15:18:05 +01:00
Florian Roth
bb466407ee
rule: operation Wocao activity
2019-12-20 15:00:07 +01:00
Florian Roth
708c17e2bc
rule: Bloodhound
2019-12-20 14:59:36 +01:00
Florian Roth
ab038d1ac7
style: minor changes
2019-12-20 14:59:26 +01:00
Thomas Patzke
9ca52259dd
Fixed identifier
2019-12-20 00:11:34 +01:00
Thomas Patzke
924e1feb54
UUIDs + moved unsupported logic
...
* Added UUIDs to all contributed rules
* Moved unsupported logic directory out of rules/ because this breaks CI
testing.
2019-12-19 23:56:36 +01:00
Thomas Patzke
694d666539
Merge branch 'master' into oscd
2019-12-19 23:15:15 +01:00
christophetd
e99b0fe2d7
Add sigma2attack
2019-12-19 00:00:13 +01:00
Riccardo Ancarani
8b70cb6761
Add Covenant default named pipe
...
Covenant (https://github.com/cobbr/Covenant ) can use named pipes for peer to peer communication.
The default named pipe name is "\gruntsvc".
References: https://posts.specterops.io/designing-peer-to-peer-command-and-control-ad2c61740456
2019-12-18 15:19:47 +00:00
Florian Roth
0a26184286
Merge pull request #563 from Neo23x0/devel
...
Devel
2019-12-17 14:48:07 +01:00
Florian Roth
c8b6b5c556
rule: updating csc.exe rule
2019-12-17 13:45:40 +01:00
Florian Roth
7a3041c593
rule: improved csc.exe rule
2019-12-17 11:05:43 +01:00
Thomas Patzke
397b3b8cc6
Updated rule test MITRE ATT&CK identifiers
2019-12-17 01:13:06 +01:00
Florian Roth
e8d92fab0c
rule: ryuk ransomware
2019-12-16 20:33:12 +01:00
Florian Roth
da06e5bc1c
Merge pull request #562 from Neo23x0/devel
...
Improved PowerShell Encoded Command Rule
2019-12-16 19:31:15 +01:00
Florian Roth
bbaa9df217
rule: better JAB rule
2019-12-16 19:08:51 +01:00
Florian Roth
f83eb2268e
rule: improved JAB expression
2019-12-16 19:04:05 +01:00
Florian Roth
bd7c996588
rule: suspicious PS rule modified to cover newest malware campaigns
2019-12-16 19:02:57 +01:00
Thomas Patzke
ef63a65efe
Converted to Unix line end
2019-12-15 23:30:42 +01:00
Yugoslavskiy Daniil
d19df2e4f7
fix issues with wrong tagging
2019-12-15 00:17:22 +01:00
Yugoslavskiy Daniil
9a511e5e62
fix issue with doubled detection section in apt_silence_downloader_v3.yml
2019-12-15 00:06:28 +01:00
Florian Roth
7acfecbe66
Merge pull request #530 from bartblaze/master
...
Add scriptlets
2019-12-14 11:24:51 +01:00
Thomas Patzke
d2a940a0a6
Merge branch 'devel' of https://github.com/Neo23x0/sigma
2019-12-13 22:01:40 +01:00
Thomas Patzke
5930c1c290
Updated changelog
2019-12-13 22:00:40 +01:00
Thomas Patzke
ee4138c48e
Merge pull request #526 from zouzias/hotfix_aggregate_count_distinct_groupby
...
[feature] extend es-dsl to support nested aggregations
2019-12-13 21:55:47 +01:00
Thomas Patzke
a25b2ec361
Merge pull request #523 from refractionPOINT/lc-added-mtd
...
LC added FP metadata
2019-12-13 21:50:52 +01:00
Thomas Patzke
1369b3a2dc
Merge pull request #537 from webhead404/webhead404-contrib-sigma
...
Added sigma rule to detect external devices or USB drive
2019-12-13 21:50:01 +01:00
Thomas Patzke
38b3ace461
Merge pull request #556 from Karneades/fixChangelog
...
Add release date for each version in changelog
2019-12-13 21:47:58 +01:00
Thomas Patzke
7a280ae092
Merge pull request #557 from robrankin/fix_dupe_rule_name
...
Elastalert error, duplicate rule titles
2019-12-13 21:46:58 +01:00
Florian Roth
1b42f2a0e2
Merge pull request #561 from Neo23x0/devel
...
Devel
2019-12-12 13:34:58 +01:00
Florian Roth
67dfd729fd
rule: extended Proxy UA suspicious rule
2019-12-12 10:42:23 +01:00
Florian Roth
9c59e3cf13
Merge branch 'master' into devel
2019-12-12 09:40:02 +01:00
Florian Roth
065df363dc
rule: added Empire UA
2019-12-12 09:39:28 +01:00
Florian Roth
c25b902add
Merge pull request #558 from vburov/patch-7
...
Added svchost.exe as a parent image
2019-12-10 20:17:22 +01:00
Florian Roth
611b72dba5
Merge pull request #559 from vburov/patch-8
...
Added some suspicious locations
2019-12-10 20:15:16 +01:00
Vasiliy Burov
977551c69d
Added some suspicious locations
...
Added 'C:\Windows\Tasks' and 'C:\Windows\System32\Tasks' as suspicious locations accordingly article: https://github.com/ThreatHuntingProject/ThreatHunting/blob/master/hunts/suspicious_process_creation_via_windows_event_logs.md
2019-12-10 20:17:40 +03:00
Vasiliy Burov
0dd4324aba
Added svchost.exe as a parent image
...
Added svchost.exe as a parent image accordingly this article (https://www.carbonblack.com/2014/06/10/screenshot-demo-hunt-evil-faster-than-ever-with-carbon-black/ ) and my investigations.
2019-12-10 19:31:12 +03:00
Karneades
fd4536afb5
Resolve PR #556 merge conflict
2019-12-09 21:23:00 +01:00
Rob Rankin
e251568760
Data Compressed duplciate titles
2019-12-09 16:24:10 +00:00
Rob Rankin
b771dd3d3b
Rule name conflicts in Elastalert output
2019-12-09 16:14:28 +00:00
Thomas Patzke
b701e9be50
Added ECS proxy configuration
2019-12-09 16:34:07 +01:00
Karneades
1c05b858fd
Add release date for each version in changelog
2019-12-09 16:18:58 +01:00
Thomas Patzke
a9d6158dde
Merge branch 'rules'
2019-12-09 16:17:39 +01:00
Thomas Patzke
2ea87f187c
Added Ursnif proxy detections
2019-12-09 16:02:10 +01:00
Yugoslavskiy Daniil
185a634bd9
update authors for 2 rules
2019-12-07 02:10:06 +01:00
Yugoslavskiy Daniil
4789b15fd5
add rules by Sergey Soldatov, Kaspersky Lab
2019-12-07 01:45:55 +01:00
Thomas Patzke
991108e64d
Further proxy field name fixes (config + rules)
2019-12-07 00:23:30 +01:00
Thomas Patzke
dd8442590f
Fixed proxy rule field names
2019-12-07 00:11:33 +01:00
Thomas Patzke
51e9689425
Sigmatool release 0.15.0
2019-12-06 22:13:44 +01:00
Thomas Patzke
58d8512396
Merge pull request #553 from berggren/patch-1
...
Add source distribution for PyPi when building
2019-12-06 22:10:19 +01:00
Johan Berggren
d8e1f56219
Add source distribution for PyPi when building
...
Add sdist when building. This makes it easier to build packages from PyPi for example Debian PPA pkgs etc.
This will not affect anything else, just make the source distribution available in PyPi as a tar.gz archive.
If this gets merged, please bump the version and push to PyPi as well.
2019-12-06 15:45:28 +01:00
Florian Roth
e1244acf49
rule: fixed and extended bitsadmin rule
2019-12-06 13:39:04 +01:00
Florian Roth
c1647ca4b7
Merge branch 'master' into devel
2019-12-06 13:38:29 +01:00
Florian Roth
e91a79e707
Merge pull request #550 from refractionPOINT/lc-proxy-support
...
LimaCharlie basic support for Proxy rule category.
2019-12-06 08:20:14 +01:00
Florian Roth
6359223390
Merge pull request #551 from axi0m/patch-1
...
Add hastebin raw URI to contains selection
2019-12-06 08:19:44 +01:00
Kevin Dienst
865251238f
Add hastebin raw URI to contains selection
2019-12-05 14:16:20 -06:00
Maxime Lamothe-Brassard
27bb07b74e
Adding support for basic proxy rules using the HTTP_REQUEST events from the Chrome LC Agent.
2019-12-05 09:35:09 -08:00
Florian Roth
ab2dd094a5
fix: fixed broken link in elise rule
2019-12-05 09:56:20 +01:00
Florian Roth
8e107f43a2
rule: raw paste service access
2019-12-05 08:54:49 +01:00
Thomas Patzke
ad7d5d2a39
Added WMI login rule
2019-12-04 11:13:04 +01:00
Thomas Patzke
e8c1c97f3e
Added rule for failed code integrity checks
2019-12-03 15:08:26 +01:00
Thomas Patzke
c47af5169c
Increased SID history rule severity
2019-12-03 14:28:46 +01:00
Thomas Patzke
76578927e8
Added domain trust rule
2019-12-03 14:28:20 +01:00
Florian Roth
c8e29da7ec
fix: simplified rule with RE
2019-12-03 11:24:06 +01:00
Florian Roth
fc09533f56
style: fixed title
2019-12-03 11:24:06 +01:00
yugoslavskiy
15cb1c42a9
Merge branch 'mrblacyk-oscd' into oscd
2019-12-02 02:57:07 +01:00
yugoslavskiy
edad1695f6
Merge branch 'oscd' of https://github.com/mrblacyk/sigma into mrblacyk-oscd
2019-12-02 02:56:53 +01:00
yugoslavskiy
48a94d1609
Update lnx_dd_delete_file.yml
2019-12-02 02:54:48 +01:00
yugoslavskiy
ca1c2f4436
Update lnx_chattr_immutable_removal.yml
2019-12-02 02:54:32 +01:00
yugoslavskiy
9e90335a5a
Update lnx_pers_systemd_reload.yml
2019-12-02 02:54:13 +01:00
yugoslavskiy
46ca68436e
Update lnx_file_or_folder_permissions.yml
2019-12-02 02:53:35 +01:00
yugoslavskiy
1273a10dcb
add win_new_service_creation.yml
2019-12-02 01:19:54 +01:00
yugoslavskiy
9fba097421
add sysmon_in_memory_powershell.yml by Tom Kern
2019-12-01 23:26:00 +01:00
booberry46
df162b232f
Update win_malware_emotet.yml
2019-11-30 13:17:44 +08:00
Thomas Patzke
98be3ce069
Fixed changelog (missing title)
2019-11-30 00:34:17 +01:00
mrblacyk
9d0889def4
Adding auditd compatibility
2019-11-29 09:34:08 +01:00
mrblacyk
cafbb25d2e
Update lnx_file_or_folder_permissions.yml
2019-11-29 09:33:04 +01:00
mrblacyk
bf5e6cc56b
Adding auditd compatibility
2019-11-29 09:32:05 +01:00
mrblacyk
a15c84eb80
Adding auditd compatibility
2019-11-29 09:27:31 +01:00
Yugoslavskiy Daniil
71e588cae1
add apt silence rules by Group-IB
2019-11-28 21:15:55 +01:00
yugoslavskiy
d5722979ea
add rules by Daniel Bohannon
2019-11-27 00:02:45 +01:00
yugoslavskiy
41a09cde34
updated filenames
2019-11-26 23:31:18 +01:00
webhead404
21ef152e3a
Update win_external_device.yml
2019-11-20 16:19:45 -06:00
webhead404
2bfd4ea654
Added MITRE tags
2019-11-20 16:18:03 -06:00
webhead404
b96ad8ccd7
Merge pull request #2 from webhead404/webhead404-contrib
...
