Thomas Patzke
e248012783
Release 0.19
2021-02-23 21:27:14 +01:00
Thomas Patzke
5cfd837776
Removed irrelevant type check in fieldlist backend
...
Fixes issue #1351
2021-02-23 21:15:29 +01:00
Thomas Patzke
74ae89833f
Added long description to PyPI distribution
2021-02-23 21:06:25 +01:00
Florian Roth
c38e998846
Merge pull request #1356 from roysjosh/master
...
fix: case in level
2021-02-23 09:37:36 +01:00
Joshua Roys
025a17e44b
fix: case in level
...
Otherwise es-rule ends up with a null risk_score and invalid severity.
2021-02-22 21:34:06 -05:00
Florian Roth
96803a5a27
Merge pull request #1355 from Neo23x0/rule-devel
...
Rule devel
2021-02-22 17:46:21 +01:00
Florian Roth
94035e1e11
fix: error in condition
2021-02-22 17:30:11 +01:00
Florian Roth
749789c17d
fix: condition in eventlog rule
2021-02-22 17:24:19 +01:00
Florian Roth
aea03076c2
rule: simplified rule
2021-02-22 17:19:14 +01:00
Florian Roth
43b2ad580f
rule: DEWMODE webshell
2021-02-22 17:15:32 +01:00
Florian Roth
f834862833
Merge pull request #1107 from vburov/patch-10
...
Update win_susp_eventlog_cleared.yml
2021-02-18 11:19:53 +01:00
Florian Roth
a6684c66d6
Merge pull request #1110 from vburov/patch-11
...
Update win_disable_event_logging.yml
2021-02-18 11:18:32 +01:00
Florian Roth
f62fc2e889
Merge pull request #1341 from d4rk-d4nph3/master
...
Added rule for TerraMaster TOS CVE-2020-28188
2021-02-18 11:17:48 +01:00
Florian Roth
786a799c3f
Merge pull request #1345 from blueteam0ps/patch-2
...
Created win_sus_auditpol_usage.yml
2021-02-18 11:17:04 +01:00
Florian Roth
76e6f38215
Merge pull request #1348 from bartlomiej-czyz/patch-1
...
Create win_metasploit_or_impacket_smb_psexec_service_install.yaml
2021-02-18 11:14:40 +01:00
Florian Roth
089a931007
rule: ScreenConnect remote access
2021-02-11 13:04:16 +01:00
Florian Roth
4c2691d3c3
rule: disable windows eventlog
2021-02-11 12:28:52 +01:00
Florian Roth
18f2e32774
Domestic Kitten Furball malware pattern
2021-02-08 17:52:55 +01:00
bartlomiej-czyz
b771fb0c55
Change win_metasploit_or_impacket_smb_psexec_service_install.yml severity level
2021-02-08 12:45:59 +01:00
Florian Roth
da570ba173
Merge pull request #1217 from noraj/patch-2
...
readme: package in linux distros
2021-02-08 09:29:08 +01:00
Florian Roth
08a5f400ba
Update README.md
2021-02-07 15:27:59 +01:00
Florian Roth
8ae8c213a9
Merge pull request #1337 from architect00/master
...
rule: scheduled task deletion
2021-02-07 15:26:13 +01:00
Florian Roth
10d440eb15
Merge pull request #1349 from bartlomiej-czyz/patch-2
...
Create win_rundll32_without_parameters.yml
2021-02-07 15:21:45 +01:00
Florian Roth
12054544bb
Merge pull request #1350 from Christopolos94/master
...
Updated fields to align with MS Advanced Threat Hunting Schema.
2021-02-04 13:23:38 +01:00
Chris Brake
4aa7505b40
Updated fields to align with MS Advanced Threat Hunting Schema. Standardised and sorted fields across schemas.
2021-02-04 11:54:29 +00:00
bartlomiej-czyz
ae15cef5e7
Rename .yaml to .yml
2021-02-03 22:20:48 +01:00
bartlomiej-czyz
e79168ee56
Create win_rundll32_without_parameters.yml
2021-02-03 22:18:23 +01:00
bartlomiej-czyz
3e9c177c65
Create win_metasploit_or_impacket_smb_psexec_service_install.yaml
2021-02-03 22:16:21 +01:00
BlueTeamOps
c3c706503e
Update win_sus_auditpol_usage.yml
2021-02-02 22:24:54 +11:00
BlueTeamOps
b0d0bb95b0
Created win_sus_auditpol_usage.yml
...
This adds detection for suspicious behaviour of the auditpol binary
2021-02-02 19:12:13 +11:00
Bhabesh Rai
a8d33171d7
Fixed c-uri
2021-02-02 10:23:47 +05:45
Florian Roth
309e15dc5c
rule: add call by ordinal
2021-02-01 20:16:31 +01:00
Florian Roth
597633c938
rule: ShimCache Flush
2021-02-01 20:05:28 +01:00
Florian Roth
e80e4b210f
fix: missing global action and sections
2021-02-01 20:00:17 +01:00
Florian Roth
2c48d2b0bb
fix: missing global action and sections
2021-02-01 20:00:06 +01:00
Thomas Patzke
9eafc8d6a5
Merge pull request #1342 from k3mpaxl/master
...
Fixing Qradar implementation for creating valid AQL queries
2021-02-01 19:58:39 +01:00
Bhabesh Rai
63e2f4bbce
Added rule for Sudo CVE-2021-3156 Exploitation Attempt
2021-02-01 23:08:45 +05:45
Florian Roth
179db920ec
Merge pull request #1343 from Neo23x0/rule-devel
...
Rule devel
2021-02-01 12:28:22 +01:00
Florian Roth
aaeb72a2b6
fix: FPs
2021-02-01 11:47:23 +01:00
Florian Roth
33fee6af8b
rule: security product uninstallation
2021-01-30 11:24:08 +01:00
Florian Roth
e533b4effb
fix: tags
2021-01-28 13:51:51 +01:00
Florian Roth
cd4491cba2
rule: disable volume snaptshots
2021-01-28 13:48:30 +01:00
Gregor
921ebf7445
Optimizing Qradar query generation in cases where field definitions are missing
2021-01-26 15:24:44 +01:00
Gregor
ac3730d2fa
Fixing Qradar implementation for create valid AQL queries
2021-01-25 15:37:05 +01:00
Florian Roth
6b9eef58da
Merge pull request #1338 from Neo23x0/rule-devel
...
Improved UNC2452 activity rules
2021-01-25 14:36:44 +01:00
Florian Roth
7d99a48bb2
rule: new Quakbot pattern
2021-01-25 12:03:30 +01:00
Florian Roth
a4bec724a6
rule: SonicWall exploitation
2021-01-25 11:54:23 +01:00
Bhabesh Rai
465ab713b0
Added rule for TerraMaster TOS CVE-2020-28188
2021-01-25 13:01:27 +05:45
Thomas Patzke
72468e671f
Merge pull request #1340 from WuerthIT/bugfix_field_support
...
bugfix field support
2021-01-22 16:58:45 +01:00
Florian Roth
e34bed0f76
Merge pull request #1339 from WuerthIT/fix_for_pcap_rule
...
fix service from system to security for rule win_pcap_drivers.yml
2021-01-22 16:15:23 +01:00
k-vdv
89a4e48b0a
bugfix field support
2021-01-22 09:28:23 +01:00
Florian Roth
b62c705bf0
Improved UNC2452 activity rules
2021-01-22 09:18:11 +01:00
k-vdv
e4edf7bc1b
fix service from system to security for rule win_pcap_drivers.yml
2021-01-22 09:10:02 +01:00
David Straßegger
6a6929cfb6
implemented rule for scheduled task deletion
2021-01-22 08:09:56 +01:00
Florian Roth
efa39eb18d
Merge pull request #1336 from Neo23x0/rule-devel
...
rule: Raccine uninstall
2021-01-21 18:17:31 +01:00
Florian Roth
4ad70f0aaa
rule: Raccine uninstall
2021-01-21 17:59:17 +01:00
Florian Roth
492d931138
Merge pull request #1335 from Neo23x0/rule-devel
...
rule: UNC2452 PowerShell pattern
2021-01-21 09:20:22 +01:00
Florian Roth
c5a7558ca0
fix: fixed actor name in description
2021-01-21 09:19:51 +01:00
Florian Roth
a0b8eeac6f
fix: minor issues
2021-01-20 18:52:50 +01:00
Florian Roth
8b319e3686
rule: UNC2452 PowerShell pattern
2021-01-20 18:51:49 +01:00
Florian Roth
cd4fbca66b
Merge pull request #1330 from d4rk-d4nph3/master
...
Added Stealthy Office Persistence via VSTO
2021-01-20 11:36:25 +01:00
Florian Roth
c00d3a8fe0
Merge pull request #1334 from Neo23x0/rule-devel
...
rule: plink anomaly rules
2021-01-20 11:36:16 +01:00
Bhabesh Rai
dac229a8bb
Added rule for Oracle WebLogic Exploit CVE-2021-2109
2021-01-20 14:28:18 +05:45
Florian Roth
eedc483be4
rework: impossible rule with Sysmon
2021-01-19 14:12:40 +01:00
Florian Roth
fdc969385a
rule: plink anomaly rules
2021-01-19 12:39:40 +01:00
Florian Roth
7162528a1a
docs: removed CVE
2021-01-15 13:25:10 +01:00
Florian Roth
3d2c6a118d
Merge pull request #1332 from 2d4d/master
...
Add xHunt Campaign: BumbleBee Webshell
2021-01-13 18:19:01 +01:00
Florian Roth
d58cdeab3a
Merge pull request #1331 from Neo23x0/rule-devel
...
rule: NTFS vulnerability
2021-01-12 09:09:33 +01:00
Arnim Rupp
b2860b870e
Update win_webshell_detection.yml
2021-01-11 21:08:20 +01:00
Florian Roth
cf37abee4d
docs: more details
2021-01-11 19:56:36 +01:00
Arnim Rupp
5d80d634c3
Add xHunt Campaign: BumbleBee Webshell
...
add commands and TTP from https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/
2021-01-11 19:44:07 +01:00
Florian Roth
a0fccf8647
rule: NTFS vulnerability
...
https://twitter.com/jonasLyk/status/1347900440000811010
2021-01-11 14:51:26 +01:00
Bhabesh Rai
93c7931037
Added Stealthy Office Persistence via VSTO
2021-01-10 17:54:17 +05:45
Florian Roth
c571285fd8
Merge pull request #1329 from Neo23x0/rule-devel
...
Rule devel
2021-01-09 11:32:36 +01:00
Florian Roth
63cc0d23c6
changes provided by FPT.EagleEye Team in
...
https://github.com/Neo23x0/sigma/pull/1218/files
2021-01-09 10:38:20 +01:00
Florian Roth
19171f5bed
Merge pull request #1315 from rtkdmasse/split-up-cmstp-rule
...
Split up cmstp rule into 3 separate rules and remove duplicates
2021-01-09 10:30:33 +01:00
Florian Roth
947925d81f
Merge pull request #1318 from rtkdmasse/azure-sysmon-image_load-generic
...
Update the azure image_load rule to be a generic sysmon rule
2021-01-09 10:29:52 +01:00
Florian Roth
04f7766d7a
Merge pull request #1319 from hieuttmmo/master
...
Detect Emotet DLL loading by looking rundll32.exe
2021-01-09 10:29:24 +01:00
Florian Roth
1a8bb9c991
Merge pull request #1327 from 2d4d/master
...
more AV event and suspicious commands
2021-01-09 10:28:30 +01:00
Arnim Rupp
d5de3fe5f9
more AV event and suspicious commands
...
some of the AV events are duplicates to win_av_relevant_match.yml, should we clean that up or include the strings in both?
2021-01-07 17:54:19 +01:00
Florian Roth
30dcc28a1f
Cisco ASA FTD Exploit CVE-2020-3452
2021-01-07 13:17:58 +01:00
Florian Roth
11c216629b
fix: thor sources for applocker with wrong prefix
2021-01-07 12:27:37 +01:00
yugoslavskiy
5ec4e42569
Merge pull request #1165 from w0rk3r/oscd3
...
[OSCD] Updated win_etw_trace_evasion - Added new detections, Removed reference to deprecated rule and changed selections
2021-01-06 00:12:22 +03:00
Thomas Patzke
789dfb3f47
Merge pull request #1291 from lprat/fix_issue_1285
...
fix issue 1285
2020-12-30 23:06:38 +01:00
Thomas Patzke
675d93ee3d
Replaced string comparison with isinstance
2020-12-30 22:50:13 +01:00
Thomas Patzke
1bb0963784
Moved set_size option to class where it's used
2020-12-30 22:25:57 +01:00
Thomas Patzke
ac55c7fdd4
Merge branch 'elasticsearch_backend' of https://github.com/WuerthIT/sigma into pr-1308
2020-12-30 22:18:13 +01:00
Florian Roth
ab408750ac
Merge pull request #1314 from Neo23x0/rule-devel
...
rule: Lazarus activity
2020-12-30 13:27:38 +01:00
Florian Roth
9ecaeb715f
Merge pull request #1317 from rtkdmasse/fix-missing-product-mouse-lock
...
Fix missing product mouse lock
2020-12-30 13:27:20 +01:00
Florian Roth
15f5efc9c4
Merge pull request #1322 from maravedi/patch-1
...
Update sumologic.yml
2020-12-29 17:59:13 +01:00
Florian Roth
126a17a276
Merge pull request #1323 from ZikyHD/master
...
Typo on field name
2020-12-29 15:39:36 +01:00
ZikyHD
8a6b182fee
Update win_susp_adfind.yml
2020-12-29 14:41:46 +01:00
ZikyHD
ece829bb25
Update win_susp_adfind.yml
...
Typo on field name
2020-12-29 14:40:36 +01:00
maravedi
fa6f75f07e
Update sumologic.yml
...
The commit from vihreb on October 6, 2020 (https://github.com/Neo23x0/sigma/commit/51df5ad8764cd6896a3ef83ad388aebc136d5815 ) removed some items from the allowed fields list for the sumologic backend (https://github.com/Neo23x0/sigma/blob/51df5ad8764cd6896a3ef83ad388aebc136d5815/tools/sigma/backends/sumologic.py#L161 ) with the expectation that they are included in the sumologic config, however the default sumologic config does not reflect that change. This breaks the parsing of maps from rules. For example, when trying to run sigmac on a rule with multiple EventID values, the result is an error that states "argument of type 'int' is not iterable."
I suspect that this change in the behavior of the backend was made to accommodate for new sumologic-cse config which may not need the additional allowed fields that the regular sumologic config does. As such, I think it would probably make the most sense to re-add these fields to the sumologic config file rather than directly back into the backend for sumologic.
Note: In the config, I did not include those fields that are presently hard coded in the allowed field list in the sumologic backend (e.g. _sourceCategory and _view were removed). I also removed "sourcename" since from what I can tell, the syntax that vihreb added to the sumologic backend "_sourceName" is actually correct.
2020-12-28 16:46:32 -05:00
Florian Roth
0a83f91386
Merge pull request #1321 from d4rk-d4nph3/master
...
Fixed typo in file format
2020-12-28 09:13:48 +01:00
Bhabesh Rai
bf77c8266a
Fixed typo in file format
2020-12-28 11:46:02 +05:45
Florian Roth
896fc21911
Merge pull request #1320 from d4rk-d4nph3/master
...
Added rule for CVE-2020-10148 SolarWinds Orion API Authentication Bypass
2020-12-27 20:37:36 +01:00
Florian Roth
a6212a4490
style: some minor style changes
2020-12-27 20:06:19 +01:00
Bhabesh Rai
1cfad987b0
Added rule for CVE-2020-10148 SolarWinds Orion API Authentication Bypass
2020-12-27 17:34:49 +05:45
Florian Roth
43033ab874
Update win_susp_emotet_rudll32_execution.yml
2020-12-25 09:05:55 +01:00
Tran Trung Hieu
d551b88d5c
Edit title convention
2020-12-25 14:21:26 +07:00
Tran Trung Hieu
4297e68704
Detect Emotet DLL loading by looking rundll32.exe
2020-12-25 14:09:40 +07:00
Daniel Masse
fedda17231
Update the azure image_load rule to be a generic sysmon rule
2020-12-23 16:29:49 -05:00
Daniel Masse
bf539fd1fe
Revert "Fix bug changing the logsource service to category"
...
This reverts commit 0f51e53d0e .
2020-12-23 15:50:49 -05:00
Daniel Masse
71ea5c7437
Add missing product in logsource
2020-12-23 15:45:00 -05:00
Daniel Masse
0f51e53d0e
Fix bug changing the logsource service to category
2020-12-23 15:12:31 -05:00
Daniel Masse
e4c052154d
Remove unneeded file
2020-12-23 14:30:24 -05:00
Daniel Masse
d2edf715f2
Split up cmstp rule into 3 separate rules and remove duplicates
2020-12-23 12:17:39 -05:00
Florian Roth
dedc34e91a
fix: typos and description
2020-12-23 14:46:08 +01:00
Florian Roth
cdc29dfbe8
rule: Lazarus activity
2020-12-23 14:43:32 +01:00
Florian Roth
821af35557
Merge pull request #1313 from Neo23x0/rule-devel
...
Rule devel
2020-12-23 13:57:11 +01:00
Florian Roth
7286d01f78
fix: typo in rule
2020-12-23 13:26:44 +01:00
Florian Roth
80aa398392
rule: Lazarus group loaders
2020-12-23 13:25:16 +01:00
Florian Roth
e67d17a967
rule: improved solarwinds webshell rule
2020-12-22 10:36:34 +01:00
Florian Roth
f20f346a6a
Merge pull request #1264 from omkar72/sdev-1
...
Adding 2 rules - Conhost & office test registry persistence
2020-12-21 18:28:59 +01:00
Florian Roth
f46c590d91
Merge pull request #1288 from 0xtf/patch-1
...
add SIEGMA and S2AN
2020-12-21 18:27:52 +01:00
Florian Roth
a314b54f93
docs: fix typo
2020-12-21 18:27:43 +01:00
Florian Roth
e78d7e6aee
Merge pull request #1296 from mat-gas/fix-references
...
fix "references" field + add test for references in plural form
2020-12-21 18:25:35 +01:00
Florian Roth
377454cb31
Merge pull request #1299 from tjgeorgen/patch-1
...
ATT&CK subtechnique tag updates
2020-12-21 18:24:00 +01:00
Florian Roth
35ab80b39e
Merge pull request #1306 from d4rk-d4nph3/master
...
Added rule for Impacket's PsExec execution
2020-12-21 18:23:41 +01:00
Florian Roth
1bb249c6ec
Merge pull request #1312 from Neo23x0/rule-devel
...
rule: Solarwinds SUPERNOVA web shell access
2020-12-21 11:30:56 +01:00
Florian Roth
9c8e1387a9
rule: Solarwinds SUPERNOVA web shell access
2020-12-17 09:05:08 +01:00
k-vdv
7e6f01f611
elasticsearch backend: new parameter and fields support
2020-12-14 16:07:09 +01:00
Bhabesh Rai
0a7e95954e
Fix for fail build
2020-12-14 12:55:08 +05:45
Bhabesh Rai
63fb31882e
Added rule for Impacket's PsExec execution
2020-12-14 12:48:26 +05:45
Florian Roth
80e1a5e7eb
Merge pull request #1292 from toffeebr33k/master
...
Create 2 new rules on AWS Privilege Escalation and AWS Enumeration
2020-12-13 19:06:44 +01:00
Florian Roth
1b0aaf62c3
Merge pull request #1266 from omkar72/ryuk
...
modifying couple of rules
2020-12-13 19:05:54 +01:00
Florian Roth
e2ade077ed
Merge pull request #1275 from bczyz1/patch-3
...
update win_apt_slingshot.yml
2020-12-13 19:04:47 +01:00
Florian Roth
d1f7a206b9
Merge pull request #1289 from weslambert/master
...
Fix typo
2020-12-13 19:04:07 +01:00
Florian Roth
9f70bcab23
Merge pull request #1300 from shilch/master
...
Add sigmac flag to delimit results by NUL instead of \n
2020-12-13 19:03:27 +01:00
Florian Roth
5197f21ed1
fix: duplicate ID
2020-12-13 18:59:04 +01:00
Florian Roth
c6eadea9d9
Merge pull request #1304 from hieuttmmo/master
...
Detects suspicious shell spawn from MSSQL process, this might be sigh…
2020-12-11 18:40:27 +01:00
Florian Roth
612008a4d8
fix identation
2020-12-11 18:40:17 +01:00
Tran Trung Hieu
edc79a8bb6
Detects suspicious shell spawn from MSSQL process, this might be sight of RCE or SQL Injection
2020-12-11 15:17:23 +07:00
Florian Roth
cfe60d180b
Merge pull request #1301 from d4rk-d4nph3/master
...
Added rule for Fortinet CVE-2018-13379 preauth file read exploitation.
2020-12-08 11:09:51 +01:00
Florian Roth
b6d62b7a21
Merge pull request #1302 from Neo23x0/rule-devel
...
TA505 Dropper, minor fix in PowerShell Rule
2020-12-08 10:40:07 +01:00
Florian Roth
2c642c64d2
Removed a value
2020-12-08 10:38:32 +01:00
Florian Roth
a87a81d8cc
Update web_fortinet_cve_2018_13379_preauth_read_exploit.yml
2020-12-08 10:33:52 +01:00
Florian Roth
640470cefd
TA505 Loader Rule
2020-12-08 10:15:30 +01:00
Bhabesh Rai
3ddf940812
Added rule for Fortinet CVE-2018-13379 preauth file read exploitation.
2020-12-08 14:46:47 +05:45
Simon
97fcae56fd
Update sigmac.py
2020-12-06 20:08:00 +01:00
Florian Roth
540039cbc3
fix: Malicious Nishang PowerShell Commandlets FP with MDATP
2020-12-05 09:33:42 +01:00
Simon
4a4d3e1d35
Update sigmac.py
2020-12-04 18:22:24 +01:00
Simon Hilchenbach
a40ef7360d
Add sigmac flag to delimit results by NUL instead of \n
2020-12-04 18:05:23 +01:00
tjgeorgen
1c6c3a36fe
include updated RDP att&ck tag
2020-12-04 11:59:23 -05:00
tjgeorgen
0eda1ab462
also update tag for folder variant
2020-12-04 11:42:05 -05:00
tjgeorgen
5208bdd65a
add new version of ATT&CK T1500 tag
2020-12-04 11:19:16 -05:00
Thomas Patzke
578d2f0585
Merge pull request #1283 from 404d/mdatp-fixes
...
mdatp: Mapping and generic event changes, case insensitive search
2020-11-29 21:56:17 +01:00
OG
70fb078a56
Update sysmon_office_test_regadd.yml
2020-11-29 18:02:37 +05:30
OG
8e801ede32
Update win_susp_psexec_eula.yml
2020-11-29 17:45:29 +05:30
mat
b3e36281b5
fix reference field + add test for references in plural form
2020-11-27 10:17:45 +01:00
Florian Roth
3d39d49d65
Merge pull request #1295 from findthebad/fix-winlogbeat-config
...
Updated winlogbeat.yml config to include OriginalFileName
2020-11-26 23:17:45 +01:00
findthebad
ad899899ab
Updated winlogbeat.yml config to include OriginalFileName
2020-11-26 14:48:14 -05:00
Florian Roth
084cd39505
Merge pull request #1294 from Neo23x0/devel
...
Trickbot rules improved
2020-11-26 10:13:35 +01:00
Florian Roth
c6fc9de144
New Trickbot wermgr rule
2020-11-26 09:54:27 +01:00
Florian Roth
c111ab3141
Improved Trickbot recon rule
2020-11-26 09:54:13 +01:00
Florian Roth
b31ed47ccf
Merge branch 'master' into devel
2020-11-26 09:44:56 +01:00
Florian Roth
13354dd7a2
Merge pull request #1293 from hegga/cb-fix-domain-fieldmapping
...
Fix field mapping for DestinationHostname
2020-11-26 09:40:28 +01:00
Helge Aksdal
3a7c114ca3
Fix field mapping for DestinationHostname
2020-11-26 04:17:28 +01:00
bczyz1
05398ae95e
change field newprocessname -> image
2020-11-23 13:43:19 +01:00
toffeebr33k
c8c4183678
Update aws_enum_listing.yml
2020-11-22 01:53:58 +08:00
toffeebr33k
3d0e1988c6
Update aws_enum_listing.yml
2020-11-22 01:41:20 +08:00
toffeebr33k
273590b151
Update aws_enum_listing.yml
2020-11-22 01:17:42 +08:00
toffeebr33k
52fca0fe3a
Update aws_enum_listing.yml
2020-11-22 01:05:56 +08:00
toffeebr33k
e764ca687a
Update aws_enum_listing.yml
2020-11-22 00:50:34 +08:00
toffeebr33k
00504ee186
Update aws_update_login_profile.yml
2020-11-22 00:42:25 +08:00
toffeebr33k
3dd1525b98
Update aws_update_login_profile.yml
2020-11-22 00:38:41 +08:00
toffeebr33k
6b65180464
Add files via upload
2020-11-22 00:33:47 +08:00
toffeebr33k
cff82ff79a
Delete aws_update_login_profile.yml
2020-11-22 00:33:17 +08:00
toffeebr33k
7e1c918b4d
Delete aws_enum_listing.yml
2020-11-22 00:32:59 +08:00
toffeebr33k
551764b630
Add files via upload
2020-11-22 00:26:17 +08:00
toffeebr33k
3dd25ddea4
Delete aws_update_login_profile.yml
2020-11-22 00:25:54 +08:00
toffeebr33k
fba9c12bb2
Delete aws_enum_listing.yml
2020-11-22 00:25:29 +08:00
toffeebr33k
6c1f3f5969
Update aws_update_login_profile.yml
2020-11-21 23:45:10 +08:00
toffeebr33k
70e725e82e
Update aws_enum_listing.yml
2020-11-21 23:44:14 +08:00
toffeebr33k
596d1b6e4c
Update aws_update_login_profile.yml
2020-11-21 23:29:49 +08:00
toffeebr33k
a786ebd04b
Update aws_enum_listing.yml
2020-11-21 23:28:57 +08:00
toffeebr33k
1ca903b168
Update aws_enum_listing.yml
2020-11-21 23:22:07 +08:00
toffeebr33k
7f61591865
Add files via upload
2020-11-21 23:12:50 +08:00
Thomas Patzke
0ed54a6cae
Merge pull request #1290 from arollyson/helix_backend
...
Backend: FireEye Helix
2020-11-21 00:06:19 +01:00
Lionel
7ca368d1ed
fix issue 1285
...
https://github.com/Neo23x0/sigma/issues/1285
2020-11-20 16:42:20 +01:00
bczyz1
193021eff8
Update win_apt_slingshot.yml
...
fix condition
2020-11-20 09:19:03 +01:00
Alek Rollyson
83b8af6cd2
Add FirEye Helix backend
2020-11-19 11:18:28 -05:00
weslambert
832e582b8d
Fix typo
2020-11-17 17:44:40 -05:00
Tiago Faria
93b06d5425
add SIEGMA and S2AN
2020-11-17 22:36:47 +00:00
Florian Roth
7566f19635
Merge pull request #1267 from w0rk3r/ecs-1
...
Suricata ECS
2020-11-17 15:05:47 +01:00
Florian Roth
9944c0e563
Merge branch 'master' into pr/1267
2020-11-17 14:33:55 +01:00
Florian Roth
1540241106
Merge branch 'master' of https://github.com/Neo23x0/sigma
2020-11-17 14:29:42 +01:00
Florian Roth
88e3de816d
docs: uberAgent ESA target in README
2020-11-17 14:29:36 +01:00
Florian Roth
c5c6557ca2
Merge pull request #1256 from vastlimits/master
...
Backend: uberAgent ESA converter backend
2020-11-17 14:29:01 +01:00
Florian Roth
94540ea0b6
Merge pull request #1284 from heyibrahimkhan/master
...
added role name field to ecs-cloudtrail.
2020-11-17 14:24:40 +01:00
heyibrahimkhan@gmail.com
eed4fe04d5
added role name field to ecs-cloudtrail.
2020-11-13 05:59:55 +05:00
Simen Lybekk
c0a7cdc3de
mdatp: Use case-insensitive searches by default
...