Create win_external_device
2019-11-20 16:09:15 -06:00
webhead404
5c5d28acdc
Create win_external_device
2019-11-20 16:07:29 -06:00
Florian Roth
39293d5f2b
rule: another reference for CVE-2019-1388 rule
2019-11-20 15:09:30 +01:00
Florian Roth
00a26dff16
Merge pull request #536 from Neo23x0/devel
...
Changes to CVE-2019-1388 rule
2019-11-20 09:27:56 +01:00
Florian Roth
f9e6a929ba
rule: made it more specific - command line must contain URL
2019-11-20 09:23:04 +01:00
Florian Roth
55e66b1843
rule: added status
2019-11-20 09:21:42 +01:00
Florian Roth
0b9cd47c1e
Merge pull request #535 from Neo23x0/devel
...
Rule to detect CVE-2019-1388
2019-11-20 09:19:52 +01:00
Florian Roth
4022e3251b
rule: changed title
2019-11-20 09:16:00 +01:00
Florian Roth
158f6b3065
rule: exploitation of CVE-2019-1388
2019-11-20 09:12:02 +01:00
Florian Roth
a6d069c6d2
Merge branch 'master' into devel
2019-11-19 15:59:22 +01:00
Florian Roth
98aa4d4ecb
fix: fixed typo in rule for renamed procdump
2019-11-19 15:59:07 +01:00
yugoslavskiy
1b591ee598
add JET CSIRT team sysmon_process_reimaging.yml with unsupported logic
2019-11-19 02:17:07 +01:00
yugoslavskiy
2a33e6fed9
unify location of rules with unsupported logic
2019-11-19 02:12:22 +01:00
yugoslavskiy
efc404fbae
resolve conflicts with rule IDs; restored and deprecated sysmon_mimikatz_detection_lsass.yml
2019-11-19 02:11:19 +01:00
Maxime Lamothe-Brassard
61bcc46394
Prettier formatting of YAML.
2019-11-18 14:50:41 -05:00
Florian Roth
0dd583510a
Merge pull request #534 from Neo23x0/devel
...
rules and fixes
2019-11-18 16:01:26 +01:00
Florian Roth
2c855be9d3
fix: casing fix in renamed procdump rule
2019-11-18 15:57:14 +01:00
Florian Roth
fdc32889a7
rule: PulseSecure CVE-2019-11510 attack
2019-11-18 15:33:58 +01:00
Florian Roth
93f890b31d
rule: renamed procdump
2019-11-18 15:27:04 +01:00
Florian Roth
da05c9bb82
fix: line break in description
2019-11-18 15:26:55 +01:00
Florian Roth
2c54d1afe4
rule: removed Zebrocy rule because it doesn't work that way
...
reason: command line gets split up at the '&' character, which results in two command lines
2019-11-18 11:42:38 +01:00
Austin Clark
ad1a6a2bd3
Update cisco_cli_net_sniff.yml
2019-11-15 19:32:53 +01:00
Austin Clark
441a302623
Update cisco_cli_moving_data.yml
2019-11-15 19:31:41 +01:00
Austin Clark
93a40b3b97
Update cisco_cli_modify_config.yml
2019-11-15 19:31:07 +01:00
Austin Clark
9cd6670501
Update cisco_cli_local_accounts.yml
2019-11-15 19:30:33 +01:00
Austin Clark
ed85f1e612
Update cisco_cli_input_capture.yml
2019-11-15 19:11:03 +01:00
Austin Clark
d8e0cfb64c
Update cisco_cli_file_deletion.yml
2019-11-15 19:10:19 +01:00
Austin Clark
af1cf4615f
Update cisco_cli_dos.yml
2019-11-15 19:09:38 +01:00
Austin Clark
46c63094de
Update cisco_cli_discovery.yml
2019-11-15 19:08:53 +01:00
Austin Clark
ac07b00497
Update cisco_cli_disable_logging.yml
2019-11-15 19:08:08 +01:00
Austin Clark
6448631005
Update cisco_cli_crypto_actions.yml
2019-11-15 19:07:09 +01:00
Austin Clark
82237fa347
Update cisco_cli_collect_data.yml
2019-11-15 19:05:55 +01:00
Austin Clark
55f467eae2
Update cisco_cli_clear_logs.yml
2019-11-15 19:05:02 +01:00
Maxime Lamothe-Brassard
9eed57ee1d
Adding the "falsepositives" field to the LC metadata.
2019-11-15 08:30:41 -05:00
Florian Roth
396c506794
Merge pull request #532 from Neo23x0/devel
...
rule: RottenPotato attack pattern
2019-11-15 12:01:42 +01:00
Florian Roth
04288771a1
fix: bugfix in RottenPotato rule - wrong identifier
2019-11-15 11:50:03 +01:00
Florian Roth
7e6031705e
rule: RottenPotato attack pattern
2019-11-15 11:44:18 +01:00
Florian Roth
c99ab28834
Merge pull request #531 from Neo23x0/devel
...
Devel
2019-11-15 00:34:38 +01:00
Florian Roth
ff3ed04405
rule: Exploiting SetupComplete.cmd CVE-2019-1378
2019-11-15 00:26:18 +01:00
Florian Roth
2cf6e16024
fix: missing new MITRE tactics category in tests
2019-11-14 23:31:38 +01:00
Bart
a5b4b276d4
Add scriptlets
...
Adds .sct and .vbe.
2019-11-14 22:26:22 +01:00
Austin Clark
4ec6babdff
Delete test
2019-11-14 20:56:21 +01:00
Austin Clark
85403d353c
Add files via upload
2019-11-14 20:55:28 +01:00
Austin Clark
2c8f6b5020
Create test
2019-11-14 20:53:56 +01:00
Anastasios Zouzias
3c7f522017
add .keyword on aggs; add extra unit test
2019-11-14 14:34:50 +01:00
Florian Roth
e8bfc28284
Merge branch 'devel'
2019-11-14 10:16:56 +01:00
Florian Roth
2b7699cc15
fix: fixed broken condition
2019-11-14 10:15:18 +01:00
Florian Roth
2e452d4035
Merge pull request #528 from Neo23x0/devel
...
Rule: suspicious msiexec directory
2019-11-14 10:00:12 +01:00
Florian Roth
95a8563606
Rule: suspicious msiexec directory
2019-11-14 09:51:55 +01:00
yugoslavskiy
ac21810d7a
Merge pull request #516 from yugoslavskiy/oscd_task_#2_credentials_dumping
...
oscd task #2 completed
2019-11-14 01:03:27 +03:00
yugoslavskiy
1cc9ddc8b8
Update win_dumping_ntdsdit_via_netsync.yml
2019-11-14 01:00:28 +03:00
yugoslavskiy
d29941b414
Update win_dumping_ntdsdit_via_dcsync.yml
2019-11-14 00:59:38 +03:00
yugoslavskiy
01ed5a7135
Update sysmon_unsigned_image_loaded_into_lsass.yml
2019-11-14 00:58:39 +03:00
yugoslavskiy
20a5c9498c
Update sysmon_raw_disk_access_using_illegitimate_tools.yml
2019-11-14 00:58:00 +03:00
yugoslavskiy
4b8873b706
Update sysmon_lsass_memory_dump_file_creation.yml
2019-11-14 00:55:20 +03:00
yugoslavskiy
f0cce60a2c
Update sysmon_cred_dump_tools_dropped_files.yml
2019-11-14 00:53:25 +03:00
yugoslavskiy
9b9f37715f
Update process_creation_shadow_copies_deletion.yml
2019-11-14 00:50:10 +03:00
yugoslavskiy
a1831bb503
Update process_creation_shadow_copies_creation.yml
2019-11-14 00:48:50 +03:00
yugoslavskiy
1445589839
Update process_creation_copying_sensitive_files_with_credential_data.yml
2019-11-14 00:47:14 +03:00
yugoslavskiy
c7c29a39b6
Update win_susp_lsass_dump_generic.yml
2019-11-14 00:45:47 +03:00
yugoslavskiy
633c6db254
Update win_remote_registry_management_using_reg_utility.yml
2019-11-14 00:44:47 +03:00
yugoslavskiy
cd31354df2
Update win_quarkspwdump_clearing_hive_access_history.yml
2019-11-14 00:43:56 +03:00
yugoslavskiy
334626168c
Update win_mal_service_installs.yml
2019-11-14 00:43:03 +03:00
yugoslavskiy
fecaddcd47
Merge pull request #505 from darkquasar/master
...
Adding rule Suspicious In-Memory Module Execution
2019-11-14 00:36:53 +03:00
yugoslavskiy
cd69111522
Merge branch 'oscd' into master
2019-11-14 00:36:34 +03:00
yugoslavskiy
3cd1abd0a1
Update sysmon_suspicious_remote_thread.yml
2019-11-14 00:34:09 +03:00
yugoslavskiy
1e75979a2a
Update sysmon_minidumwritedump_lsass.yml
2019-11-14 00:32:06 +03:00
yugoslavskiy
f2caf366cb
moved net_possible_dns_rebinding.yml to unsupported logic directory; renamed win_powershell_bitsjob.yaml -> win_powershell_bitsjob.yml
2019-11-14 00:24:53 +03:00
yugoslavskiy
94caaff4fa
Merge branch 'oscd' of https://github.com/Neo23x0/sigma into oscd
2019-11-14 00:23:22 +03:00
yugoslavskiy
cb29628ceb
modify rules based on BSI contribution
2019-11-14 00:23:16 +03:00
yugoslavskiy
c8ee6e9631
Merge pull request #504 from yugoslavskiy/oscd_ilyas_ochkov
...
[OSCD] Ilyas Ochkov contribution
2019-11-14 00:22:48 +03:00
yugoslavskiy
b47748399d
Update sysmon_new_dll_added_to_appcertdlls_registry_key.yml
2019-11-14 00:19:30 +03:00
yugoslavskiy
1fe7f55d47
Update sysmon_suspicious_outbound_kerberos_connection.yml
2019-11-14 00:10:05 +03:00
yugoslavskiy
07ad11f3ae
Update sysmon_possible_dns_rebinding.yml
2019-11-14 00:08:50 +03:00
yugoslavskiy
ded75d033a
Update sysmon_new_dll_added_to_appinit_dlls_registry_key.yml
2019-11-13 23:47:24 +03:00
yugoslavskiy
0cb1d4fdbd
Update sysmon_new_dll_added_to_appcertdlls_registry_key.yml
2019-11-13 23:44:03 +03:00
yugoslavskiy
bba360212a
Update sysmon_new_dll_added_to_appcertdlls_registry_key.yml
2019-11-13 23:43:45 +03:00
yugoslavskiy
e6e308ef51
Update sysmon_disable_security_events_logging_adding_reg_key_minint.yml
2019-11-13 23:40:29 +03:00
yugoslavskiy
d8447946d6
Update win_suspicious_outbound_kerberos_connection.yml
2019-11-13 23:37:25 +03:00
yugoslavskiy
7f01a5b1bb
Update win_new_or_renamed_user_account_with_dollar_sign.yml
2019-11-13 23:35:59 +03:00
yugoslavskiy
26479485e6
Update win_new_or_renamed_user_account_with_dollar_sign.yml
2019-11-13 23:34:46 +03:00
Thomas Patzke
cf22e9e576
Added hint on failed UUID check
2019-11-12 23:37:28 +01:00
Thomas Patzke
8d8530be2a
Added UUID check to CI tests
2019-11-12 23:15:30 +01:00
Thomas Patzke
0592cbb67a
Added UUIDs to rules
2019-11-12 23:12:27 +01:00
Thomas Patzke
ca53e937d9
Removed sigma.output from setup packages
2019-11-12 23:11:39 +01:00
Thomas Patzke
5f6a4225ec
Unified line terminators of rules to Unix
2019-11-12 23:05:36 +01:00
Thomas Patzke
d16175fe35
Added id diff filter script
2019-11-12 23:05:27 +01:00
Thomas Patzke
3828f4a95c
Merge branch 'uuid' into assign-ids
2019-11-12 22:46:54 +01:00
Thomas Patzke
d42cc78509
Converted rules Sysmon/1 parts to generic process_creation
2019-11-12 21:06:24 +01:00
Thomas Patzke
0065e2420f
Merge branch 'oscd-qa'
2019-11-12 20:54:11 +01:00
Anastasios Zouzias
e7ed0fa9ea
added unit test
2019-11-12 14:06:10 +01:00
Florian Roth
b7c3f8da91
refactor: cleanup, single element lists, renamed files, level adjustments
2019-11-12 12:55:05 +01:00
Anastasios Zouzias
324005a126
[feature] extend es-dsl to support nested aggregations
2019-11-12 11:46:43 +01:00
Thomas Patzke
ffdf312932
Added Ursnif user agents
2019-11-12 08:52:37 +01:00
Thomas Patzke
6d62d426c9
Added sigma-uuid tool
...
* Moved SigmaYAMLDumper to new sigma.output module
2019-11-11 23:35:16 +01:00
yugoslavskiy
a4331b0eec
Merge pull request #498 from theRabbitCode/oscd
...
[OSCD] Added Atomic Blue Detections Repo
2019-11-11 23:22:57 +03:00
yugoslavskiy
1f142f6613
Delete win_reg_sam_dumping.yml
...
redundant with https://github.com/Neo23x0/sigma/pull/516/files#diff-2f8d87b345d7d8c228d22b7a3b83c6ee
authorship has been updated
2019-11-11 23:22:47 +03:00
yugoslavskiy
cad0e30933
Update process_creation_grabbing_sensitive_hives_via_reg.yml
2019-11-11 23:22:25 +03:00
yugoslavskiy
38d0f832a4
Update win_uac_wsreset.yml
2019-11-11 23:13:28 +03:00
yugoslavskiy
49fb6bdf8f
Update win_uac_fodhelper.yml
2019-11-11 23:10:49 +03:00
yugoslavskiy
f991bf20b0
Update win_uac_cmstp.yml
2019-11-11 23:05:43 +03:00
yugoslavskiy
7f975f5878
Update win_trust_discovery.yml
2019-11-11 23:02:13 +03:00
yugoslavskiy
4c10a36e94
Update win_remote_time_discovery.yml
2019-11-11 22:51:35 +03:00
yugoslavskiy
ef55a580cf
Update win_net_enum.yml
2019-11-11 22:36:00 +03:00
yugoslavskiy
4635c5b1f9
Update win_net_user_add.yml
2019-11-11 22:35:43 +03:00
yugoslavskiy
bf4c2a508d
Update win_powershell_bitsjob.yaml
2019-11-11 22:06:57 +03:00
yugoslavskiy
90bf1c4187
Update win_powershell_audio_capture.yml
2019-11-11 22:03:49 +03:00
yugoslavskiy
8d9e293143
Update win_net_user_add.yml
2019-11-11 22:00:46 +03:00
yugoslavskiy
81b373cea7
Update win_net_enum.yml
2019-11-11 21:54:23 +03:00
yugoslavskiy
b181f09339
Update win_net_enum.yml
2019-11-11 21:53:18 +03:00
yugoslavskiy
f169163d3e
Update win_mshta_javascript.yml
2019-11-11 21:49:46 +03:00
yugoslavskiy
20a116cde5
Update win_lsass_dump.yml
2019-11-11 21:46:54 +03:00
Florian Roth
b6f94b1352
Merge pull request #522 from Neo23x0/devel
...
fix: wrong mapping on thor.cfg
2019-11-11 09:21:09 +01:00
Florian Roth
e2628d6df6
fix: wrong mapping on thor.cfg
2019-11-11 09:20:20 +01:00
yugoslavskiy
119a3417c6
Update win_interactive_at.yml
2019-11-11 04:06:37 +03:00
yugoslavskiy
e18ff0b9f9
Update win_interactive_at.yml
2019-11-11 04:05:21 +03:00
yugoslavskiy
c584b67095
Update win_indirect_cmd.yml
2019-11-11 03:20:09 +03:00
yugoslavskiy
f585c556a4
Update win_hh_chm.yml
2019-11-11 03:04:54 +03:00
yugoslavskiy
7e170900ba
Merge pull request #485 from 4A616D6573/patch-1
...
Update win_susp_net_execution.yml
2019-11-11 02:58:31 +03:00
yugoslavskiy
24ea49a2a1
Update win_susp_net_execution.yml
2019-11-11 02:57:59 +03:00
yugoslavskiy
03d08067b5
Delete win_fsutil_usn_delete.yml
...
redundant with ./rules/windows/process_creation/win_susp_fsutil_usage.yml.
authorship has been updated
2019-11-11 02:11:28 +03:00
yugoslavskiy
e7e9185f99
Delete win_eventlog_cleared.yml
...
redundant with ./rules/windows/process_creation/win_susp_eventlog_clear.yml
2019-11-11 01:59:29 +03:00
yugoslavskiy
521d9311c7
Delete win_cmd_rar.yml
...
redundant with ./rules/windows/process_creation/win_data_compressed_with_rar.yml
authorship was updated
2019-11-11 01:58:22 +03:00
yugoslavskiy
afb17d0e0e
Update win_bootconf_mod.yml
2019-11-11 01:53:46 +03:00
yugoslavskiy
fc8901fa1a
Update win_soundrec_audio_capture.yml
2019-11-11 01:45:39 +03:00
yugoslavskiy
bdff2c312b
Update lnx_auditd_ld_so_preload_mod.yml
2019-11-11 01:44:53 +03:00
yugoslavskiy
570f5b238e
Update win_soundrec_audio_capture.yml
2019-11-11 01:40:45 +03:00
yugoslavskiy
37098be291
Update win_net_user_add.yml
2019-11-11 01:35:51 +03:00
yugoslavskiy
385ebac502
Merge pull request #497 from Heirhabarov/master
...
OSCD Task 1 - Privilege Escalation
2019-11-11 01:33:28 +03:00
yugoslavskiy
8adc51d4aa
Update sysmon_possible_privilege_escalation_via_service_registry_permissions_weakness.yml
2019-11-11 01:30:19 +03:00
yugoslavskiy
20c87ae83c
Update win_whoami_as_system.yml
2019-11-11 01:18:45 +03:00
yugoslavskiy
0e6d4f7d76
Update win_using_sc_to_change_sevice_image_path_by_non_admin.yml
2019-11-11 01:17:47 +03:00
yugoslavskiy
454701cbee
Update win_possible_privilege_escalation_using_rotten_potato.yml
2019-11-11 01:10:18 +03:00
yugoslavskiy
24e17a9c50
Update win_meterpreter_or_cobaltstrike_getsystem_service_start.yml
2019-11-11 01:08:35 +03:00
yugoslavskiy
a69d9d9980
Update win_meterpreter_or_cobaltstrike_getsystem_service_installation.yml
2019-11-11 01:04:01 +03:00
yugoslavskiy
69a99bc2c3
Merge pull request #493 from alx1m1k/oscd
...