This sohuld match the draft Sigma specification as well as other backends
2020-11-12 14:09:30 +01:00
Simen Lybekk
a75d4fb561
mdatp: Add more field mappings and table<->generic event mappings, skip IMPHASH as it's not supported
2020-11-12 13:15:38 +01:00
Sven Scharmentke
446b0b7f9d
Merge branch 'master_origin'
2020-11-11 12:32:53 +01:00
Sven Scharmentke
a58d04e4df
Rules: Support image_load
2020-11-11 12:31:55 +01:00
Thomas Patzke
43b9b17767
Merge pull request #1281 from andurin/kibana-ndjson-configs
...
kibana-ndjson for all configs which already have kibana
2020-11-11 07:34:37 +01:00
Florian Roth
af4d546408
Merge pull request #1282 from Neo23x0/rule-devel
...
fix: FPs with notepad++ GUP rule
2020-11-10 13:39:28 +01:00
Florian Roth
2e9d7951a6
Merge pull request #1272 from bczyz1/patch-2
...
Fix typo in win_apt_lazarus_session_hijack.yml
2020-11-10 13:35:08 +01:00
Florian Roth
230562bdf6
Merge pull request #1278 from K-Yo/update-navigator-v4
...
Update navigator v4
2020-11-10 13:34:46 +01:00
Florian Roth
c087e39698
Merge pull request #1277 from K-Yo/fix-unicode-error
...
Fix unicode error in sigma2attack
2020-11-10 13:34:05 +01:00
Florian Roth
f6c0fb2d33
fix: FPs with notepad++ GUP rule
2020-11-09 16:34:12 +01:00
Hendrik
7e742cc049
kibana-ndjson for all configs which already have kibana
2020-11-09 08:46:17 +01:00
Thomas Patzke
485457ee55
Merge pull request #1280 from andurin/kibana-ndjson
...
Elasticsearch Kibana ndjson backend
2020-11-06 13:44:00 +01:00
Hendrik
96e90fbff2
Fix recursion of rules
2020-11-06 12:43:52 +01:00
Olivier Caillault
34f24a60a1
Updating attack navigator version to v4.0
2020-11-05 23:37:01 +01:00
Hendrik
bf5d40eec3
New Backend - Kibana NDJSON
...
Tested against 7.9.3
2020-11-05 23:34:25 +01:00
K-Yo
c17c1fa96b
Merge pull request #1 from K-Yo/fix-unicode-error
...
Fix unicode error in sigma2attack
2020-11-05 22:39:54 +01:00
Olivier Caillault
31639366cd
Fix unicode error in sigma2attack
2020-11-05 22:30:12 +01:00
Florian Roth
6dfeb6a63b
Merge pull request #1276 from Neo23x0/rule-devel
...
rule: FPs with WmiPrvSE rule
2020-11-05 17:04:25 +01:00
Florian Roth
c3785d6dc7
rule: FPs with WmiPrvSE rule
2020-11-05 16:44:33 +01:00
bczyz1
c554aaea8f
update win_apt_slingshot.yml
...
- optimized rule
- added detection of task modification (flag /change + /disable as described here https://stackoverflow.com/questions/26169582/does-anyone-know-of-a-way-to-turn-off-windows-defragmenters-default-schedule-us )
2020-11-05 15:51:22 +01:00
Florian Roth
784150b66c
Merge pull request #1273 from Neo23x0/rule-devel
...
rule: added second expression
2020-11-04 17:09:47 +01:00
Florian Roth
908023fa66
rule: added second expression
2020-11-04 16:43:35 +01:00
bczyz1
4a5b2d642e
Fix typo in win_apt_lazarus_session_hijack.yml
2020-11-03 14:46:29 +01:00
Florian Roth
413abf13cd
Merge pull request #1270 from Neo23x0/rule-devel
...
rule: reworked weblogic CVE-2020-14882 rule
2020-11-03 10:40:39 +01:00
Florian Roth
f848bb912c
rule: reworked weblogic CVE-2020-14882 rule
2020-11-03 10:39:40 +01:00
Florian Roth
b218264d47
Merge pull request #1268 from Neo23x0/rule-devel
...
rule: WebLogic exploit CVE-2020-14882
2020-11-03 10:35:05 +01:00
Thomas Patzke
c202feaf87
Merge pull request #1269 from Neo23x0/ci
...
Removed ES query tests
2020-11-02 23:11:05 +01:00
Thomas Patzke
31241d9bbd
Removed ES query tests
2020-11-02 22:57:01 +01:00
Florian Roth
dd0d1d053c
rule: WebLogic exploit CVE-2020-14882
2020-11-02 11:11:37 +01:00
Jonhnathan
9173fb2cb9
Update Makefile
2020-11-01 21:28:26 -03:00
Jonhnathan
83f2646667
Merge branch 'ecs-1' of https://github.com/w0rk3r/sigma into ecs-1
2020-11-01 21:22:48 -03:00
Jonhnathan
21161c82cc
Revert "Create win_susp_replace_lolbin.yml"
...
This reverts commit e6a6549676 .
2020-11-01 21:21:47 -03:00
Jonhnathan
90e211bad8
Create ecs-suricata.yml
2020-11-01 21:21:04 -03:00
Jonhnathan
c84641d332
Revert "Changed the rule to download only and not the copy"
...
This reverts commit 1324bc1ad1 .
2020-11-01 20:36:02 -03:00
Jonhnathan
972a04fb60
Revert "Update win_susp_replace_lolbin.yml"
...
This reverts commit 6b2c235ab3 .
2020-11-01 20:35:59 -03:00
omkargudhate22
f1bb9726ca
updated mitre tag
2020-10-30 13:35:40 +05:30
omkar72
86a849728d
ryuk changes
2020-10-30 13:15:11 +05:30
omkargudhate22
df07d53fea
formatting values
2020-10-25 18:23:29 +05:30
omkargudhate22
06890ba28b
update title
2020-10-25 15:10:12 +05:30
omkar72
021842eaa3
office test reg
2020-10-25 12:36:08 +05:30
omkar72
42de51cadc
conhost executions
2020-10-25 12:33:59 +05:30
Florian Roth
6f9aeb5ea9
Merge pull request #1263 from Neo23x0/rule-devel
...
feat: cover newest emotet campaigns
2020-10-24 00:02:39 +02:00
Florian Roth
75637324e0
feat: cover newest emotet campaigns
2020-10-23 23:44:48 +02:00
Thomas Patzke
16d63cc5d2
Decreased coverage requirement
2020-10-23 20:17:58 +02:00
Thomas Patzke
f0e89b0c8c
Fixed: typecheck in sumologig-cse
2020-10-23 19:49:55 +02:00
Thomas Patzke
e30237c5c5
Fixed test configuration
2020-10-23 19:30:59 +02:00
Thomas Patzke
2fb7dd5e99
Fixes
...
* Removed Splunk regex query
* Added test for sumologic-cse backend
2020-10-23 15:31:00 +02:00
Thomas Patzke
9dc806448c
Merge branch 'master' of https://github.com/socprime/sigma into pr-1049
2020-10-23 14:57:25 +02:00
vh
383823f49a
Fix: added default value of current_table
2020-10-21 10:12:17 +03:00
Sven Scharmentke
c042651e4d
Merge pull request #1 from svnscha/feature/backend-uberagent
...
Backend: uberAgent ESA converter backend
2020-10-21 08:59:12 +02:00
Sven Scharmentke
ca852eca0e
PR Review: Minor fixes
2020-10-21 08:54:50 +02:00
vh
f45e45d736
Fix: Import SigmaRegularExpressionModifier in the splunk backend.
2020-10-20 18:13:53 +03:00
Florian Roth
e7462be5b9
Merge pull request #1254 from Neo23x0/rule-devel
...
Rule devel
2020-10-20 13:53:30 +02:00
Sven Scharmentke
03ad9e22e1
Backend: uberAgent ESA converter backend
...
This commit adds the first version of the uberAgent ESA converter backend for sigma. This backend generates ESA compatible query rules for uberAgent ESA Activity Monitoring.
2020-10-20 13:23:05 +02:00
Florian Roth
ee789a309c
fix: FP with expression
2020-10-20 13:11:10 +02:00
Florian Roth
198b292c26
rule: emotet encoded commands
2020-10-20 12:51:58 +02:00
Jonhnathan
6b2c235ab3
Update win_susp_replace_lolbin.yml
2020-10-18 23:44:18 -03:00
Alexandre ZANNI
c961fa046e
readme: package in linux distros
2020-10-17 15:50:19 +02:00
Florian Roth
75f177210e
Merge pull request #1205 from Neo23x0/rule-devel
...
fix: ping hex ip rule
2020-10-16 12:33:03 +02:00
Florian Roth
986b711de6
Merge branch 'master' into rule-devel
2020-10-16 12:01:29 +02:00
Florian Roth
48f1be04d4
fix: ping hex ip rule
2020-10-16 10:06:24 +02:00
Jonhnathan
8f6ad7df6b
Update win_etw_trace_evasion.yml
2020-10-15 09:22:13 -03:00
Jonhnathan
043033c1b7
Update win_etw_trace_evasion.yml
2020-10-13 22:59:06 -03:00
Jonhnathan
ac1a6927ad
Update win_etw_trace_evasion.yml
2020-10-13 22:55:13 -03:00
Jonhnathan
e3446b873a
Correct duplicated selection
2020-10-13 22:54:30 -03:00
Jonhnathan
b1c9871b74
Add Additional detections for other techniques
2020-10-13 22:51:48 -03:00
Jonhnathan
a01c08f617
Removed reference to deprecated rule and improve logic
2020-10-13 17:45:35 -03:00
Jonhnathan
4c75d22d93
Revert "Create win_susp_replace_lolbin.yml"
...
This reverts commit e6a6549676 .
2020-10-13 17:40:10 -03:00
Jonhnathan
1455d414bc
Revert "Changed the rule to download only and not the copy"
...
This reverts commit 1324bc1ad1 .
2020-10-13 17:40:07 -03:00
Thomas Patzke
f064102399
Merge pull request #996 from fryguy04/master
...
removed leading slash and allow for mult spaces
2020-10-12 23:32:17 +02:00
Thomas Patzke
976fc92b22
Merge pull request #971 from alan8trend/parse_nested_parentheses
...
Add support nested parentheses for Sigma condition
2020-10-12 23:30:36 +02:00
Thomas Patzke
e8cdd4777a
Merge pull request #1026 from ryanplasma/fix-pymisp-error
...
Fix error with pymisp in sigma2misp
2020-10-12 23:14:13 +02:00
Florian Roth
d30502cdab
Merge pull request #1134 from Neo23x0/rule-devel
...
Rule devel
2020-10-12 10:25:13 +02:00
Florian Roth
3affdd12e0
fix: rule title casing
2020-10-12 09:51:35 +02:00
Florian Roth
0d0cda0f86
docs: improved false positive notes
2020-10-12 09:18:42 +02:00
Florian Roth
e7c6794ecd
rule: suspicious wmic process call create + rundll32
2020-10-12 09:18:30 +02:00
Florian Roth
2e732eb01f
Merge branch 'master' into rule-devel
2020-10-12 09:13:24 +02:00
Vasiliy Burov
e10771652b
Update win_disable_event_logging.yml
2020-10-09 18:27:04 +03:00
Vasiliy Burov
c77a190a6b
Update win_susp_eventlog_cleared.yml
...
Added events about security log clearance. Also, I think that the rule "sigma/rules/windows/builtin/win_susp_security_eventlog_cleared.yml" can be deleted.
2020-10-09 16:51:18 +03:00
Jonhnathan
1324bc1ad1
Changed the rule to download only and not the copy
2020-10-07 16:18:21 -03:00
Jonhnathan
e6a6549676
Create win_susp_replace_lolbin.yml
...
Item 77 of #1014
2020-10-07 10:37:15 -03:00
vh
51df5ad876
Added:
...
Sumo Logic CSE Rule Backend
Updated:
Mapping depence on logsource
Azure Sentinel Query Backend
MDATP: query with few logsources
CROWDSTRIKE: fix generateMapItemTypedNode
2020-10-06 15:07:52 +03:00
Florian Roth
c56cd2dfff
Merge pull request #1024 from omkar72/master
...
Com hijack shell folder
2020-10-02 09:24:16 +02:00
omkargudhate22
4487d9cc7e
added event type & changed technique
2020-10-02 09:22:14 +05:30
Florian Roth
d3ee1aba66
docs: MITRE ATT&CK(R) trademark references removed or adjusted
...
https://github.com/Neo23x0/sigma/issues/1028
2020-09-30 08:53:52 +02:00
Ryan Plas
cdbee4b531
Fix error with pymisp in sigma2misp
2020-09-29 12:01:33 -04:00
Florian Roth
c17ca6d5fe
Merge pull request #1018 from savvyspoon/wcry-dns
...
WannaCry Killswitch domain DNS query
2020-09-29 09:27:21 +02:00
omkargudhate22
68a992d903
updated name
2020-09-27 21:57:19 +05:30
omkargudhate22
e7c8197e34
Updated fields & renamed
2020-09-27 21:52:59 +05:30
omkargudhate22
ebe3dce1d7
Update sysmon_comhijack_uac_bypass.yml
2020-09-27 21:44:41 +05:30
omkar72
3f148e6c7c
COM hijack of shell folder to execute arbitrary application & UAC bypass using sdclt.
2020-09-27 21:19:04 +05:30
omkargudhate22
15c8721e7b
Merge pull request #1 from Neo23x0/master
...
Updating my fork
2020-09-27 19:12:36 +05:30
Florian Roth
d7d9c0e772
Merge pull request #1021 from hieuttmmo/master
...
Sigma rule to detect AdFind.exe execution
2020-09-27 09:50:41 +02:00
Florian Roth
8020fe3c40
false positive condition
2020-09-26 17:03:29 +02:00
Florian Roth
60795f7050
Update win_susp_adfind.yml
...
Fear that a simple adfind.exe causes too many false positives
2020-09-26 17:02:39 +02:00
Florian Roth
dbdd758365
Duplicate Rule
...
we already have a rule for that
2020-09-26 17:01:32 +02:00
Tran Trung Hieu
d4dd0600ad
Fix logsource service to process_creation
2020-09-26 21:45:23 +07:00
Tran Trung Hieu
c756fc8576
Detect Suspicious AdFind Execution
2020-09-26 21:34:06 +07:00
Mike Wade
f76f80db80
Killswitch domain
2020-09-16 20:32:31 -06:00
Mike Wade
7b1ef9ea64
fixing test runner issues
2020-09-15 15:45:33 -06:00
Mike Wade
6ed36b0e41
fixed issues with tabs and duplicate tags
2020-09-15 08:52:00 -06:00
Florian Roth
2cd9b794e6
Merge pull request #1007 from d4rk-d4nph3/master
...
Windows Defender AMSI Trigger Detected
2020-09-15 15:45:00 +02:00
Florian Roth
19ccfb80da
Merge pull request #1016 from NVISO-BE/win_vul_cve_2020_1472
...
Added win_vul_cve_2020_1472 rule
2020-09-15 15:43:53 +02:00
Remco Hofman
6cadfa5b2b
Added win_vul_cve_2020_1472 rule
2020-09-15 15:13:53 +02:00
Mike Wade
1ddba05eb2
Second round
2020-09-15 07:02:30 -06:00
Mike Wade
da9b32bdd6
we
2020-09-15 06:24:44 -06:00
Mike Wade
8ce73bd8df
Fixed issues with tags and missing files
2020-09-15 06:10:57 -06:00
Thomas Patzke
b0ccf44243
Added test
2020-09-15 12:42:37 +02:00
Thomas Patzke
378d9c94cf
Merge branch 'master' of https://github.com/socprime/sigma into pr-981
2020-09-15 12:14:49 +02:00
Thomas Patzke
64961c6d42
Added test
2020-09-15 09:06:02 +02:00
Thomas Patzke
28426f9b7f
Merge branch 'Netwitness-EPL' of https://github.com/snake-jump/sigma into pr-1001
2020-09-15 08:29:03 +02:00
Florian Roth
50db6dcc69
Merge pull request #1002 from scottdermott/master
...
+ Adding exclusion for Azure AD Sync (MSOL_xxxxxxxx)
2020-09-15 08:17:02 +02:00
Florian Roth
ade9cf9b84
Merge pull request #1004 from oscd-initiative/master
...
fix typos, update tags
2020-09-15 08:16:25 +02:00
snake-jump
5119f887c8
add Regular expression support
...
Add Regular expression support for netwitness-epl backend
2020-09-14 22:04:47 +02:00
snake-jump
531557465c
delete raise exception in case of sigma key is keyword(s)
2020-09-14 16:00:03 +02:00
Bhabesh Rai
03c7d751c0
Windows Defender AMSI Trigger Detected
2020-09-14 18:10:38 +05:45
Mike Wade
57cae0ded1
Fixed reference typo
2020-09-13 22:07:43 -06:00
Mike Wade
52ab677798
Fixed my git issue
2020-09-13 22:03:04 -06:00
Mike Wade
249c255435
No Idea why these files are deleted
2020-09-13 22:00:30 -06:00
Yugoslavskiy Daniil
1fc202fe5d
fix typos, update tags
2020-09-13 15:46:45 +02:00
Dermott, Scott J
c72ac8f73e
Merge branch 'master' of https://github.com/scottdermott/sigma
2020-09-11 16:19:54 +01:00
Scott Dermott
1f50e0af35
+ Adding exclusion for Azure AD Sync (MSOL_xxxxxxxx)
...
AD Connect on premise AD accounts to Azure AD. The replication process is completed under the context of the 'MSOL_xxxxxxxx' user account. The AD Connect application is installed on a member server (i.e. not on a DC).
https://techcommunity.microsoft.com/t5/azure-advanced-threat-protection/ad-connect-msol-user-suspected-dcsync-attack/m-p/788028
2020-09-11 16:06:51 +01:00
snake-jump
09f25cf992
delete sqlparse module usage
2020-09-10 19:05:55 +02:00
snake-jump
e74846b767
modify comment
2020-09-10 18:09:15 +02:00
snake-jump
64035fd799
initial commit for Netwitness-EPL backend
2020-09-10 17:12:12 +02:00
Tran Trung Hieu
49ba107dce
Fixed Title
2020-09-10 17:36:37 +07:00
Tran Trung Hieu
f7d5240d40
Added UID, fixed rule description
2020-09-10 17:20:16 +07:00
Tran Trung Hieu
1b6c6ec5bf
Detects a suspicious activities of MpCmdRun.exe, which could be an action for downloading a file from the internet using Windows Defender
2020-09-10 17:16:06 +07:00
Florian Roth
7d6043bd0d
rule: reworked suspicious user agents
2020-09-10 10:33:11 +02:00
Florian Roth
0603264a09
Merge pull request #999 from d4rk-d4nph3/master
...
Added Credential Dumping by LaZagne
2020-09-09 15:13:23 +02:00
Bhabesh Rai
ed059a9831
Added Credential Dumping by LaZagne
2020-09-09 18:27:14 +05:45
Florian Roth
de5444a81e
Merge pull request #989 from oscd-initiative/master
...
[OSCD Initiative][ATT&CK tags update]
2020-09-08 13:27:58 +02:00
Florian Roth
af3b93a522
Merge pull request #914 from omergunal/ogunal-2
...
New rules for Linux
2020-09-07 09:41:43 +02:00
Florian Roth
39dfcd40ec
Merge pull request #921 from d4rk-d4nph3/master
...
Added support for Defender's PSExec and WMI ASR rules.
2020-09-07 09:40:46 +02:00
Florian Roth
6f96bbbe65
Merge pull request #977 from barvhaim/patch-1
...
Update win_new_service_creation.yml typo
2020-09-07 09:39:28 +02:00
Florian Roth
37751fc3a1
Merge pull request #978 from barvhaim/patch-2
...
Update sysmon_apt_muddywater_dnstunnel.yml typo
2020-09-07 09:39:11 +02:00
Florian Roth
2e6f87e2ef
Update win_susp_ping_hex_ip.yml
2020-09-07 09:34:18 +02:00
Florian Roth
f338f83270
Merge pull request #997 from EccoTheFlintstone/fp
...
Fix various false positives on windows rules
2020-09-07 09:33:22 +02:00
e6e6e
98c412044a
att&ck tags review: windows/process_creation part 5
...
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-09-07 02:00:41 +04:00
e6e6e
7ae76b8d99
Revert "att&ck tags review: windows/process_creation part 5"
...
This reverts commit e94c47e74e .
2020-09-07 01:28:08 +04:00
e6e6e
e94c47e74e
att&ck tags review: windows/process_creation part 5
...
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-09-07 01:19:41 +04:00
Alexey Lednyov
7834fdd750
att&ck tags review: windows/registry_event
2020-09-06 22:10:44 +03:00
ecco
ebc1d38027
fix in memory powershell false positive
2020-09-06 09:25:56 -04:00
ecco
b9f7d58dbc
fix ADSI rule false positive
2020-09-06 09:17:53 -04:00
grikos
961e4eef4c
att&ck tags review: windows/process_creation part 6
2020-09-05 20:35:21 +03:00
Florian Roth
e1529b445e
docs: added MITRE ATT&CK tags
2020-09-05 09:17:23 +02:00
Florian Roth
12a6ad224c
Merge branch 'master' into rule-devel
2020-09-05 09:13:34 +02:00
503139
df74abc957
removed leading slash and allow for mult spaces
2020-09-04 13:33:31 -04:00
Florian Roth
61e8498551
Merge pull request #995 from veritasr3x/master
...
Windows Defender LOLBIN
2020-09-04 17:06:24 +02:00
Florian Roth
22465037ac
Update win_susp_mpcmdrun_download.yml
2020-09-04 16:50:57 +02:00
Florian Roth
3283e33cbc
Update and rename win_lolbas_mpcmdrun.yml to win_susp_mpcmdrun_download.yml
2020-09-04 16:49:44 +02:00
Matthew Matchen
df532be142
Added ID field using UUID generated value
2020-09-04 16:38:52 +02:00
Matthew Matchen
2c69815b7b
Removed empty ID field
2020-09-04 16:32:41 +02:00
Matthew Matchen
e0baa097a8
Initial creation
2020-09-04 16:00:23 +02:00
veritasr3x
3e8dda723b
Merge pull request #1 from Neo23x0/master
...
Repo Update
2020-09-04 15:46:10 +02:00
aw350m3
bd5026f6b9
fixed typos in tags
2020-09-03 14:29:05 +00:00
aw350m3
198e42d724
deleted extra spaces
2020-09-03 14:22:31 +00:00
aw350m3
b00047a4e8
att&ck tags review: application, apt, cloud, generic, proxy
2020-09-03 14:16:54 +00:00
Alexey Lednyov
cf011e4a00
Removed duplicate key 'modified'
2020-09-03 17:12:37 +03:00
Alexey Lednyov
1eb675f693
att&ck tags review: web, network/zeek
2020-09-03 17:06:37 +03:00
Florian Roth
22547e188b
some fixes and additions
2020-09-03 13:30:21 +02:00
Florian Roth
4ade5bd957
Merge pull request #991 from Neo23x0/rule-devel
...
Rule devel
2020-09-03 12:15:05 +02:00
Florian Roth
720ac0d998
fix: syntax bug in rule
2020-09-03 09:18:28 +02:00
Yugoslavskiy Daniil
71fec94417
review network/cisco/aaa
2020-09-03 00:34:41 +02:00
Florian Roth
198469bed3
Merge branch 'master' into rule-devel
2020-09-02 17:40:12 +02:00
Florian Roth
423f81c912
Update win_mouse_lock.yml
2020-09-02 14:49:37 +02:00
Florian Roth
73bc514f60
fix: 1 of them / one selection
2020-09-02 12:34:35 +02:00
Florian Roth
7ddb63ec1b
fix: FPs with McAfee and CyberReason
2020-09-02 12:30:34 +02:00
Yugoslavskiy Daniil
11e0f794d9
review windows/process_creation part 4
2020-09-02 02:34:34 +02:00
aw350m3
7c6c5263ab
fix duplication of key modified in win_malware_emotet.yml
2020-09-01 17:09:54 +00:00
aw350m3
8ed3eb1494
att&ck tags review: windows/process_creation part 3
2020-09-01 17:02:59 +00:00
grikos
65d201b1e4
att&ck tags review: windows/process_creation part 7
2020-08-30 19:17:38 +03:00
Yugoslavskiy Daniil
e04b896cbc
fix tags
2020-08-29 21:34:20 +02:00
grikos
a95c4347d9
fixed typo in tag
2020-08-29 20:19:46 +03:00
grikos
6092bfcec1
att&ck tags review: windows/process_creation part 9
2020-08-29 19:22:09 +03:00
grikos
6eadfccc68
Merge branch 'master' of https://github.com/oscd-initiative/sigma
2020-08-29 12:30:45 +03:00
aw350m3
ae99a2b207
Removed extra space that broke tests
2020-08-29 04:46:12 +00:00
aw350m3
4ed3db8d23
Merge branch 'master' of github.com:oscd-initiative/sigma
2020-08-29 04:39:45 +00:00
aw350m3
da766a245f
att&ck tags review: windows/process_creation part 2
2020-08-29 04:39:30 +00:00
Yugoslavskiy Daniil
cd12ab8a77
Merge branch 'master' of https://github.com/oscd-initiative/sigma
2020-08-29 02:03:39 +02:00
Yugoslavskiy Daniil
5b70cfd3f7
review windows/sysmon
2020-08-29 02:03:28 +02:00
yugoslavskiy
21a8667720
Merge pull request #1 from zinint/master
...
Linux rules reviewed
2020-08-29 01:55:24 +02:00
yugoslavskiy
a3ec8729c6
Merge pull request #2 from grikos/attack_tags_review_process_creation_8
...
attack_tags_review_process_creation_8
2020-08-29 01:55:09 +02:00
grikos
3783b34832
Merge branch 'master' of https://github.com/grikos/sigma
2020-08-28 17:17:11 +03:00
grikos
293662810e
att&ck tags review: windows/process_creation part 8
2020-08-28 17:14:26 +03:00
vh
a2fec9f3b9
Fix sysmon backend
2020-08-28 12:26:40 +03:00
Alexey Lednyov
880b10cce1
att&ck tags review: windows/process_creation part 1, network
2020-08-27 20:43:47 +03:00
Florian Roth
7d3a6293f5
rule: Snatch ransomware
2020-08-26 09:42:34 +02:00
aw350m3
eb6b9be5a2
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-08-25 23:51:22 +00:00
Thomas Patzke
bae09e9447
Sigmatools release 0.18.1
2020-08-26 00:06:25 +02:00
grikos
ac0e42d0e2
Merge pull request #2 from aw350m33d/master
...
sync master
2020-08-25 23:07:48 +03:00
Thomas Patzke
b742e4ef08
Merge pull request #990 from neu5ron/es_backend
...
ES and Readme from SOC Prime
2020-08-25 21:34:55 +02:00
Nate Guagenti
f21b3c50c6
control whether to use an analyzed field or different type if a query/value contains a wildcard.
...
Signed-off-by: Nate Guagenti <neu5ron@users.noreply.github.com >
2020-08-25 13:13:18 -04:00
Nate Guagenti
a7ffb96b6b
elasticsearch regex escape of '.' for case insensitivity backend options
...
Signed-off-by: Nate Guagenti <neu5ron@users.noreply.github.com >
2020-08-25 13:10:25 -04:00
Nate Guagenti
474e04dfe3
add new options to readme for elasticbackend
...
Signed-off-by: Nate Guagenti <neu5ron@users.noreply.github.com >
2020-08-25 13:00:22 -04:00
Nate Guagenti
76910eaee4
fix sub field name usage if there are 3 or more fields..
...
Signed-off-by: Nate Guagenti <neu5ron@users.noreply.github.com >
2020-08-25 12:56:57 -04:00
Nate Guagenti
0d713e4544
control whether to use an analyzed field or different type if a query/value contains a wildcard.
...
Signed-off-by: Nate Guagenti <neu5ron@users.noreply.github.com >
2020-08-25 12:56:33 -04:00
Timur Zinniatullin
8dba6ceee6
2nd review
2020-08-25 09:31:38 +03:00
Timur Zinniatullin
1244cacfbf
Update lnx_auditd_create_account.yml
2020-08-25 09:20:27 +03:00
aw350m3
c28fce6273
fix duplication of key "modified" in mapping
2020-08-25 00:53:09 +00:00
aw350m3
c22273d162
fix duplication of key modified in mapping
2020-08-25 00:50:38 +00:00
aw350m3
5af0f1392d
att&ck tags review: windows/powershell, windows/process_access, windows/network_connection
2020-08-24 23:31:35 +00:00
aw350m3
399f378269
att&ck tags review: windows/powershell, windows/process_access, windows/network_connection
2020-08-24 23:31:26 +00:00
Yugoslavskiy Daniil
5026438524
fix modified field
2020-08-25 01:29:57 +02:00
aw350m3
1999fb609e
Merge branch 'master' of github.com:oscd-initiative/sigma
2020-08-24 23:14:13 +00:00
Yugoslavskiy Daniil
f274f39b54
Merge branch 'master' of https://github.com/oscd-initiative/sigma
2020-08-25 01:09:24 +02:00
Yugoslavskiy Daniil
42c4079ed8
att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other
2020-08-25 01:09:17 +02:00
Florian Roth
5a9ed1da15
Merge pull request #988 from defensivedepth/master
...