[OSCD] rules from Jet CSIRT team
2019-11-10 23:11:24 +03:00
yugoslavskiy
1f5a31f0e7
fix logsource for remote_powershell_session_process.yml
2019-11-10 23:10:24 +03:00
yugoslavskiy
fcde35d6ab
Update sysmon_regsvr32_network_activity.yml
2019-11-10 22:51:53 +03:00
yugoslavskiy
0beeaadb6f
Update sysmon_narrator_feedback_persistance.yml
2019-11-10 22:47:48 +03:00
yugoslavskiy
5756df1922
rename file
2019-11-10 21:56:34 +03:00
yugoslavskiy
86d315598b
Merge branch 'oscd' of https://github.com/Neo23x0/sigma into oscd
2019-11-10 21:40:15 +03:00
yugoslavskiy
6f2243efc4
fix reg rule
2019-11-10 21:40:08 +03:00
yugoslavskiy
e5e44e2ade
Merge pull request #488 from stvetro/oscd
...
[OSCD][ART] Task 7: T1060, T1031
2019-11-10 21:39:32 +03:00
yugoslavskiy
f2f1628506
Update and rename sysmon_runkey_from_powershell.yml to sysmon_asep_regirstry_modification.yml
2019-11-10 21:36:21 +03:00
yugoslavskiy
0d00b643cd
Update win_susp_service_path_modification.yml
2019-11-10 21:25:26 +03:00
yugoslavskiy
b9991bb2ec
Update win_susp_netsh_dll_persistence.yml
2019-11-10 21:21:42 +03:00
yugoslavskiy
b665b1b990
Update and rename win_susp_direct_run_key_modification.yml to win_susp_direct_asep_reg_keys_modification.yml
2019-11-10 21:19:06 +03:00
yugoslavskiy
0db5436778
add tieto dns exfil rules
2019-11-10 20:27:21 +03:00
yugoslavskiy
bdac415fea
Merge pull request #486 from yugoslavskiy/tieto_oscd
...
[OSCD] Tieto DNS exfiltration rules
2019-11-10 19:36:02 +03:00
yugoslavskiy
4fa928866f
oscd task #6 done.
...
add 25 new rules:
- win_ad_replication_non_machine_account.yml
- win_dpapi_domain_backupkey_extraction.yml
- win_protected_storage_service_access.yml
- win_dpapi_domain_masterkey_backup_attempt.yml
- win_sam_registry_hive_handle_request.yml
- win_sam_registry_hive_dump_via_reg_utility.yml
- win_lsass_access_non_system_account.yml
- win_ad_object_writedac_access.yml
- powershell_alternate_powershell_hosts.yml
- sysmon_remote_powershell_session_network.yml
- win_remote_powershell_session.yml
- win_scm_database_handle_failure.yml
- win_scm_database_privileged_operation.yml
- sysmon_wmi_module_load.yml
- sysmon_remote_powershell_session_process.yml
- sysmon_rdp_registry_modification.yml
- sysmon_powershell_execution_pipe.yml
- sysmon_alternate_powershell_hosts_pipe.yml
- sysmon_powershell_execution_moduleload.yml
- sysmon_createremotethread_loadlibrary.yml
- sysmon_alternate_powershell_hosts_moduleload.yml
- powershell_remote_powershell_session.yml
- win_non_interactive_powershell.yml
- win_syskey_registry_access.yml
- win_wmiprvse_spawning_process.yml
improve 1 rule:
- rules/windows/builtin/win_account_backdoor_dcsync_rights.yml
2019-11-10 18:43:41 +03:00
yugoslavskiy
c0ac9b8fb9
fix conflict
2019-11-10 17:31:33 +03:00
yugoslavskiy
127335a0ec
Merge pull request #482 from yugoslavskiy/master
...
[OSCD][The ThreatHunter-Playbook] Task 6: DONE
2019-11-10 17:27:54 +03:00
yugoslavskiy
a59d4fdd33
Merge branch 'master' of https://github.com/Neo23x0/sigma into oscd
2019-11-10 14:47:27 +03:00
Thomas Patzke
feb836cbf2
Sigmatools release 0.14
2019-11-10 00:09:59 +01:00
Florian Roth
8cc16d252a
fix: more FP reductions
2019-11-09 23:36:29 +01:00
Florian Roth
038f205f0f
fix: FPs with UserInitMprLogonScript rule
2019-11-09 23:32:53 +01:00
Florian Roth
fbe138ed90
rule: reduced level of rule to medium due to FPs
2019-11-09 23:24:31 +01:00
Florian Roth
faeccf0c3d
Merge branch 'master' into devel
2019-11-09 22:42:16 +01:00
Florian Roth
a0beda240c
fix: fixed wrong field mapping in windows-audit source config
2019-11-09 22:42:00 +01:00
Florian Roth
ef0af10747
Merge pull request #521 from Neo23x0/devel
...
fix: fixed false positive in suspicious shell spawn rule
2019-11-09 12:50:50 +01:00
Florian Roth
9835950f04
rule: SID to AD object rule level adjusted
2019-11-09 12:49:54 +01:00
Florian Roth
be62fad5cc
fix: fixed false positive in suspicious shell spawn rule
2019-11-09 10:45:46 +01:00
Thomas Patzke
2222550b6e
Allow ignore of type errors with sigmac -I
2019-11-08 23:56:39 +01:00
Thomas Patzke
8f1974d7d3
Added regular expression support in es-dsl backend
2019-11-08 23:56:39 +01:00
Thomas Patzke
2078a1d4f2
Added changelog
2019-11-08 23:56:39 +01:00
Thomas Patzke
8ae824f09f
Improved rules
...
Reduced false positives
2019-11-08 23:56:14 +01:00
Thomas Patzke
465e41bfbb
Added regular expression support in es-dsl backend
2019-11-08 22:31:02 +01:00
Thomas Patzke
238adf9eea
Improved rule test
...
* Added ATT&CK technique
* Removed invalid tags
2019-11-08 22:03:19 +01:00
Thomas Patzke
6e2fe09d24
Removed invalid tags
2019-11-08 22:02:12 +01:00
Thomas Patzke
5d995ad704
sigma-similarity: primary rule set for restriction of comparison
2019-11-08 21:15:13 +01:00
yugoslavskiy
5861664d0f
Update win_dsquery_domain_trust_discovery.yml
2019-11-08 02:58:32 +03:00
yugoslavskiy
3624a7d5da
Update win_file_permission_modifications.yml
2019-11-08 02:51:42 +03:00
yugoslavskiy
7d3c9e129d
Update win_service_stop.yml
2019-11-08 02:40:37 +03:00
yugoslavskiy
b176339da8
Merge pull request #479 from alexpetrov12/master
...
add rule
2019-11-08 02:16:22 +03:00
yugoslavskiy
00fc6c62b4
Delete renamed_binary_description.yml
...
agreed on improvements. will be added later
2019-11-08 02:16:01 +03:00
yugoslavskiy
98f32e9098
Delete sysmon_mimikatz_сreds_dump.yml
...
merged with rules/windows/sysmon/sysmon_cred_dump_lsass_access.yml
2019-11-08 02:06:31 +03:00
yugoslavskiy
6d61401b12
Delete sysmon_сreds_dump.yml
...
merged with rules/windows/sysmon/sysmon_cred_dump_lsass_access.yml
2019-11-08 02:06:20 +03:00
yugoslavskiy
6b98c37910
Update and rename sysmon_mimikatz_detection_lsass.yml to sysmon_cred_dump_lsass_access.yml
2019-11-08 02:05:34 +03:00
yugoslavskiy
562e07de38
Delete cobalt_execute_assembly.yml
...
merged with existing [sysmon_cobaltstrike_process_injection.yml](https://github.com/Neo23x0/sigma/blob/oscd/rules/windows/sysmon/sysmon_cobaltstrike_process_injection.yml )
2019-11-08 01:42:42 +03:00
yugoslavskiy
52d099a6e3
improve sysmon_cobaltstrike_process_injection.yml
2019-11-08 01:41:26 +03:00
yugoslavskiy
4443870577
Delete win_odbcconf_execution.yml
...
merged with rules/windows/process_creation/win_odbcconf_execution.yml
2019-11-08 01:36:03 +03:00
yugoslavskiy
3b34ed6150
add modifiers
2019-11-08 01:34:30 +03:00
Thomas Patzke
8b7560c2f4
Added changelog
2019-11-07 23:08:44 +01:00
yugoslavskiy
8164e1e096
Update sysmon_mimikatz_detection_lsass.yml
2019-11-07 04:50:22 +03:00
yugoslavskiy
7affc09c19
Update sysmon_mimikatz_detection_lsass.yml
2019-11-07 04:33:40 +03:00
yugoslavskiy
92e09db9ab
Update win_susp_lsass_dump_generic.yml
2019-11-07 04:27:53 +03:00
yugoslavskiy
6083d70975
Update sysmon_registry_persistence_key_linking.yml
2019-11-07 04:23:20 +03:00
yugoslavskiy
82b185db6a
Update win_sysmon_driver_unload.yml
2019-11-07 04:11:26 +03:00
yugoslavskiy
404a6d9915
Update win_netsh_packet_capture.yml
2019-11-07 03:37:41 +03:00
yugoslavskiy
ddf24819ed
Update silenttrinity_stage_use.yml
2019-11-07 03:33:12 +03:00
yugoslavskiy
0d8c64da86
duplicate rule deleted
...
this rule already present in Sigma repo — [./rules/windows/process_creation/win_susp_comsvcs_procdump.yml](https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_comsvcs_procdump.yml )
2019-11-07 03:21:09 +03:00
yugoslavskiy
5513687e63
Merge branch 'master' of https://github.com/Neo23x0/sigma into oscd
2019-11-07 03:03:35 +03:00
webhead404
a704256632
Merge pull request #1 from webhead404/webhead404-patch-1
...
Update and add another selection for regsvr32
2019-11-06 15:51:30 -06:00
webhead404
f7a968e3d2
Update and add another selection for regsvr32
...
Added cmd.exe to the detection after observing Atomic Red Team test
https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1117/T1117.md#atomic-test-2---regsvr32-remote-com-scriptlet-execution
2019-11-06 15:49:53 -06:00
booberry46
cfe7ddbe5b
Update av_exploiting.yml
...
Not sure if the '' affects.