Zeek RDP rule
2020-08-24 12:39:49 +02:00
aw350m3
ba2e891433
windows/powershell folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-24 00:01:50 +00:00
aw350m3
08170bbcca
fix tags for suspicious outbound kerberos activity rule
2020-08-23 21:10:29 +00:00
Josh Brower
4c4b8db7cf
Zeek RDP rule
2020-08-23 13:16:42 -04:00
aw350m3
4cdd8be354
Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:20:58 +00:00
aw350m3
3aa1ad68fb
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
aw350m3
80deaf84ca
windows/network_connection folder reviewed
2020-08-22 23:36:30 +00:00
Florian Roth
f788a723b6
Merge pull request #986 from diskurse/devel
...
win_defender_history_delete.yml
2020-08-21 16:05:49 +02:00
Cian Heasley
28fe002f34
win_defender_history_delete.yml
...
Windows Defender logs when the history of detected infections is deleted. Log file will contain the message "Windows Defender Antivirus has removed history of malware and other potentially unwanted software".
2020-08-21 13:51:05 +01:00
Florian Roth
437a807a1d
Merge pull request #985 from architect00/master
...
added troubleshooting links to root README.md
2020-08-20 14:56:27 +02:00
David Straßegger
1e8a5b64d9
added troubleshooting links to root README.md
2020-08-20 14:02:26 +02:00
Florian Roth
79adaceffa
Merge pull request #979 from barvhaim/patch-3
...
Update win_susp_rasdial_activity.yml to use `contains` instead of `equal`
2020-08-18 15:08:15 +02:00
Florian Roth
bc74ac1f8a
Update win_susp_rasdial_activity.yml
2020-08-18 14:40:37 +02:00
Florian Roth
fd23a18241
Merge pull request #982 from tungn12/master
...
Carbon black mapping wrong and fix wild card
2020-08-18 14:33:22 +02:00
Florian Roth
0ba9383774
Merge pull request #984 from EccoTheFlintstone/fix_fp3
...
SIGMA ASEP: remove some false positives
2020-08-18 14:29:35 +02:00
ecco
de4810233c
remove false positives in Windows being too broad and add specific keys looked at + add keys from wow64
2020-08-18 05:28:37 -04:00
tung12
1921e9dd89
Fix wild card and some escaped characters
2020-08-18 15:57:13 +07:00
SOC Prime
d3ba1e4fb8
Add sysmon backend
2020-08-18 11:20:22 +03:00
SOC Prime
8fead9f864
Merge pull request #4 from Neo23x0/master
...
Repositories synchronization
2020-08-18 11:12:15 +03:00
Florian Roth
da54e89f30
Merge pull request #976 from diskurse/rule-devel
...
Rule devel
2020-08-17 15:02:31 +02:00
Florian Roth
8a02541b0a
style: removed lists where unnecessary
2020-08-17 15:02:16 +02:00
Florian Roth
6dc8dbb6d8
style: removed lists where unnecessary
2020-08-17 15:01:52 +02:00
tung12
172f7b371e
Change mapped Image to path
2020-08-17 15:05:44 +07:00
Bar Haim
bd96b1c5ad
Update win_susp_rasdial_activity.yml
...
`rasdial` is an `exe`, and probably appear as `rasdial.exe`
`LIKE` is more fit in this case
2020-08-16 16:17:49 +03:00
Bar Haim
c7dc9df87e
Update sysmon_apt_muddywater_dnstunnel.yml
2020-08-16 12:39:04 +03:00
Bar Haim
4168f1e430
Update win_new_service_creation.yml
2020-08-16 11:44:40 +03:00
Thomas Patzke
3d9855dd06
Merge pull request #975 from scottdermott/master
...
+ Adding Mitre Sub-Techniques and python update script to fetch latest from Mitre CTI
2020-08-13 13:18:57 +02:00
Cian Heasley
b378b3d62b
win_mouse_lock.yml
...
In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
2020-08-13 12:09:07 +01:00
Cian Heasley
6fa5a6c93d
Delete win_mouse_lock.yml
2020-08-13 12:08:04 +01:00
Cian Heasley
b8b4ab5a2a
win_mouse_lock.yml
...
In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
2020-08-13 12:07:34 +01:00
Cian Heasley
d1e9f01d23
win_dnscat2_powershell_implementation.yml
...
The PowerShell implementation of DNSCat2 calls nslookup to craft queries. Counting nslookup processes spawned by PowerShell will show hundreds or thousands of instances if PS DNSCat2 is active locally.
2020-08-13 12:06:48 +01:00
Dermott, Scott J
7e6828dd40
+ Adding Mitre Sub-Techniques and python update script to fetch latest Pre, Enterprise & Mobile Tactics and Techniques from Mitre CTI
2020-08-13 10:24:44 +01:00
Florian Roth
2e29c07e83
Merge pull request #928 from duzvik/master
...
Create sysmon_abusing_azure_browser_sso.yml
2020-08-12 17:15:27 +02:00
Florian Roth
61a05ee054
reordered fields, changed indentation
2020-08-12 16:44:37 +02:00
Thomas Patzke
01125ffd3b
Fixed: Elastalert backend handling of conditional field mappings
2020-08-11 23:29:18 +02:00
alan tseng
e9af2fb119
support nested conditions for Sigma
...
The parser finds the close token in pairs with left token.
So the parser will support nested parentheses in the conditions.
2020-08-07 14:58:32 +08:00
Thomas Patzke
d73447c111
Merge pull request #939 from ktecv2000/master
...
add wmi persistence script event consumer false positive
2020-08-05 23:28:26 +02:00
Thomas Patzke
f827a557f2
Merge pull request #936 from rtkmokuka/typo_wmiprvse_spawning_process
...
Change fitler typo from 'Username' to 'User' for Wmiprvse Spawning Process rule
2020-08-05 23:26:14 +02:00
Thomas Patzke
9b2f8ce1f9
Merge pull request #953 from barvhaim/master
...
STIX Backend added and updated fields mapping
2020-08-05 23:25:17 +02:00
Florian Roth
98ca8b4ce9
Merge pull request #968 from zinint/master
...
ATT&CK mapping update suggestions for \linux\
2020-08-05 00:37:36 +02:00
Timur Zinniatullin
72fdf0da45
Update lnx_auditd_susp_cmds.yml
2020-08-04 20:00:30 +03:00
Timur Zinniatullin
4e688233d7
ATT&CK mapping update suggestions for \linux\
2020-08-04 19:48:18 +03:00
Florian Roth
4529e4cd52
Merge pull request #966 from Neo23x0/rule-devel
...
rule: TAIDOOR malware load
2020-08-04 14:54:24 +02:00
Florian Roth
052379a512
fix: tightened TAIDOOR rule
2020-08-04 14:37:18 +02:00
Florian Roth
c4953409aa
rule: TAIDOOR malware load
...
https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a
2020-08-04 14:31:29 +02:00
Florian Roth
fa36adfe6d
Merge pull request #965 from IPv777/patch-2
...
.002 = SMB/Windows Admin Shares
2020-08-03 18:05:12 +02:00
IPv777
a52583dc68
.002 = SMB/Windows Admin Shares
2020-08-03 17:43:14 +02:00
Florian Roth
732c1fa356
Merge pull request #964 from Neo23x0/rule-devel
...
New rules
2020-08-03 15:28:45 +02:00
Florian Roth
5625f471d7
Merge pull request #963 from diskurse/rule-devel
...
win_webshell_regeorg.yml
2020-08-03 13:51:16 +02:00
Florian Roth
3abc3d0a76
docs: add FP condition
2020-08-03 13:50:47 +02:00
Florian Roth
6f7aecbe06
fix: preventive change to avoid FPs
2020-08-03 13:49:52 +02:00
Cian Heasley
de33b953ba
Add files via upload
...
Webshell ReGeorg Detection Via Web Logs
2020-08-03 12:20:04 +01:00
Florian Roth
df3bfb1b37
rule: Winnti Pipemon
2020-07-30 18:55:47 +02:00
bar
8352eefe22
STIX Support keywords (value without field)
2020-07-28 18:52:02 +03:00
bar
53f36d2ab6
Merge remote-tracking branch 'upstream/master'
2020-07-28 16:24:51 +03:00
Florian Roth
5abf101c0b
Merge pull request #954 from Neo23x0/rule-devel
...
Rule devel
2020-07-28 10:22:52 +02:00
Florian Roth
8970d03f6f
Merge pull request #952 from Neo23x0/devel
...
feat: Detect duplicate rule tags
2020-07-28 10:21:59 +02:00
bar
565f77c199
Added STIX target to README.md
2020-07-27 15:35:30 +03:00
bar
de475bb500
updated STIX mapping for more rule fields
2020-07-27 14:36:30 +03:00
Florian Roth
80f4b4ec71
fix: rules with duplicate tags
2020-07-27 11:44:47 +02:00
Florian Roth
051e2ce905
feat: detect duplicate tags
2020-07-27 11:37:58 +02:00
Thomas Patzke
481b695eff
Merge pull request #950 from barvhaim/master
...
STIX Backend bug-fix and mapping updates
2020-07-26 18:33:35 +02:00
bar
32cf352236
Merge remote-tracking branch 'upstream/master'
2020-07-26 14:56:06 +03:00
bar
9643e01b54
extension should use '..'
2020-07-26 12:16:48 +03:00
Thomas Patzke
dcb07bab2f
Merge pull request #949 from 0xballistics/powershell_backend_fix
...
partial(?) fix of #762
2020-07-25 10:18:05 +02:00
Florian Roth
a0ac6c46c7
Merge pull request #948 from IPv777/patch-1
...
remove duplicate tag
2020-07-24 20:32:40 +02:00
Simran Kaur Soin
b8b1f83ae6
Merge pull request #3 from simrankaursoin/master
...
Fix bug with NOT handling
2020-07-24 11:55:17 -04:00
IPv777
77a8ac59ef
remove duplicate
2020-07-24 16:38:08 +02:00
Florian Roth
a55630f02c
Merge pull request #947 from ryanplasma/master
...
Minor fixes to two rules
2020-07-24 09:25:55 +02:00
Ryan Plas
aa548ba1a9
Add quotes due to a colon in the falsepositives string
2020-07-23 23:33:36 -04:00
Ryan Plas
e52489aaf6
Change production status to stable
2020-07-23 23:33:36 -04:00
Simran Soin
c329f6412d
Fix bug with NOT handling
2020-07-23 11:47:55 -04:00
Simran Kaur Soin
7e32557ffc
Merge pull request #2 from simrankaursoin/master
...
Update base.py and qradar.py
2020-07-23 11:12:17 -04:00
Florian Roth
8a4b53eb3a
fix: rule leads to FPs on systems that don't log the cmdline parameters
2020-07-23 17:04:16 +02:00
Simran Soin
6c7b4cf408
Revert additional change in base.py
2020-07-23 10:47:22 -04:00
Simran Soin
ef9af3730a
Remove unnecessary edits from qradar.py
2020-07-23 10:34:29 -04:00
Simran Soin
0e49a6acdf
Default NOT to false for all functions
2020-07-23 10:18:16 -04:00
Simran Soin
0fac21f4a3
Remove modifications from base file and override in stix.py
2020-07-23 10:13:30 -04:00
Simran Kaur Soin
a03d1b091e
Merge pull request #1 from simrankaursoin/master
...
Fix NOT bug
2020-07-23 09:50:18 -04:00
Simran Soin
30ff22776a
Fix NOT bug
2020-07-23 09:41:33 -04:00
Florian Roth
951c6fee8b
Update sysmon_password_dumper_lsass.yml
2020-07-23 14:31:21 +02:00
bar
5019f2f160
added mapping for stix web, cloud, linux
2020-07-22 21:41:46 +03:00
Florian Roth
02a6b20f5f
Merge pull request #944 from rtkdmasse/update-rule-selections
...
Add 'contains' for the ps encoded chars rule
2020-07-22 17:48:18 +02:00
Daniel Masse
13cf0488ae
Add 'contains' for the ps encoded chars rule
2020-07-22 10:49:22 -04:00
Florian Roth
db98fe79b0
Revert "rule: update - MATA framework UserAgent"
...
This reverts commit 81ef0137c5 .
2020-07-22 14:02:51 +02:00
Florian Roth
81ef0137c5
rule: update - MATA framework UserAgent
2020-07-22 14:02:13 +02:00
Florian Roth
9682d37ead
Merge pull request #941 from architect00/master
...
fixed wrong function call for elastalert aggregation. fixes #940
2020-07-22 13:13:18 +02:00
Florian Roth
769a9212a5
Merge pull request #943 from diskurse/rule-devel
...
Webshell Recon Detection Via CommandLine & ProcessesAdd files via upload
2020-07-22 13:02:44 +02:00
Cian Heasley
023bf76363
Add files via upload
...
Looking for processes spawned by web server components that indicate reconnaissance by popular public domain webshells for whether perl, python or wget are installed.
2020-07-22 09:05:50 +01:00
bar
0543ec1ae3
mapping update, removed unused fields
2020-07-21 19:49:26 +03:00
bar
83623f396c
Merge remote-tracking branch 'upstream/master'
2020-07-21 17:22:06 +03:00
bar
da30266c60
ImageLoaded mapping added
2020-07-21 17:21:14 +03:00
David Straßegger
875360f373
fixed wrong function call for elastalert aggregation. fixes #940
2020-07-20 14:32:30 +02:00
Poming huang
2b2bf34a64
add wmi persistence script event consumer false positive
2020-07-20 12:27:16 +08:00
Florian Roth
71aa8ad3ba
Merge pull request #937 from brachera/master
...