2019-11-06 16:16:49 +08:00
Thomas Patzke
ef14ee542d
Added modifiers: startswith and endswith
2019-11-05 23:04:13 +01:00
Thomas Patzke
97d13660f7
Merge pull request #517 from Neo23x0/devel
...
Firewall Deactivation Rule
2019-11-05 22:54:50 +01:00
Thomas Patzke
7a81054cdd
Merge pull request #518 from refractionPOINT/master
...
LimaCharlie Productionization
2019-11-05 22:54:01 +01:00
Maxime Lamothe-Brassard
1b9054c1f3
Adding some comments
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
b7018bcd4a
Adding a post-mapper mechanism to fix some common issues in Sigma rules to LC.
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
c2e621cf08
Fixing another edge case with string escape.
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
0c6b9e532b
Remove debugging statement
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
6f2f1d2bd7
Add ability to map fields and values based on callbacks.
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
0b9a3f3a08
Refactor to better support keyword fields.
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
9aedb8f764
Adding another exception case to get more "contains" shortcuts instead of REs.
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
102ab3081b
Fix the convertion from simple wildcard strings to a full regular expression so that it is always correct. The previous solution just mostly-worked.
2019-11-05 08:39:24 -05:00
Maxime Lamothe-Brassard
e52f29dda9
Fix matches operator field set to value instead of re.
2019-11-05 08:38:06 -05:00
Florian Roth
c60563e546
rule: add modified rule date
2019-11-05 11:24:52 +01:00
yugoslavskiy
82f23c5f63
Merge pull request #477 from zinint/oscd
...
add 13 new rules:
- rules/linux/auditd/lnx_auditd_masquerading_crond.yml
- rules/linux/auditd/lnx_auditd_user_discovery.yml
- rules/linux/auditd/lnx_data_compressed.yml
- rules/linux/auditd/lnx_network_sniffing.yml
- rules/windows/powershell/powershell_data_compressed.yml
- rules/windows/powershell/powershell_winlogon_helper_dll.yml
- rules/windows/process_creation/win_change_default_file_association.yml
- rules/windows/process_creation/win_data_compressed_with_rar.yml
- rules/windows/process_creation/win_local_system_owner_account_discovery.yml
- rules/windows/process_creation/win_network_sniffing.yml
- rules/windows/process_creation/win_query_registry.yml
- rules/windows/process_creation/win_service_execution.yml
- rules/windows/process_creation/win_xsl_script_processing.yml
modify 1 rule:
- rules/windows/process_creation/win_possible_applocker_bypass.yml
2019-11-05 04:55:29 +03:00
yugoslavskiy
cc7aebe9b6
Update win_service_execution.yml
2019-11-05 04:42:53 +03:00
yugoslavskiy
534f5fc0e1
Update lnx_network_sniffing.yml
2019-11-05 04:40:40 +03:00
yugoslavskiy
70fdd9c7d7
Update lnx_data_compressed.yml
2019-11-05 04:38:27 +03:00
yugoslavskiy
ac95d840b4
Update powershell_winlogon_helper_dll.yml
2019-11-05 04:33:07 +03:00
yugoslavskiy
479aafe466
Update win_service_execution.yml
2019-11-05 04:26:19 +03:00
yugoslavskiy
37674b944f
Update win_query_registry.yml
2019-11-05 03:04:46 +03:00
yugoslavskiy
9d9de64387
Update win_query_registry.yml
2019-11-05 03:00:33 +03:00
yugoslavskiy
27e63abcc4
Update and rename win_custom_service_execution.yml to win_service_execution.yml
2019-11-05 02:57:15 +03:00
yugoslavskiy
3d5f5e2fe7
Update win_custom_service_execution.yml
2019-11-05 02:56:50 +03:00
yugoslavskiy
66bfbd0af9
Update and rename win_service_execution.yml to win_custom_service_execution.yml
2019-11-05 02:55:41 +03:00
yugoslavskiy
c147863eb3
Update powershell_data_compressed.yml
2019-11-05 02:38:36 +03:00
yugoslavskiy
b755d4fb68
Update and rename win_system_owner_user_discovery.yml to win_local_system_owner_account_discovery.yml
2019-11-05 02:31:20 +03:00
yugoslavskiy
9831897b6b
Update win_xsl_script_processing.yml
2019-11-05 01:32:29 +03:00
yugoslavskiy
ce55f80fb6
Update win_xsl_script_processing.yml
2019-11-05 01:31:55 +03:00
zinint
cd1cd48619
Delete win_app_windows_discovery.yml
2019-11-05 01:18:26 +03:00
zinint
a3ec56da07
Update win_xsl_script_processing.yml
2019-11-05 00:02:19 +03:00
zinint
fd6875485b
Add files via upload
2019-11-05 00:00:14 +03:00
zinint
cd43354c04
Delete sysmon_xsl_script_processing.yml
2019-11-04 23:47:23 +03:00
zinint
2679baddcd
Delete powershell_network_sniffing.yml
2019-11-04 23:46:43 +03:00
yugoslavskiy
e81f4f0ea6
Update sysmon_xsl_script_processing.yml
2019-11-04 23:42:47 +03:00
yugoslavskiy
b565398bc5
Update win_network_sniffing.yml
2019-11-04 23:02:03 +03:00
yugoslavskiy
e38116fce2
Update and rename win_data_compressed.yml to win_data_compressed_with_rar.yml
2019-11-04 22:55:32 +03:00
yugoslavskiy
cb167e73b1
fix filenames
2019-11-04 22:49:28 +03:00
yugoslavskiy
f880fa82b5
Rename process_creation_change_default_file_association.yml to win_change_default_file_association.yml
2019-11-04 22:48:13 +03:00
yugoslavskiy
cbf01aa51e
Update and rename win_change_default_file_association.yml to process_creation_change_default_file_association.yml
2019-11-04 22:46:55 +03:00
yugoslavskiy
75f2b8536f
Update lnx_auditd_user_discovery.yml
2019-11-04 22:14:30 +03:00
yugoslavskiy
8b2216e94e
Update lnx_auditd_masquerading_crond.yml
2019-11-04 22:14:10 +03:00
yugoslavskiy
0d5489bbb0
Update lnx_auditd_user_discovery.yml
2019-11-04 22:07:30 +03:00
yugoslavskiy
bb71f95810
Update lnx_auditd_masquerading_crond.yml
2019-11-04 21:58:42 +03:00
yugoslavskiy
ce849a1184
Merge branch 'master' into oscd
2019-11-04 20:48:19 +03:00
yugoslavskiy
1f1fd68331
Merge pull request #472 from feedb/oscd
...
add 11 new rules:
- rules/linux/auditd/lnx_auditd_web_rce.yml
- rules/windows/process_creation/process_creation_susp_bginfo.yml
- rules/windows/process_creation/process_creation_susp_cdb.yml
- rules/windows/process_creation/process_creation_susp_devtoolslauncher.yml
- rules/windows/process_creation/process_creation_susp_dnx.yml
- rules/windows/process_creation/process_creation_susp_dxcap.yml
- rules/windows/process_creation/process_creation_susp_msoffice.yml
- rules/windows/process_creation/process_creation_susp_odbcconf.yml
- rules/windows/process_creation/process_creation_susp_openwith.yml
- rules/windows/process_creation/process_creation_susp_psr_capture_screenshots.yml
- rules/windows/sysmon/sysmon_webshell_creation_detect.yml
2019-11-04 20:40:58 +03:00
yugoslavskiy
3f1c94837b
Rename process_creation_susp_openwith_execution.yml to process_creation_susp_openwith.yml
2019-11-04 20:38:44 +03:00
yugoslavskiy
54e9be9cd0
Rename process_creation_susp_devtoolslauncher_execution.yml to process_creation_susp_devtoolslauncher.yml
2019-11-04 20:38:24 +03:00
yugoslavskiy
999126446b
Rename win_susp_psr_capture_screenshots.yml to process_creation_susp_psr_capture_screenshots.yml
2019-11-04 20:37:16 +03:00
yugoslavskiy
85cd989b6f
Rename win_susp_openwith_execution.yml to process_creation_susp_openwith_execution.yml
2019-11-04 20:36:58 +03:00
yugoslavskiy
8d0923de2d
Rename win_susp_odbcconf.yml to process_creation_susp_odbcconf.yml
2019-11-04 20:36:46 +03:00
yugoslavskiy
de098ff5b7
Rename win_susp_msoffice.yml to process_creation_susp_msoffice.yml
2019-11-04 20:36:21 +03:00
yugoslavskiy
9c19d1b58c
Rename win_susp_dxcap.yml to process_creation_susp_dxcap.yml
2019-11-04 20:36:07 +03:00
yugoslavskiy
66eba43a8d
Rename win_susp_dnx.yml to process_creation_susp_dnx.yml
2019-11-04 20:35:53 +03:00
yugoslavskiy
d18314b6b2
Rename win_susp_devtoolslauncher_execution.yml to process_creation_susp_devtoolslauncher_execution.yml
2019-11-04 20:35:43 +03:00
yugoslavskiy
49bc6ada25
Rename win_susp_cdb.yml to process_creation_susp_cdb.yml
2019-11-04 20:35:28 +03:00
yugoslavskiy
95412e5f30
Rename win_susp_bginfo.yml to process_creation_susp_bginfo.yml
2019-11-04 20:35:11 +03:00
yugoslavskiy
19396fd274
Update sysmon_webshell_creation_detect.yml
2019-11-04 19:23:52 +03:00
yugoslavskiy
9371e533c3
Update win_susp_openwith_execution.yml
2019-11-04 19:05:23 +03:00
yugoslavskiy
e6a39f1061
Update win_susp_odbcconf.yml
2019-11-04 19:01:30 +03:00
yugoslavskiy
c18fa0940d
Update win_susp_msoffice.yml
2019-11-04 18:44:07 +03:00
yugoslavskiy
bd0ebf0604
Update win_susp_dxcap.yml
2019-11-04 18:43:42 +03:00
yugoslavskiy
df07291e53
Update win_susp_cdb.yml
2019-11-04 18:43:03 +03:00
yugoslavskiy
a66539c771
Update win_susp_msoffice.yml
2019-11-04 18:42:26 +03:00
yugoslavskiy
56b7402e62
Update win_susp_dxcap.yml
2019-11-04 18:38:37 +03:00
yugoslavskiy
a9fdfee5c2
Update win_susp_dnx.yml
2019-11-04 18:34:25 +03:00
yugoslavskiy
dc23e566a0
Update win_susp_devtoolslauncher_execution.yml
2019-11-04 18:30:04 +03:00
yugoslavskiy
989d75033a
Update win_susp_cdb.yml
2019-11-04 18:25:30 +03:00
yugoslavskiy
43c20d203d
Update and rename win_susp_capture_screenshots.yml to win_susp_psr_capture_screenshots.yml
2019-11-04 18:16:39 +03:00
yugoslavskiy
a800093aaf
Update win_susp_bginfo.yml
2019-11-04 18:14:44 +03:00
Florian Roth
5786688f97
rule: Firewall disabled via Netsh
2019-11-04 16:10:10 +01:00
yugoslavskiy
8a35a51211
Update lnx_auditd_web_rce.yml
2019-11-04 18:08:17 +03:00
yugoslavskiy
2697b829b0
fix logic
2019-11-04 14:57:58 +03:00
darkquasar
5f027e97c2
fixing as as per comment on rule
...