Updates to rules and tags
2020-07-18 08:19:48 +02:00
Aidan Bracher
ff3f9fe9b3
Updated tags
2020-07-18 03:02:43 +01:00
Aidan Bracher
1fd73a23b2
Updated tags with sub-techniques
2020-07-18 03:01:34 +01:00
Aidan Bracher
4ac1058ab5
Updated tags
2020-07-18 03:01:11 +01:00
Aidan Bracher
4ffe9cb042
Updated tags with sub-techniques
2020-07-18 02:53:46 +01:00
Aidan Bracher
3bd768e49b
Updated tags with sub-techniques
2020-07-18 02:52:15 +01:00
Aidan Bracher
dcf20e580d
Updated tags to include sub-techniques
2020-07-18 02:50:57 +01:00
Aidan Bracher
1442812681
Updated tags
2020-07-18 02:44:53 +01:00
Aidan Bracher
b61527d0b2
Added ATT&CK tactic
2020-07-18 02:42:10 +01:00
Aidan Bracher
161829a4c0
Added ATT&CK tactic
2020-07-18 02:41:48 +01:00
Aidan Bracher
147fd46157
Added ATT&CK tactic
2020-07-18 02:41:10 +01:00
Aidan Bracher
2d227a08c5
Updated suspicious service with sub-techniques
2020-07-18 02:40:22 +01:00
Aidan Bracher
97452a9df3
Update to include sub-technique mapping
2020-07-18 02:38:47 +01:00
Aidan Bracher
30bd591c96
Update win_apt_ke3chang to include sub-techniques
2020-07-18 02:37:56 +01:00
Aidan Bracher
ad9a8ff956
Updated to include extra registry key
2020-07-18 02:37:11 +01:00
Aidan Bracher
ea1b2ae59f
Updated invoke_phantom with sub-technique mapping
2020-07-18 02:32:42 +01:00
Aidan Bracher
23dd2e3cac
Updated to include sub-technique mapping
2020-07-18 02:29:58 +01:00
Aidan Bracher
2006aa8f5e
Inclusion of registry keys for WinDefender disabling
2020-07-18 02:23:30 +01:00
Marko Okuka
1d39b40fd1
Fixing typo in rule: Username to User
2020-07-16 10:09:29 -04:00
Florian Roth
ae05e8eb11
Merge pull request #935 from SanWieb/933-EventID-process_creation
...
Revert "Ref #933 - Added windows Process Creation to config"
2020-07-16 14:32:19 +02:00
Sander
94272c7770
Revert "Ref #933 - Added windows Process Creation to config"
...
This reverts commit 6c35a7afa0 .
2020-07-16 14:30:17 +02:00
Florian Roth
80e6e933a9
Merge pull request #934 from SanWieb/933-EventID-process_creation
...
Proposed fix for #933
2020-07-16 13:38:12 +02:00
Sander
6c35a7afa0
Ref #933 - Added windows Process Creation to config
2020-07-16 13:16:57 +02:00
Florian Roth
3025d6850c
Merge pull request #932 from rtkdmasse/rule-selection-typos
...
Change the selection from Command to CommandLine in a couple of rules
2020-07-16 09:10:15 +02:00
Florian Roth
992bf676f9
Update sysmon_apt_pandemic.yml
2020-07-16 08:48:32 +02:00
Florian Roth
b1de627e94
Update win_apt_zxshell.yml
2020-07-16 08:47:24 +02:00
Florian Roth
4b9b57330a
Merge pull request #931 from brachera/master
...
Fix for indentation issue
2020-07-16 08:46:42 +02:00
Daniel Masse
0489a50bd0
Change the selection from Command to CommandLine in a couple of rules
2020-07-15 15:55:26 -04:00
Florian Roth
f8e10273ef
Merge pull request #929 from Neo23x0/pr/919
...
Pr/919
2020-07-15 21:30:57 +02:00
Florian Roth
b50d234cb5
Merge pull request #913 from ryanplasma/master
...
Update logsources description->definition
2020-07-15 21:30:33 +02:00
Sander Wiebing
254942e4c3
Merge pull request #4 from Neo23x0/master
...
Update repository
2020-07-15 17:58:01 +02:00
Aidan Bracher
e0476d5ce6
Merge branch 'master' of git://github.com/Neo23x0/sigma
2020-07-15 16:35:29 +01:00
Aidan Bracher
1e5ee5823c
Fix for indentation issue
...
Wrong indentation of line 182 meant that even where config options
were given, the default per backend was being used, rendering
custom config useless.
2020-07-15 16:29:27 +01:00
Florian Roth
d0c09f10a9
changed newline character to LF
2020-07-15 16:46:44 +02:00
Ryan Plas
de53a08746
Merge branch 'master' of github.com:Neo23x0/sigma
2020-07-15 10:27:33 -04:00
duzvik
a9b860d749
Update sysmon_abusing_azure_browser_sso.yml
2020-07-15 14:24:49 +03:00
duzvik
d24e15cc27
Update sysmon_abusing_azure_browser_sso.yml
2020-07-15 14:12:58 +03:00
duzvik
c5dfffdac0
Create sysmon_abusing_azure_browser_sso.yml
2020-07-15 14:02:34 +03:00
Florian Roth
8f66803ddf
Merge pull request #927 from Neo23x0/rule-devel
...
improved CVE-2020-1350 rule
2020-07-15 12:06:31 +02:00
Florian Roth
1c103a749f
fix: more FPs based on feedback
...
https://twitter.com/GossiTheDog/status/1283341486680166400
2020-07-15 12:05:50 +02:00
Florian Roth
c2eb110fca
fix: more exact patterns
2020-07-15 11:56:11 +02:00
Florian Roth
ae7fbb9245
fix: false positive filters based on SOC Prime's rule
2020-07-15 11:49:20 +02:00
Florian Roth
e5a34a965c
Merge pull request #926 from Neo23x0/rule-devel
...
rule: CVE-2020-1350
2020-07-15 11:19:07 +02:00
Florian Roth
80639afd43
rule: CVE-2020-1350
2020-07-15 11:03:31 +02:00
Bhabesh Rai
e0c1d84951
Added new Lateral Movement Attack ID
2020-07-14 22:32:29 +05:45
Florian Roth
c7e412788a
Merge pull request #924 from Neo23x0/devel
...
Live MITRE ATT&CK data from TAXI service in Test Scripts
2020-07-14 18:15:29 +02:00
Florian Roth
38c29977ff
Merge pull request #925 from Neo23x0/rule-devel
...
fix: issue reported as https://github.com/Neo23x0/sigma/issues/923
2020-07-14 18:14:51 +02:00
Florian Roth
1928b3dc06
Merge pull request #920 from qwerty1q2w/feature
...
Added AppLocker log source and new rule
2020-07-14 18:03:17 +02:00
Florian Roth
741d42ce88
fix: issue reported as https://github.com/Neo23x0/sigma/issues/923
2020-07-14 17:59:59 +02:00
Florian Roth
71e66ea9ba
refactor: tests use live data from MITRE's TAXI service
2020-07-14 17:54:02 +02:00
Florian Roth
58b68758b4
fix: wrong MITRE ATT&CK ids used in the beta version
2020-07-14 17:53:32 +02:00
Florian Roth
43fb39a0b4
Merge pull request #922 from Neo23x0/devel
...
refactor: ignore sub techniques as long as we do not have a complete …
2020-07-14 12:50:35 +02:00
Florian Roth
cf25b9c509
feat: filename test
2020-07-14 12:33:16 +02:00
Florian Roth
495376df77
refactor: references test without warnings for missing refs
2020-07-14 12:33:02 +02:00
Florian Roth
bae979f5c7
refactor: ignore sub techniques as long as we do not have a complete list
2020-07-14 11:56:28 +02:00
Bhabesh Rai
6fb045aa4b
Conforming to Rule Creation Guide.
2020-07-14 14:20:07 +05:45
Bhabesh Rai
66ad325fde
Added support for Defender's PSExec and WMI ASR rules.
2020-07-14 14:01:43 +05:45
Florian Roth
44381610ea
Merge pull request #918 from Neo23x0/devel
...
References Test
2020-07-14 09:28:44 +02:00
Florian Roth
781667ef22
fix: zeek rule references isn't a list
2020-07-14 00:33:47 +02:00
Ryan Plas
9eb5d8da4d
Add logsource attribute rule test
2020-07-13 17:02:28 -04:00
Ryan Plas
04fd598bcf
Update additional rules to have correct logsource attributes
2020-07-13 17:02:17 -04:00
Pushkarev Dmitry
efe720d44e
Added new rule. AppLocker
2020-07-13 20:51:48 +00:00
Pushkarev Dmitry
6c999df3b7
Added AppLocker log source
2020-07-13 20:48:06 +00:00
Pushkarev Dmitry
8e3f973e69
Added AppLocker log source
2020-07-13 20:46:49 +00:00
Pushkarev Dmitry
bdfb646228
Added AppLocker log source
2020-07-13 20:45:30 +00:00
Pushkarev Dmitry
364af53902
Added AppLocker log source
2020-07-13 20:44:03 +00:00
Pushkarev Dmitry
326cf05a74
Added AppLocker log source
2020-07-13 20:41:54 +00:00
Pushkarev Dmitry
46a6183745
Added AppLocker log source
2020-07-13 20:32:03 +00:00
Pushkarev Dmitry
a58e037509
Added AppLocker log source
2020-07-13 20:30:02 +00:00
Pushkarev Dmitry
7fb2e2b845
Added AppLocker log source
2020-07-13 20:29:13 +00:00
Pushkarev Dmitry
e376948258
Added AppLocker log source
2020-07-13 20:27:52 +00:00
Pushkarev Dmitry
0d925896b9
Added AppLocker log source
2020-07-13 20:23:42 +00:00
Pushkarev Dmitry
c30a256030
Added AppLocker log source
2020-07-13 20:21:46 +00:00
Pushkarev Dmitry
1da229e3a9
Added AppLocker log source
2020-07-13 20:20:28 +00:00
Pushkarev Dmitry
3a19e3cf23
Added AppLocker log source
2020-07-13 20:18:01 +00:00
Bart
308420bf7f
Update sysmon_dllhost_net_connections.yml
...
Fix @
2020-07-13 21:20:55 +02:00
Bart
007f62ba01
Add Dllhost WAN access
2020-07-13 21:12:37 +02:00
Florian Roth
b3e15eea68
fix: nested check
2020-07-13 18:49:00 +02:00
Florian Roth
91c0bea570
fix: typo and reordered
2020-07-13 18:22:47 +02:00
Florian Roth
758f5039b5
fix: no error on rules without references
2020-07-13 18:16:32 +02:00
Florian Roth
8d91659c2a
fix: typo in field value
2020-07-13 18:08:00 +02:00
Florian Roth
4c610ec693
feat: test references is list
2020-07-13 18:07:19 +02:00
Florian Roth
f12cb7309b
fix: references is not a list
2020-07-13 17:37:03 +02:00
Florian Roth
437a567e4f
Merge pull request #917 from Neo23x0/rule-devel
...
New Empire Rules and Updates
2020-07-13 16:37:59 +02:00
Florian Roth
1c63a93643
fix: wrong casing in tag
2020-07-13 16:20:51 +02:00
Florian Roth
87ce5e5745
fix: missing MITRE ATT&CK IDs in test
2020-07-13 16:02:22 +02:00
Florian Roth
1b75a3a96b
Merge pull request #916 from viniciusvec/patch-2
...
Update lnx_shell_clear_cmd_history.yml
2020-07-13 15:54:11 +02:00
Florian Roth
557e8b0faf
rule: improved Empire detection
2020-07-13 15:47:53 +02:00
viniciusvec
26f0d49772
Update lnx_shell_clear_cmd_history.yml
...
Renamed tags to match production MITRE: https://attack.mitre.org/techniques/T1070/003/
2020-07-13 14:06:14 +01:00
Florian Roth
7e8aa7b12b
Merge pull request #915 from Neo23x0/rule-devel
...
rule: regsvr32 flags anomaly
2020-07-13 12:16:05 +02:00
Florian Roth
7a63fd56da
rule: regsvr32 flags anomaly
2020-07-13 11:59:44 +02:00
Ömer Günal
bee467dbd6
Rename lnx_setgid_setuid to lnx_setgid_setuid.yml
2020-07-13 01:36:20 +03:00
Ömer Günal
bf8f0307b7
Rename lnx_space_after_filename_ to lnx_space_after_filename_.yml
2020-07-13 01:33:59 +03:00
Ömer Günal
4b74a0df76
Create lnx_space_after_filename_
2020-07-13 01:33:39 +03:00
Ömer Günal
c749aa2539
Create lnx_setgid_setuid
2020-07-13 01:33:09 +03:00
Ömer Günal
6b24a5df65
Create lnx_security_tools_disabling.yml
2020-07-13 01:32:24 +03:00
Ömer Günal
bdeca13825
Create lnx_proxy_connection.yml
2020-07-13 01:31:05 +03:00
Ömer Günal
708a28e307
Delete lnx_space_after_filename.yml
2020-07-13 01:26:37 +03:00
Ömer Günal
af6ad5a41b
Delete lnx_setuid_setgid.yml
2020-07-13 01:26:29 +03:00
Ömer Günal
64a9b6e098
Delete lnx_disabling_security_tools.yml
2020-07-13 01:26:11 +03:00
Ömer Günal
7466c8d425
Delete lnx_connection_proxy.yml
2020-07-13 01:26:03 +03:00
Ömer Günal
7ce16d1bbc
Update lnx_space_after_filename.yml
2020-07-13 01:07:32 +03:00
Ryan Plas
25d978d9bd
Update powershell_shellcode_b64.yml logsource to use the correct Sigma schema values
2020-07-11 22:17:06 -04:00
Ryan Plas
3bb45f00af
Update web_citrix_cve_2019_19781_exploit.yml logsource to use the correct Sigma schema values
2020-07-11 00:00:21 -04:00
Florian Roth
1a87492bd4
Merge pull request #912 from Neo23x0/rule-devel
...
rule: improved Citrix rule
2020-07-10 19:46:09 +02:00
Florian Roth
129925ce0b
rule: improved Citrix rule
2020-07-10 18:15:35 +02:00
Florian Roth
17dedddbdd
Merge pull request #911 from Neo23x0/rule-devel
...
rule: Citrix Netscaler Attack CVE-2020-8193 CVE-2020-8195
2020-07-10 18:09:19 +02:00
Florian Roth
383953c74e
rule: better rule name and descriptions, plus MITRE ATT&CK tags
2020-07-10 17:55:13 +02:00
Florian Roth
0d89208242
rule: updated Citrix rule
2020-07-10 17:49:18 +02:00
Florian Roth
eda08e3a89
rule: Citrix Netscaler Attack CVE-2020-8193 CVE-2020-8195
2020-07-10 17:45:11 +02:00
Florian Roth
3ab5eb97d8
Merge pull request #901 from brachera/master
...
rule: Leviathan registry key
2020-07-10 16:42:02 +02:00
Florian Roth
49aa0b4621
Merge pull request #909 from EccoTheFlintstone/fp2
...
add WMI module load false positive
2020-07-10 15:45:53 +02:00
Florian Roth
5de82628fa
Update sysmon_apt_leviathan.yml
2020-07-10 15:41:55 +02:00
Florian Roth
168952840b
Merge pull request #910 from Neo23x0/rule-devel
...
Rule devel
2020-07-10 14:17:22 +02:00
Florian Roth
268a28daed
rule: Evilnum Golden Chicken rule OCX
2020-07-10 13:02:52 +02:00
ecco
e30eaa0202
be more specific about file location
2020-07-09 13:33:59 -04:00
ecco
94e3bd9e6b
add WMI module load false positive
2020-07-09 13:32:21 -04:00
Florian Roth
6ad2f07193
Merge pull request #907 from EccoTheFlintstone/fix_fp
...
add WMI and powershell false positives
2020-07-09 17:42:53 +02:00
ecco
905f1b3823
add WMI and powershell false positives
2020-07-09 10:26:54 -04:00
Florian Roth
7949729fa4
rule: PowerShell encoded character syntax
2020-07-09 08:52:32 +02:00
Florian Roth
5200f1f85d
Merge pull request #905 from barvhaim/stix-mapping
...
Incorrect mapping fixes [stix backend]
2020-07-08 19:22:23 +02:00
bar
ca7cf8478d
- IntegrityLevel mapping to integritylevel
2020-07-08 19:37:24 +03:00
Florian Roth
14210aba16
Merge pull request #906 from GelosSnake/patch-1
...
adding google chrome to FP list
2020-07-08 16:57:29 +02:00
bar
8855a87dbf
- TargetProcessAddress mapping should be as startaddress mapping
...
- remove extra '-'
2020-07-08 17:35:57 +03:00
Florian Roth
e3734aaa27
fix: missing upper tick
2020-07-08 15:53:04 +02:00
GelosSnake
efae210556
adding google chrome to FP list
...
legitimate errors generated by Google Chrome are reported often.
Official google standpoint on this:
https://support.google.com/chrome/a/thread/15440066?hl=en
2020-07-08 16:44:41 +03:00
bar
8889ae21ca
DestinationPort to network-traffic:dst_port mapping fix
2020-07-08 14:31:04 +03:00
bar
50ef79b398
Custom STIX object "x-sigma" for fields that missing mapping, so the pattern is STIX valid
2020-07-08 14:09:26 +03:00
Thomas Patzke
8cec884d96
Merge branch 'pr-709'
2020-07-08 08:00:03 +02:00
Thomas Patzke
bd9410fe06
Added CI test
2020-07-07 23:46:49 +02:00
Thomas Patzke
205b584e80
Merge branch 'pr-829'
2020-07-07 23:42:57 +02:00
Thomas Patzke
3e17cc1900
Merge pull request #894 from caliskanfurkan/master
...
ditsnap, a credential access tool used in ransomware attacks
2020-07-07 23:21:36 +02:00
Thomas Patzke
28013a15e1
Improved rule
2020-07-07 23:18:07 +02:00
Thomas Patzke
90f09f7b12
Merge branch 'devel' of https://github.com/diskurse/sigma into pr-829
2020-07-07 23:15:39 +02:00
Thomas Patzke
3c760fabc1
Merge pull request #745 from Rettila/master
...
Added new rules
2020-07-07 23:14:19 +02:00
Thomas Patzke
9bcff522b6
Merge branch 'master' of https://github.com/rashimo/sigma into pr-709
2020-07-07 23:12:03 +02:00
Thomas Patzke
7eb499ad85
Added rule id
2020-07-07 22:54:55 +02:00
Thomas Patzke
360b5714a8
Splitted and improved new rule
2020-07-07 22:47:14 +02:00
Thomas Patzke
0ce5f2cc75
Merge branch 'patch-2' of https://github.com/4A616D6573/sigma into pr-483
2020-07-07 22:37:11 +02:00
Thomas Patzke
4762a59b89
Merge pull request #891 from rtkbkish/image-load-fixes
...
Fix typo for rule in image_load category
2020-07-07 22:31:32 +02:00
Thomas Patzke
2032a1e7fd
Merge pull request #898 from rtkbkish/fix-uac-registry
...
Proposed fix for sysmon_uac_bypass_eventvwr
2020-07-07 22:29:39 +02:00
Thomas Patzke
9e85731253
Merge pull request #899 from rtkbkish/refix-rules
...
Re-fix sysmon rules that lost changes with category refactoring.
2020-07-07 22:28:37 +02:00
Thomas Patzke
a11bc000fd
Merge pull request #900 from barvhaim/stix
...
STIX backend added including mapping configurations for windows logs and QRadar
2020-07-07 22:26:51 +02:00
Florian Roth
b0e59bdb40
Merge pull request #903 from Neo23x0/rule-devel
...
rule: extended F5 BIG-IP exploitation detection rule
2020-07-07 22:06:00 +02:00
Florian Roth
acfe20aa34
rule: extended F5 BIG-IP exploitation detection rule
2020-07-07 21:45:08 +02:00
bar
35bb8df0b5
updated makefile with stix coverage cmd
2020-07-07 16:39:59 +03:00
Aidan Bracher
90983dcc4b
add level field to rule
2020-07-07 14:28:18 +01:00
Aidan Bracher
f549a14d9a
rule: Leviathan registry key
2020-07-07 13:27:57 +01:00
bar
acbab2db4b
stix backend + mapping configurations for windows logs and qradar
2020-07-07 15:04:16 +03:00
Florian Roth
99ac4f1f3d
fix: FPs with RedMimicry rule
2020-07-07 10:11:58 +02:00
Florian Roth
c8ca55b3e4
fix: duplicate wrong old key
2020-07-06 17:14:59 +02:00
Florian Roth
cc31ed8b84
fix: missing NTLM log source in THOR
2020-07-06 17:07:06 +02:00
Brad Kish
c758ca0eb9
Re-fix sysmon rules that are lost changes with category refactoring.
...
Several fixes for sysmon rules got lost when the rules were refactored to use
categories.
Re-add the fixes.
https://github.com/Neo23x0/sigma/commit/38afd8b5def24191616ff0f0c0324cfbb7f0d6d0
https://github.com/Neo23x0/sigma/commit/422b2bffd77b217e6cec9a67c496b0aa44711ece
https://github.com/Neo23x0/sigma/commit/dfae2a6df6f5bbc90a7b476c22fc9c8fedab47e9
2020-07-06 10:55:42 -04:00
Brad Kish
7e06fd80fd
Proposed fix for sysmon_uac_bypass_eventvwr
...
Issue: https://github.com/Neo23x0/sigma/issues/888
The rules were not merged correctly with the transition to sysmon categories.
Split the rule into separate documents: one for the registry_event and one for
the process_creation
2020-07-06 09:20:34 -04:00
Thomas Patzke
939156fa6d
Introduced dns_query log source category
2020-07-05 23:29:51 +02:00
Thomas Patzke
0df21289a0
Merge branch 'dns-fixes' of https://github.com/rtkbkish/sigma into pr-893
2020-07-05 23:24:56 +02:00
Thomas Patzke
57cb255208
Merge pull request #864 from cclauss/patch-3
...
Fix undefined names in sigma2misp.py
2020-07-05 23:16:22 +02:00
Florian Roth
4aae3a6aa5
Merge pull request #897 from Neo23x0/rule-devel
...
improved F5 BIG-IP rule based on private feedback
2020-07-05 16:38:20 +02:00
Florian Roth
13ab00f744
improved F5 BIG-IP rule based on private feedback
2020-07-05 16:21:48 +02:00
Florian Roth
ab9a988682
Merge pull request #896 from Neo23x0/rule-devel
...
rule: CVE-2020-5902 F5 BIG-IP Exploitation Attempt
2020-07-05 13:44:36 +02:00
Florian Roth
fbe6c0e7d9
improved F5 BIG-IP rule
2020-07-05 13:29:30 +02:00
Florian Roth
f079d0f915
rule: CVE-2020-5902 F5 BIG-IP Exploitation Attempt
...
https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/
2020-07-05 13:18:53 +02:00
Florian Roth
c51b4d0524
Merge pull request #890 from rtkbkish/file-event-fixes
...
Fixes for rules in the sysmon file_event category
2020-07-05 13:13:24 +02:00
Florian Roth
4a810dd136
Merge pull request #886 from Neo23x0/rule-devel
...
Windows Curl Rules
2020-07-05 13:12:41 +02:00
Florian Roth
facd578324
Merge pull request #892 from rtkbkish/registry-event-fixes
...
Fixes for rules in new sysmon registry_event category
2020-07-05 13:12:04 +02:00
Furkan CALISKAN
8ef82e48eb
ditsnap
2020-07-04 23:21:52 +03:00
Brad Kish
8b3b312c4e
Proposed fix for https://github.com/Neo23x0/sigma/issues/889
...
This change removes dns events from the network connection category. The
one change is that sysmon_regsvr32_network_activity.yml needs to test
the network connection category separately from the DNS event id.
2020-07-03 16:28:19 -04:00
Brad Kish
7031d9e2b8
Fix typo for rule in image_load category
...
image_load not image_loaded.
2020-07-03 16:23:17 -04:00
Brad Kish
1e9d0e9653
Fixes for rules in the sysmon file_event category
...
Fix a couple of typos
For sysmon_hack_dumpert:
Make sure the logsource is category file_event and not sysmon. Don't set
the category at the global level. Instead set in the individual document.
2020-07-03 16:22:29 -04:00
Brad Kish
4b31633355
Fixes for rules in new sysmon registry_event category
...
To be consistent with the behaviour of the other rules, the eventID should not
be specified as part of the rule. The category defines the eventID.
2020-07-03 16:20:37 -04:00
Florian Roth
11517edbd7
rule: suspicious curl usage
2020-07-03 18:55:44 +02:00
Florian Roth
c4267a4614
rule: suspicious curl file upload
2020-07-03 18:20:44 +02:00
Florian Roth
80f15a1e50
Merge pull request #885 from Neo23x0/rule-devel
...
fix: trailing whitespace
2020-07-03 18:00:19 +02:00
Florian Roth
4d9e2e8c16
fix: trailing white space
2020-07-03 17:59:50 +02:00
Ömer Günal
47a2f1bc94
Update lnx_space_after_filename.yml
2020-07-03 18:56:51 +03:00
Ömer Günal
51363d8a87
Update lnx_setuid_setgid.yml
2020-07-03 18:56:40 +03:00
Ömer Günal
87346d4b94
Update lnx_disabling_security_tools.yml
2020-07-03 18:56:30 +03:00
Ömer Günal
64afd6e7ee
Update lnx_connection_proxy.yml
2020-07-03 18:56:19 +03:00
Florian Roth
26d8810efb
Merge pull request #882 from Neo23x0/rule-devel
...
Rule devel
2020-07-03 15:33:55 +02:00
Florian Roth
8a0262d1a2
fix: in linux keyword expression
2020-07-03 15:08:20 +02:00
Florian Roth
4dc818aafd
fix: rar flags rule caused too many FPs
2020-07-03 13:20:24 +02:00
Florian Roth
5dd5b87f43
rule: guacamole exploitation detection
2020-07-03 13:20:03 +02:00
Florian Roth
abf5f799d6
docs: more references
2020-07-03 13:19:44 +02:00
Florian Roth
fa452bf3e5
Merge pull request #849 from omergunal/ogunal-1
...
Rules for detecting suspicious remote file copy
2020-07-03 11:59:45 +02:00
Florian Roth
b9966a173c
Update lnx_file_copy.yml
2020-07-03 11:32:49 +02:00
Florian Roth
6420820eb2
Merge pull request #871 from Christopolos94/master
...
Update to mdatp backend
2020-07-03 11:29:01 +02:00
Florian Roth
5f04fcccf5
fix: broken links
2020-07-03 11:22:06 +02:00
Florian Roth
3111ab8396
refactor: new way to write that rule
2020-07-03 11:20:36 +02:00
Florian Roth
d12b8347dc
fix: bug in cmstp rule
...
https://github.com/Neo23x0/sigma/issues/876
2020-07-03 11:19:11 +02:00
Florian Roth
0bbf40fb14
refactor: include xcopy
2020-07-03 11:03:45 +02:00
Florian Roth
3bea08edfc
refactor: copy from/to system32 rule
2020-07-03 10:56:26 +02:00
Florian Roth
02dee36f4c
Merge pull request #880 from Neo23x0/rule-devel
...
fix: typo in systemroot
2020-07-03 10:25:31 +02:00
Florian Roth
34ea706e4f
fix: typo in systemroot
2020-07-03 10:24:58 +02:00
Florian Roth
53620a0d2f
Merge pull request #879 from Neo23x0/rule-devel
...
fix: missing copy command
2020-07-03 10:18:21 +02:00
Florian Roth
0fa1c1525b
fix: missing copy command
2020-07-03 10:17:34 +02:00
Florian Roth
248506be93
Merge pull request #878 from Neo23x0/rule-devel
...
DesktopImgDownLdr Rules and extra rule
2020-07-03 10:14:58 +02:00
Florian Roth
1f0b1e58a9
fix: bugs in rule and title
2020-07-03 09:54:10 +02:00
Florian Roth
01ed87186f
Copy From System Root rule
2020-07-03 09:45:58 +02:00
Florian Roth
33fef8bcf5
DesktopImgDownLdr rules
2020-07-03 09:45:48 +02:00
Thomas Patzke
43e5ae5d24
Added Windows NTLM log source + fixes
2020-07-02 23:20:36 +02:00
Thomas Patzke
de0bb36c51
Merge branch 'master' of https://github.com/4A616D6573/sigma into pr-785
2020-07-02 23:04:59 +02:00
Florian Roth
bb86d9c125
Merge pull request #875 from Neo23x0/rule-devel
...
fix: duplicate IDs and rule titles
2020-07-01 16:58:06 +02:00
Florian Roth
4c4ed1a4a2
fix: duplicate IDs and rule titles
2020-07-01 16:37:27 +02:00
Florian Roth
61c3b2e0d6
Merge pull request #873 from Neo23x0/rule-devel
...
fix: remove duplicate rules in sysmon (generic rule cleanup)
2020-07-01 11:29:04 +02:00
Florian Roth
9c0f9f398f
refactor: sysmon rule cleanup > generlization
2020-07-01 10:58:39 +02:00
Florian Roth
4231fe2efc
fix: remove duplicate rules in sysmon (generic rule cleanup)
2020-07-01 10:23:30 +02:00
Florian Roth
bc71ee5614
Merge pull request #872 from Neo23x0/rule-devel
...