https://github.com/Neo23x0/sigma/pull/505#discussion_r340790327
2019-11-03 20:35:58 -08:00
yugoslavskiy
becb80f609
add rules/windows/builtin/win_quarkspwdump_clearing_hive_access_history.yml
2019-11-04 05:38:49 +03:00
yugoslavskiy
1f7b3bc9a2
add rules/windows/builtin/win_quarkspwdump_clearing_hive_access_history.yml
2019-11-04 05:05:57 +03:00
yugoslavskiy
701e7f7cc6
oscd task #2 completed
...
- new rules:
+ rules/windows/builtin/win_susp_lsass_dump_generic.yml
+
rules/windows/builtin/win_transferring_files_with_credential_data_via_ne
twork_shares.yml
+
rules/windows/builtin/win_remote_registry_management_using_reg_utility.y
ml
+ rules/windows/sysmon/sysmon_unsigned_image_loaded_into_lsass.yml
+ rules/windows/sysmon/sysmon_lsass_memory_dump_file_creation.yml
+
rules/windows/sysmon/sysmon_raw_disk_access_using_illegitimate_tools.yml
+ rules/windows/sysmon/sysmon_cred_dump_tools_dropped_files.yml
+ rules/windows/sysmon/sysmon_cred_dump_tools_named_pipes.yml
+
rules/windows/process_creation/process_creation_shadow_copies_creation.y
ml
+
rules/windows/process_creation/process_creation_shadow_copies_deletion.y
ml
+
rules/windows/process_creation/process_creation_copying_sensitive_files_
with_credential_data.yml
+
rules/windows/process_creation/process_creation_shadow_copies_access_sym
link.yml
+
rules/windows/process_creation/process_creation_grabbing_sensitive_hives
_via_reg.yml
+
rules/windows/process_creation/process_creation_mimikatz_command_line.ym
l
+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_dcsync.yml
+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_netsync.yml
.yml
- updated rules:
+ rules/windows/builtin/win_susp_raccess_sensitive_fext.yml
+ rules/windows/builtin/win_mal_creddumper.yml
+ rules/windows/builtin/win_mal_service_installs.yml
+ rules/windows/process_creation/win_susp_process_creations.yml
+ rules/windows/sysmon/sysmon_powershell_exploit_scripts.yml
+ rules/windows/sysmon/sysmon_mimikatz_detection_lsass.yml
- deprecated rules:
+ rules/windows/process_creation/win_susp_vssadmin_ntds_activity.yml
2019-11-04 04:26:34 +03:00
Thomas Patzke
54c75167ce
Default configurations for backends
2019-11-03 23:32:50 +01:00
Thomas Patzke
0c64992276
Merge branch 'master' of https://github.com/Neo23x0/sigma
2019-11-02 23:05:41 +01:00
Thomas Patzke
a5579fa8cd
Merge pull request #513 from Karneades/fix-sysmon-rule
...
fix: bound sysmon logon script rule to field
2019-11-02 23:04:35 +01:00
Thomas Patzke
c0f1b12833
Merge pull request #512 from Karneades/fix-win-rules
...
fix: bound windows event log rules to message field
2019-11-02 23:03:44 +01:00
Thomas Patzke
66d9de460d
Merge branch 'master' of https://github.com/Neo23x0/sigma
2019-11-02 22:56:32 +01:00
Thomas Patzke
4f19ef5708
Graylog backend now derived from es-qs
...
Technically, Graylog is ES. Fixes and improvements for ES didn't
propagate to Graylog, now they do.
2019-11-02 22:56:01 +01:00
Thomas Patzke
8af2b70594
Restrict search not bound to fields to keyword fields
2019-11-02 22:55:04 +01:00
Thomas Patzke
c9eb921f68
ConditionAND/OR constructor now allows arbeitrary number of operands
2019-11-02 22:54:35 +01:00
Karneades
0117dac1db
fix: bound sysmon logon script rule to field
...
Fixed rule:
- rules/windows/sysmon/sysmon_logon_scripts_userinitmprlogonscript.yml
2019-11-02 11:47:20 +01:00
Karneades
68fd20cb66
fix: bound windows event log rules to message field
...
Fixed rules
- rules/windows/builtin/win_susp_msmpeng_crash.yml
- rules/windows/builtin/win_alert_active_directory_user_control.yml
- rules/windows/builtin/win_av_relevant_match.yml
- rules/windows/builtin/win_mal_creddumper.yml
- rules/windows/builtin/win_susp_sam_dump.yml
- rules/windows/builtin/win_alert_mimikatz_keywords.yml
- rules/windows/builtin/win_alert_enable_weak_encryption.yml
2019-11-02 11:25:29 +01:00
4A616D6573
013d862afd
Create win_susp_local_anon_logon_created.yml
2019-10-31 21:56:30 +11:00
Florian Roth
3107c0c268
rule: Formbook rule improved
2019-10-31 09:32:18 +01:00
zinint
60bf34e220
T1042
2019-10-30 23:30:56 +03:00
zinint
12ef86fcbe
t1040
2019-10-30 23:18:37 +03:00
zinint
b3b203e5b1
t1040
2019-10-30 23:15:19 +03:00
zinint
11e7bdc727
Update lnx_network_sniffing.yml
2019-10-30 22:59:46 +03:00
zinint
fd09c00b35
Update lnx_network_sniffing.yml
2019-10-30 20:59:07 +03:00
Florian Roth
4741b6a4d6
rule: Mustang Panda dropper
2019-10-30 18:22:40 +01:00
Florian Roth
d661771608
rule: another DTRACK reference
2019-10-30 18:22:25 +01:00
zinint
3d106d8e7f
Update lnx_network_sniffing.yml
2019-10-30 19:11:51 +03:00
zinint
e0c5479f0a
Update lnx_network_sniffing.yml
2019-10-30 19:10:48 +03:00
zinint
b5b40f2861
Update lnx_network_sniffing.yml
2019-10-30 19:07:05 +03:00
zinint
cc4a8df5e3
Update lnx_network_sniffing.yml
2019-10-30 19:06:53 +03:00
zinint
7e3d8ccaf3
T1040
2019-10-30 19:05:50 +03:00
Florian Roth
3ac28f3eed
rule: DTRACK process creation
2019-10-30 15:16:33 +01:00
Thomas Patzke
219f00e3fb
Added command line parameter
...
Implements #418
2019-10-29 23:04:28 +01:00
Thomas Patzke
2eeccf48e0
Removed line breaks in Elastalert YAML output
...
Fixes #453
2019-10-29 22:45:37 +01:00
Thomas Patzke
f4e9690d6b
Merge pull request #508 from Karneades/fixRule3
...
fix: bound keywords to field in multiple PS rules
2019-10-29 22:34:08 +01:00
Thomas Patzke
78d8ca2b41
Merge pull request #507 from Karneades/fixRule2
...
fix: bound keywords to field in PS cred prompt rule
2019-10-29 22:31:01 +01:00
Thomas Patzke
40df0d4534
Merge pull request #506 from Karneades/fixRule1
...
fix: bound keywords to field in WMI persistence rule
2019-10-29 22:30:27 +01:00
Thomas Patzke
6eb49fc1ce
Merge pull request #509 from Karneades/fixRule4
...
fix: change keyword and bound it to a field in PS rule
2019-10-29 22:27:54 +01:00
Thomas Patzke
b6403793c1
Fixed escaping in rule
2019-10-29 22:06:23 +01:00
zinint
4a560e9375
T1002
2019-10-29 22:56:45 +03:00
zinint
583980f8ec
Delete win_data_compressed.yml
2019-10-29 22:56:30 +03:00
zinint
4eb7965662
T1002
2019-10-29 22:54:42 +03:00
zinint
950796f71f
Update lnx_auditd_masquerading_crond.yml
2019-10-29 22:48:39 +03:00
zinint
c5599399b5
Update lnx_auditd_masquerading_crond.yml
2019-10-29 22:48:00 +03:00
zinint
47f7d648a3
T1036
2019-10-29 22:33:03 +03:00
Karneades
ab5556ae8c
fix: change keyword and bound it to a field
2019-10-29 19:59:43 +01:00
Karneades
aafab2e936
fix: bound keywords to field in multiple PS rules
...
Rules changed:
- rules/windows/powershell/powershell_malicious_commandlets.yml
- rules/windows/powershell/powershell_malicious_keywords.yml
- rules/windows/powershell/powershell_suspicious_download.yml
- rules/windows/powershell/powershell_suspicious_invocation_specific.yml
2019-10-29 19:53:18 +01:00
Karneades
f31750e567
fix: bound keywords to field in PS cred prompt rule
2019-10-29 19:43:04 +01:00
Karneades
cd20e4a3fc
fix: bound keywords to field in WMI persistence rule
...
See #501 .
2019-10-29 19:22:41 +01:00
zinint
c243c4e210
T1035
2019-10-29 20:58:52 +03:00
booberry46
36fe748c2e
Update win_rdp_reverse_tunnel.yml
...
With the recent example for the evtx. RDP Tunneling can happen not only from port 3389. So I tune it to fit in general.
Changed the obsolete twitter status with linkage to the evtx from Samir Bousseaden
2019-10-29 17:25:37 +08:00
darkquasar
cb6eb35913
adding some more suspicious PS keywords
...
found in multiple internally analyzed malicious scripts (in the wild and as result of engagements)
2019-10-28 22:14:14 -07:00
darkquasar
96643b5446
New rule Suspicious Remote Thread Created
2019-10-28 22:12:57 -07:00
darkquasar
551d3d653c
Dumping Lsass.exe memory with MiniDumpWriteDump API
2019-10-28 22:11:55 -07:00
darkquasar
a6b24da6dd
Adding rule Suspicious In-Memory Module Execution
2019-10-28 22:07:26 -07:00
alx1m1k
116d17c9b1
Merge pull request #1 from yugoslavskiy/oscd
...
fix some typos and remove redundant references
2019-10-29 08:04:04 +03:00
Yugoslavskiy Daniil
fd606cb376
spaces fix
2019-10-29 03:59:07 +03:00
Yugoslavskiy Daniil
4251d9f490
ilyas ochkov contribution
2019-10-29 03:44:22 +03:00
Yugoslavskiy Daniil
3376cf4dd8
fix some typos and remove redundand references
2019-10-29 01:40:06 +03:00
Thomas Patzke
632c45843b
Merge pull request #500 from refractionPOINT/master
...
Adding LimaCharlie to the README's supported targets.
2019-10-28 21:17:30 +01:00
Maxime Lamothe-Brassard
f01913c996
Adding LimaCharlie to the README's supported targets.
2019-10-28 14:48:04 -05:00
Thomas Patzke
6a76f5950b
Merge pull request #499 from refractionPOINT/master
...
Adding Backend for LimaCharlie D&R rules
2019-10-28 20:38:33 +01:00
Maxime Lamothe-Brassard
f6fb9c7f5f
Fixing typo in response metadata.
2019-10-28 11:31:50 -05:00
Maxime Lamothe-Brassard
2873e1ded3
Small refactors to make more readable and remove deprecated code paths to increase coverage.
2019-10-28 10:49:05 -05:00
Florian Roth
8ff85499c8
rule: svchost dll search order hijack
2019-10-28 12:03:03 +01:00
Florian Roth
1a3444d0ef
docs: comment on rule expression
2019-10-28 12:02:46 +01:00
RRRabbit
becfca6b41
Added Atomic Blue Detections Repo
2019-10-28 11:59:49 +01:00
Teimur Kheirkhabarov
59c6250282
Delete rules/windows/.DS_Store
2019-10-28 09:38:17 +03:00
Teimur Kheirkhabarov
2fb40acfe6
Fix mistake in possible_privilege_escalation_via_service_registry_permissions_weakness
2019-10-28 09:30:26 +03:00
Teimur Kheirkhabarov
32b0a3987e
Several mistakes were fixed
2019-10-28 08:43:58 +03:00
Teimur Kheirkhabarov
3125b39239
Change incorrect MITRE Tags for some rules
2019-10-28 07:56:15 +03:00
zinint
d1cf80d9b6
Update lnx_auditd_user_discovery.yml
2019-10-28 00:00:06 +03:00
zinint
68b4541274
t1033
2019-10-27 23:59:16 +03:00
Maxime Lamothe-Brassard
a7003c2aa3
Adding support for "unix", looking like a mistake by the creator.
2019-10-27 15:55:12 -05:00
zinint
87c8326133
T1033
2019-10-27 23:49:07 +03:00
Maxime Lamothe-Brassard
d019cef439
Ading a bit more of early support for netflow and some linux exe.
2019-10-27 15:48:28 -05:00
Maxime Lamothe-Brassard
a57a7b58cf
Added conceptial support for aliasing keyworkds to a specific field depending on the log source.
2019-10-27 15:28:54 -05:00
zinint
55eaae1cea
Rename win_app_windows_descovery.yml to win_app_windows_discovery.yml
2019-10-27 23:15:10 +03:00
zinint
93b867024c
T1012
2019-10-27 23:13:03 +03:00
Teimur Kheirkhabarov
fde949174d
OSCD Task 1 - Privilege Escalation
2019-10-27 20:54:07 +03:00
Maxime Lamothe-Brassard
60b20a76a6
Fixing handling of unsupported sources.
2019-10-27 12:37:06 -05:00
Maxime Lamothe-Brassard
0fe72d6133
Emit error on full-text searches not being supported.
2019-10-27 12:26:36 -05:00
Maxime Lamothe-Brassard
f43300af8e
Fix the top level pre-condition for Windows Event Logs on LC.
2019-10-27 12:17:15 -05:00
Maxime Lamothe-Brassard
91e48d8c1b
Adding setup links and fixing test that would crash Not node, but not seen in prod rules.
2019-10-27 11:56:32 -05:00
Mikhail Larin
1f6aec8060
removed unsupported rule from oscd branch
2019-10-27 15:33:38 +03:00
4A616D6573
ca819d8707
Update win_susp_net_execution.yml
...
Updated tags to pass Travis CI checks.
2019-10-27 14:06:52 +11:00
Maxime Lamothe-Brassard
8d866b0868
Adding comments.
2019-10-26 17:37:13 -05:00
Maxime Lamothe-Brassard
bc5e9bd03a
Making rule output a full D&R (with the Response component) and includes a lot of metadata from the rule in the report.
2019-10-26 17:30:40 -05:00
Maxime Lamothe-Brassard
8cc3990aef
Extending support for more random rules with odd names.
2019-10-26 16:59:33 -05:00
Maxime Lamothe-Brassard
4d65b62063
Adding support for generating rules for Windows builtin category for use in the External Logs of LC.
2019-10-26 16:30:50 -05:00
Maxime Lamothe-Brassard
30cc7ee809
Refactor mappings into a flat structure to account for missing parameters in some combinations.
2019-10-26 16:09:39 -05:00
Maxime Lamothe-Brassard
77329714c5
Adding service to indirection of mappings since it will be used for Windows Event Logs.
2019-10-26 16:06:42 -05:00
Maxime Lamothe-Brassard
823d86c7d9
Remove unimplemented config entries and fix bug with valueNode.
2019-10-26 15:54:08 -05:00
Maxime Lamothe-Brassard
bba43c7a86
First draft of support for LimaCharlie D&R rules.
2019-10-26 15:45:48 -05:00
root
717e40e8ed
modified win_susp_dxcap.yml
2019-10-26 20:27:32 +02:00
root
9bf0150100
modified win_susp_dnx.yml
2019-10-26 20:20:21 +02:00
root
3b70f2edd6
modified win_susp_dnx.yml
2019-10-26 20:16:40 +02:00
root
3528afeef7
modified win_susp_dnx.yml
2019-10-26 20:13:53 +02:00
root
1dca0456ee
modified win_susp_dxcap.yml
2019-10-26 20:09:25 +02:00
root
cbe0d73ce8
add win_susp_dxcap.yml
2019-10-26 20:06:02 +02:00
root
aaf63d2238
add win_susp_dxcap.yml
2019-10-26 20:02:25 +02:00
root
0616c2c39d
add win_susp_dnx.yml
2019-10-26 19:58:45 +02:00
root
ee21888e67
add win_susp_cdb.yml
2019-10-26 19:49:45 +02:00
booberry46
b7fe52133d
Update win_defender_bypass.yml
2019-10-27 00:07:56 +08:00
booberry46
3f1fc9a507
Add files via upload
2019-10-27 00:06:49 +08:00
Florian Roth
66a32549f1
rule: proxy malware ua - Zebrocy
2019-10-26 14:20:29 +02:00
Florian Roth
42808b7eb8
rule: webshell detection improved
2019-10-26 09:14:54 +02:00
root
844d55c781
add win_susp_bginfo.yml
2019-10-26 08:18:37 +02:00
root
5bb5938e86
add win_susp_bginfo.yml
2019-10-26 08:16:08 +02:00
root
01c4c7cdbd
modifed win_susp_msoffice.yml
2019-10-26 08:11:09 +02:00
root
bea2daac45
modifed win_susp_msoffice.yml
2019-10-26 07:55:44 +02:00
root
fc7f8ecea3
add win_susp_msoffice.yml
2019-10-26 07:48:38 +02:00
root
611c193826
modifed win_susp_odbcconf.yml
2019-10-26 07:45:53 +02:00
Thomas Patzke
30948b9c1a
Added sigma-similarity tool
...
Fixed also bug in backend base class that was triggered by the way
backends are used by this tool.
2019-10-25 21:59:03 +02:00
root
aa9a22e662
add win_susp_odbcconf.yml
2019-10-25 19:02:17 +02:00
alexpetrov12
8c2b7e9f85
fix
2019-10-25 18:30:40 +03:00
alexpetrov12
7aa804fe90
added new rules
...
Packet capture Windows command prompt, ODBCCONF execution dll, Windows Registry Persistence - COM key linking
2019-10-25 18:01:36 +03:00
Mikhail Larin
334301c185
OSCD event rules from Jet CSIRT team
2019-10-25 17:57:56 +03:00
zinint
6e94e798be
t1010
2019-10-25 16:12:51 +03:00
stvetro
dcaacd07bf
4 rules to cover ART
2019-10-25 15:38:47 +04:00
yugoslavskiy
5eb484a062
add tieto dns exfiltration rules
2019-10-25 04:30:55 +02:00
4A616D6573
5678357f4e
Update win_susp_net_execution.yml
...
Added tag for:
References:
https://attack.mitre.org/techniques/T1077/
https://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html
2019-10-25 12:20:47 +11:00
4A616D6573
a7a753862c
Update win_susp_net_execution.yml
...
Added:
1. Additional tags for techniques as defined by Atomic Blue.
2. Detection for OriginalFileName as net.exe can easily be renamed.
Part of oscd.community effort.
2019-10-25 12:06:32 +11:00
4A616D6573
c248842995
Revert "Update win_susp_net_execution.yml"
...
This reverts commit f7e26b1e0b .
2019-10-25 12:03:23 +11:00
4A616D6573
f7e26b1e0b
Update win_susp_net_execution.yml
...
Added:
1. Additional tags for techniques as defined by Atomic Blue.
2. Detection for OriginalFileName as net.exe can easily be renamed.
Part of oscd.community effort.
2019-10-25 11:53:56 +11:00
yugoslavskiy
4fb9821b49
added:
...
win_non_interactive_powershell.yml
win_remote_powershell_session.yml
win_wmiprvse_spawning_process.yml
powershell_alternate_powershell_hosts.yml
powershell_remote_powershell_session.yml
sysmon_alternate_powershell_hosts_moduleload.yml
sysmon_alternate_powershell_hosts_pipe.yml
sysmon_non_interactive_powershell_execution.yml
sysmon_powershell_execution_moduleload.yml
sysmon_powershell_execution_pipe.yml
sysmon_remote_powershell_session_network.yml
sysmon_remote_powershell_session_process.yml
sysmon_wmi_module_load.yml
sysmon_wmiprvse_spawning_process.yml
2019-10-24 15:48:38 +02:00
zinint
aef5fa3c2b
Rename powershell_winlogon_helper_dll.yaml to powershell_winlogon_helper_dll.yml
2019-10-24 16:37:38 +03:00
Florian Roth
a5ec6722a1
rule: the actual changes to hwp rule
2019-10-24 15:35:13 +02:00
zinint
5a98fdbbbd
ART t1004
2019-10-24 16:33:29 +03:00
zinint
317e9d3df9
PS Data Compressed attack.t1002
...
PS Data Compressed attack.t1002
2019-10-24 15:43:46 +03:00
yugoslavskiy
3934f6c756
add win_ad_object_writedac_access.yml, sysmon_createremotethread_loadlibrary.yml, sysmon_rdp_registry_modification.yml; modified win_account_backdoor_dcsync_rights.yml
2019-10-24 14:34:16 +02:00
zinint
7c5dc0ca01
Update win_data_compressed.yml
2019-10-24 15:34:13 +03:00
Florian Roth
86c1b4ae4b
rule: hwp exploits
2019-10-24 11:46:56 +02:00
Yugoslavskiy Daniil
7cfd47be7c
add win_scm_database_handle_failure.yml, win_scm_database_privileged_operation.yml, win_syskey_registry_access.yml
2019-10-24 02:40:11 +02:00
alexpetrov12
cc998aa667
fix
2019-10-24 00:48:43 +03:00
alexpetrov12
f1ccf296f4
fix
2019-10-24 00:40:58 +03:00
mrblacyk
499627edf3
File permissions modification (T1222)
2019-10-23 11:24:13 -07:00
mrblacyk
4979b56296
Domain Trust Discovery rule (T1482)
2019-10-23 11:23:12 -07:00
mrblacyk
c2d906c15f
DD overwrite with zero/null (T1485)
2019-10-23 11:22:33 -07:00
mrblacyk
262514c782
Windows Service stop rule (T1489)
2019-10-23 11:22:09 -07:00
mrblacyk
5ae267e326
Linux systemd reload or start rule (T1501)
2019-10-23 11:21:19 -07:00
alexpetrov12
d3715a508b
fix
2019-10-23 18:15:46 +03:00
alexpetrov12
4c84412944
added new rule
...
silenttrinity_stage_ use, sysmon_mimikatz_сreds_dump, sysmon_registry_persistence_key_linking, sysmon_сreds_dump
2019-10-23 18:08:30 +03:00
alexpetrov12
bc943343df
update win_sysmon_driver_unload
2019-10-23 15:41:14 +03:00
alexpetrov12
215e500894
fix
2019-10-23 14:43:01 +03:00
alexpetrov12
193c95a11a
add new rule1
2019-10-23 14:27:52 +03:00
root
edcbc49ce8
add rule win_susp_open with_execution.yml win_susp_devt oolslauncher_execution.yml
2019-10-23 13:00:21 +02:00
alexpetrov12
043e3f7ca6
fix
2019-10-23 13:48:44 +03:00
alexpetrov12
e38540a37f
fix
2019-10-23 13:28:04 +03:00
alexpetrov12
c1cfbacd24
fix
2019-10-23 13:18:57 +03:00
alexpetrov12
ad9b98541c
fix
2019-10-23 13:05:38 +03:00
alexpetrov12
fa4a8c974d
fix
2019-10-23 12:45:06 +03:00
alexpetrov12
f4ea01217e
fix
2019-10-23 02:47:04 +03:00
alexpetrov12
ebe4fe0377
fix
2019-10-23 02:42:37 +03:00
alexpetrov12
29cd7fed3e
fix
2019-10-23 02:39:40 +03:00
alexpetrov12
5a260db459
fix
2019-10-23 02:27:14 +03:00
alexpetrov12
6c4f4ce309
fix
2019-10-23 02:25:04 +03:00
alexpetrov12
8d0c89b598
added new rules
...
add rule MiniDumpWriteDump via COM+, renamed_binary_description, cobalt_execute_assembly, win_sysmon_driver_onload
2019-10-23 01:55:03 +03:00
Florian Roth
3d4ce9d175
rule: another reference link for 'execution by ordinal'
2019-10-22 15:18:19 +02:00
zinint
49f9b797a7
Update sysmon_xsl_script_processing.yml
2019-10-22 15:20:15 +03:00
zinint
a8bd2c8e78
Update win_data_compressed.yml
2019-10-22 14:57:53 +03:00
zinint
74d1fef8b8
Update win_data_compressed.yml
2019-10-22 14:53:43 +03:00
zinint
cc6d4b05ac
OSCD Task 7 : ART T1002 Exfiltration With Rar
...
OSCD Task 7 : ART T1002 Compress Data for Exfiltration With Rar
2019-10-22 14:00:52 +03:00
Florian Roth
b3654947bc
rule: suspicious call by ordinal (rundll32)
2019-10-22 12:40:26 +02:00
Florian Roth
0f02f2bdfc
rule: adjusted very noisy rule on AppLocker whitelist bypass
2019-10-22 12:32:37 +02:00
root
00a757959e
add rule win_susp_capture_screenshots.yml
2019-10-22 06:06:07 +02:00
root
2bd9d8a9d8
add rule sysmon_webshell_creation_detect.yml
2019-10-22 05:56:37 +02:00
root
fb53855ae5
add rule sysmon_webshell_creation_detect.yml
2019-10-22 05:50:49 +02:00
zinint
daf1034621
Update win_possible_applocker_bypass.yml
2019-10-22 00:54:29 +03:00
zinint
789782ef59
Update sysmon_xsl_script_processing.yml
2019-10-22 00:08:46 +03:00
zinint
56f807cb44
Update sysmon_xsl_script_processing.yml
2019-10-22 00:06:54 +03:00
zinint
0d8eff0d86
Update sysmon_xsl_script_processing.yml
2019-10-22 00:06:10 +03:00
zinint
a1d72f20c8
Update sysmon_xsl_script_processing.yml
2019-10-21 23:51:39 +03:00
zinint
5248f83fb3
Update sysmon_xsl_script_processing.yml
2019-10-21 23:46:11 +03:00
zinint
a685c9c3be
Update sysmon_xsl_script_processing.yml
2019-10-21 23:39:33 +03:00
zinint
784d7138ca
OSCD Task 7 ART T1220
...
OSCD Task 7 ART T1220 rule add
2019-10-21 22:22:55 +03:00
Florian Roth
3bd3e724f1
Merge pull request #473 from joesecurity/patch-3
...
Update README.md
2019-10-21 13:34:41 +02:00
Florian Roth
439045a87b
Reordered projects
2019-10-21 13:34:30 +02:00
Florian Roth
4e7ad5c948
rule: added date to crypto miner rule
2019-10-21 13:24:33 +02:00
Florian Roth
e8963b2599
rule: crypto miner user agents in proxy logs
2019-10-21 13:21:50 +02:00
Joe Security
b815b15255
Update README.md
...
Added Joe Sandbox to list of supported Projects or Products.
2019-10-21 13:13:49 +02:00
Florian Roth
c8b5b91815
Merge pull request #471 from a2tf/rule_change_proxy_uri_to_url
...
rule: changed two proxy rules from uri-query to url
2019-10-21 12:52:36 +02:00
root
e47caf4749
add rule lnx_auditd_web_rce.yml
2019-10-21 11:54:21 +02:00
root
a499141483
modified rule lnx_auditd_web_rce.yml
2019-10-21 11:28:59 +02:00
Florian Roth
9457f01c29
Update proxy_ios_implant.yml
2019-10-21 11:20:11 +02:00
Florian Roth
f8d8eb7948
Update proxy_chafer_malware.yml
2019-10-21 11:19:59 +02:00
root
ac8308dfc9
add rule lnx_auditd_web_rce.yml
2019-10-21 11:14:24 +02:00
a2tf
a2753ba5a6
rule: changed two proxy rules from uri-query to url
2019-10-18 14:15:39 +00:00
Florian Roth
a47ec859a8
List for field 'AllowedToDelegateTo'
2019-06-19 08:20:41 +02:00
David Vassallo
41f5ebc403
Update win_alert_ad_user_backdoors.yml
...
the original rule generates false positives if the "AllowedToDelegateTo" is set to "-". This seems to be a common occurrence, hence my proposed addition
2019-06-07 13:29:45 +03:00
Unknown
7b0ecde334
Renamed jusched
...
https://www.bitdefender.com/files/News/CaseStudies/study/262/Bitdefender-WhitePaper-An-APT-Blueprint-Gaining-New-Visibility-into-Financial-Threats-interactive.pdf
2019-06-06 14:03:02 +02:00
Unknown
5037f7bf54
Merge remote-tracking branch 'sigma/development' into development
2019-06-06 13:45:25 +02:00
t0x1c-1
7b9a73fb1f
Improved Rule
...
Removed complex CommandLine
2019-06-06 13:45:21 +02:00
t0x1c-1
701801796c
Improved Rule
...
Removed complex CommandLine
2019-05-18 17:43:31 +02:00
Alec Costello
886de39814
Small edits
...
Got trigger happy, first time doing this, please dont cruicify me.
2019-05-17 17:40:32 +03:00
Alec Costello
34d9b4b365
Update win_susp_process_creations.yml
...
Tested the type method redirecting to a file and dumping the hashes out with pwdump.
Used the wmic method to create the shadow copy.
2019-05-17 16:10:43 +03:00
Alec Costello
3c8be3d48b
Update win_susp_vssadmin_ntds_activity.yml
2019-05-17 15:19:03 +03:00
Alec Costello
8b14a5673d
Update win_susp_vssadmin_ntds_activity.yml
...
Updated with SAM and SYSTEM for esentutl
2019-05-17 15:18:01 +03:00
Alec Costello
d90c0ea990
Create powershell_nishang_malicious_commandlets.yml
2019-05-16 17:51:45 +03:00