Rule devel
2020-07-01 10:16:57 +02:00
Florian Roth
ab40cdbbd7
fix: missing ATT&CK id
2020-07-01 09:57:35 +02:00
Florian Roth
154181c6c8
fix: renamed files and lien break change
2020-07-01 09:48:48 +02:00
Florian Roth
d70b63b78c
rule: RedMimicry rules (modified)
2020-07-01 09:17:31 +02:00
Florian Roth
fe71d21d97
style: removed new lines
2020-07-01 09:11:00 +02:00
Florian Roth
b7ac36e6ab
Merge branch 'master' into rule-devel
2020-07-01 09:04:46 +02:00
Florian Roth
f2587791f2
rule: suspicious rar flags
2020-07-01 09:04:26 +02:00
Chris Brake
6ed1ea6509
Updating the mdatp backend file as it is currently impossible to set an ActionType as there is no mapping to EventType
2020-06-30 14:49:29 +01:00
Florian Roth
ba682c5de6
Merge pull request #863 from qwerty1q2w/feature
...
add win_not_allowed_rdp_access.yml rule
2020-06-30 10:03:11 +02:00
Florian Roth
77553e11e8
Update win_not_allowed_rdp_access.yml
2020-06-30 10:03:00 +02:00
Florian Roth
2e3669a5a4
Merge pull request #865 from j91321/defender-rules
...
Windows Defender logsource and rules
2020-06-30 10:01:17 +02:00
Florian Roth
eb3a6e86af
Merge pull request #867 from HarishHary/suspicious_powershell_parent_process
...
New Rule: Suspicious powershell parent process
2020-06-30 10:00:28 +02:00
Florian Roth
2c3f98dc83
Merge pull request #868 from HarishHary/pwsh_xor_commandline
...
New Rule: PowerShell xor commandline
2020-06-30 10:00:07 +02:00
Harish SEGAR
9c74018e12
Added new rule for pwsh_xor_cmd (sysmon)
2020-06-29 22:18:25 +02:00
Harish SEGAR
5e740fd7b2
Added new rule for pwsh_xor_cmd (sysmon)
2020-06-29 22:13:49 +02:00
Harish SEGAR
649e4eaa63
Added new rule for pwsh_xor_cmd
2020-06-29 22:09:58 +02:00
Florian Roth
5a11ef90d0
rule reorganized
2020-06-29 21:24:47 +02:00
Harish SEGAR
1a088425f9
Fix rules.
2020-06-29 20:42:35 +02:00
Ömer Günal
0c3ce445da
Delete remote_copy.yml
2020-06-29 18:51:18 +03:00
Florian Roth
bb214f5832
rule: Explorer Root Flag Process Tree Break
2020-06-29 12:07:15 +02:00
j91321
24029d998a
FIX: lint error for title
2020-06-28 11:05:19 +02:00
j91321
ae842a65cb
Windows Defender rules and logsource
2020-06-28 10:55:32 +02:00
Christian Clauss
9dc3940c07
Fix undefined names in sigma2misp.py
...
create_new_event() -> create_new_event(args, misp) to fix:
flake8 testing of https://github.com/Neo23x0/sigma on Python 3.8.3
% _flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics_
```
./tools/sigma/sigma2misp.py:11:16: F821 undefined name 'misp'
if hasattr(misp, "new_event"):
^
./tools/sigma/sigma2misp.py:12:16: F821 undefined name 'misp'
return misp.new_event(info=args.info)["Event"]["id"]
^
./tools/sigma/sigma2misp.py:12:36: F821 undefined name 'args'
return misp.new_event(info=args.info)["Event"]["id"]
^
./tools/sigma/sigma2misp.py:14:13: F821 undefined name 'misp'
event = misp.MISPEvent()
^
./tools/sigma/sigma2misp.py:15:18: F821 undefined name 'args'
event.info = args.info
^
./tools/sigma/sigma2misp.py:16:12: F821 undefined name 'misp'
return misp.add_event(event)["Event"]["id"]
^
6 F821 undefined name 'misp'
6
```
2020-06-28 07:02:41 +02:00
Thomas Patzke
0ee47e118c
Merge branch 'pr-848'
2020-06-28 01:04:30 +02:00
Thomas Patzke
89ed9f3763
Merge pull request #819 from cclauss/patch-2
...
Undefined name: from .exceptions import SigmaCollectionParseError
2020-06-28 00:37:09 +02:00
Thomas Patzke
4309082d6b
Merge pull request #818 from cclauss/patch-1
...
Undefined name: parser_print_help() --> parser.print_help()
2020-06-28 00:34:27 +02:00
Thomas Patzke
09378b5ebf
Fixed unsupported attempt to index a set
2020-06-28 00:27:33 +02:00
Thomas Patzke
415f826ece
Merge branch 'default-pop' of https://github.com/rtkbkish/sigma into rtkbkish-default-pop
2020-06-28 00:09:39 +02:00
Thomas Patzke
b1e4f44c21
Merge pull request #823 from Kuermel/master
...
Add more Options for XPackWatcherBackend (Elasticsearch)
2020-06-28 00:03:04 +02:00
Thomas Patzke
d1f37bdbd4
Merge pull request #828 from stevengoossensB/master
...
Split rules based on Sysmon event ID
2020-06-28 00:00:32 +02:00
Thomas Patzke
de5e453e19
Merge pull request #831 from 404d/cbr-backend-tweaks
...
Add parentheses around field list groups in CB
2020-06-27 23:39:57 +02:00
Pushkarev Dmitry
502ec4b417
add win_not_allowed_rdp_access.yml rule
2020-06-26 22:15:53 +00:00
Florian Roth
555c94bd7e
Merge pull request #861 from jaegeral/patch-4
...
s/straight forward/straightforward
2020-06-26 15:40:09 +02:00
Alexander J
839e06e37a
s/straight forward/straightforward
...
Fix a typo.
2020-06-26 12:40:06 +02:00
Florian Roth
da46ff6e93
docs: descriptions for source configs
2020-06-25 13:59:51 +02:00
Florian Roth
825bda397d
desc: better descriptions in help for backends and configurations
2020-06-25 13:21:43 +02:00
Florian Roth
3decee07ba
fix: bugfix and cosmetics
2020-06-24 18:10:58 +02:00
Florian Roth
07c0a6558e
fix: wording on sysmon mapping file
2020-06-24 17:49:42 +02:00
Florian Roth
f3fedef8f5
Changed category names and remove sysmon log source
2020-06-24 17:41:21 +02:00
Florian Roth
4224a6517d
Merge pull request #859 from Neo23x0/rule-devel
...
fix: duplicate IDs
2020-06-24 17:23:13 +02:00
Florian Roth
6d7f991424
Merge pull request #853 from rtkbkish/fix-win_ad_object_writedac_access
...
Fix quoting for AD Object WriteDAC Access
2020-06-24 17:06:15 +02:00
Florian Roth
c3ffa0b9d3
fix: duplicate IDs
2020-06-24 17:04:04 +02:00
Brad Kish
d385cbfa69
Fix quoting for AD Object WriteDAC Access
...
The AccessMask field needs to be quoted so that it is compared correctly.
2020-06-22 15:31:03 -04:00
Ömer Günal
4eb97ec43d
Update lnx_file_copy.yml
2020-06-22 21:35:50 +03:00
Florian Roth
e2a16087c9
Merge pull request #851 from ozirus/master
...
Update for new method
2020-06-22 20:11:39 +02:00
Furkan ÇALIŞKAN
b091e3b1c4
Update for new method
...
Update for method mentioned in https://ired.team/offensive-security/code-execution/code-execution-through-control-panel-add-ins
2020-06-22 01:06:34 +03:00
Ömer Günal
d17e0ae6eb
typo
2020-06-20 23:04:52 +03:00
Florian Roth
1ef81a36af
Merge pull request #850 from Neo23x0/rule-devel
...
K3chang and IE Registry Mods
2020-06-19 11:25:43 +02:00
Florian Roth
912ad94771
fix: missing ATT&CK id in tests
2020-06-19 10:00:44 +02:00
Florian Roth
e1225784f7
fix: fixed indentation
2020-06-19 09:54:08 +02:00
Florian Roth
62632db818
refactor: added variant to IE rule
2020-06-19 09:53:35 +02:00
Florian Roth
5cb6f5da9d
fix: title adjusted
2020-06-19 09:39:11 +02:00
Florian Roth
b8a5cd4787
Disabled IE Security Features
2020-06-19 09:37:10 +02:00
Florian Roth
da060bfb90
Ke3chang rule
2020-06-19 09:36:54 +02:00
Florian Roth
b675c4c706
Merge branch 'master' into rule-devel
2020-06-19 09:24:26 +02:00
Ömer Günal
93719d8a01
Merge pull request #1 from omergunal/omergunal-patch-1
...
Remote file copy
2020-06-18 23:56:29 +03:00
Ömer Günal
40a07a2d4f
Delete lnx_sudo_enumeration.yml
2020-06-18 23:55:24 +03:00
Ömer Günal
d87b0c95a4
Delete lnx_trap.yml
2020-06-18 23:55:16 +03:00
Ömer Günal
8db7c3207a
Delete lnx_sudo_caching.yml
2020-06-18 23:54:43 +03:00
Ömer Günal
5bc72b6cba
Delete lnx_space_after_filename.yml
2020-06-18 23:54:28 +03:00
Ömer Günal
f10440b9fa
Delete lnx_setuid_setgid.yml
2020-06-18 23:54:20 +03:00
Ömer Günal
6c8d104e7d
Delete lnx_disabling_security_tools.yml
2020-06-18 23:54:06 +03:00
Ömer Günal
84c4683607
Delete lnx_connection_proxy.yml
2020-06-18 23:53:43 +03:00
Ömer Günal
c4a1e853bc
Remote file copy
2020-06-18 23:47:53 +03:00
Ömer Günal
c6c455a3ec
Remote file copy
2020-06-18 23:37:49 +03:00
Ömer Günal
9bfc3d6807
Delete lnx_file_copy.yml
2020-06-18 23:37:12 +03:00
Ömer Günal
a963630db8
Remote File Copy
2020-06-18 23:36:29 +03:00
Brad Kish
203aa192c7
Fix multiple references to default field mapping in same rule
...
If there is a default mapping specified for a fieldmapping and that field is
referenced multiple times in the rule, the default mapping will be "pop"ped
and return the unmapped key on subsequent uses.
Don't pop the value. Just return the first entry.
2020-06-18 13:01:31 -04:00
Florian Roth
4b0c80885f
Merge pull request #810 from EccoTheFlintstone/fp
...
add WMI module load false positives
2020-06-18 12:50:40 +02:00
Florian Roth
32ecb81630
Merge pull request #845 from ikiril01/att&ck_subtechniques_v2
...
ATT&CK subtechniques v2
2020-06-18 09:10:09 +02:00
Ivan Kirillov
69760f6446
Added subtechniques to MITRE_TECHNIQUES
2020-06-17 11:51:48 -06:00
Ivan Kirillov
b343df2225
Further subtechnique updates
2020-06-17 11:31:40 -06:00
Ömer Günal
3a607abe33
Update lnx_trap.yml
2020-06-17 19:51:53 +03:00
ecco
99bfa14ae0
add 1 more FP
2020-06-17 12:49:27 -04:00
Ömer Günal
7b86f4aefb
Update lnx_trap.yml
2020-06-17 19:47:31 +03:00
Ömer Günal
ebbd32d2e1
file extension
2020-06-17 19:43:57 +03:00
Ömer Günal
f989f7e155
file extension
2020-06-17 19:43:49 +03:00
Ömer Günal
772c03c49a
Connection Proxy
2020-06-17 19:39:55 +03:00
Ömer Günal
9d285ecf74
Trap
2020-06-17 19:39:00 +03:00
Ömer Günal
d0b66ab828
Space After Filename
2020-06-17 19:38:38 +03:00
Ömer Günal
3b8fb9e3d8
Disabling Security Tools
2020-06-17 19:38:10 +03:00
Florian Roth
0022705373
fix: filter not functional
...
since `UsrLogon.cmd` does appear only in `C:\Windows\system32\cmd.exe /c UsrLogon.cmd` command line
2020-06-17 16:09:44 +02:00
Ivan Kirillov
5c0bb0e94f
Fixed indentation
2020-06-16 15:01:13 -06:00
Ivan Kirillov
0fbfcc6ba9
Initial round of subtechnique updates
2020-06-16 14:46:08 -06:00
Florian Roth
fd2429bd34
Update lnx_setuid_setgid.yml
2020-06-16 19:46:50 +02:00
Florian Roth
06fe720165
Update lnx_sudo_enumeration.yml
2020-06-16 19:33:39 +02:00
Florian Roth
545c05d4d3
Update lnx_setuid_setgid.yml
2020-06-16 19:31:34 +02:00
Ömer Günal
0027415fa2
Update lnx_setuid_setgid.yml
2020-06-16 20:26:50 +03:00
Ömer Günal
41b2309418
file type changed
2020-06-16 20:24:09 +03:00
Ömer Günal
0d0058da43
added id
2020-06-16 20:21:07 +03:00
Ömer Günal
bbcd506fb1
added id
2020-06-16 20:21:02 +03:00
Ömer Günal
ace575aaa6
added id
2020-06-16 20:20:42 +03:00
Ömer Günal
4b1557a587
Setuid and Setgid
...
Detects suspicious change of file privileges with chown and chmod commands
2020-06-16 20:12:24 +03:00
Ömer Günal
b7e1c6750c
sudo caching
...
attack.t1206
2020-06-16 19:31:02 +03:00
Ömer Günal
e43f13ed67
Update lnx_sudo_enumeration.yml
...
attack.t1169
2020-06-16 19:20:42 +03:00
Ömer Günal
52487159c5
Detect Sudo enumeration commands
2020-06-16 19:17:00 +03:00
Florian Roth
d24ec665fd
Merge pull request #838 from rtkbkish/fix-identifier
...
Identifiers shared between global document and rule gets overwritten
2020-06-15 20:20:23 +02:00
Florian Roth
87053502a3
Merge pull request #839 from rtkbkish/fix-double-backslash
...
Fix match for double-backslash
2020-06-15 20:19:56 +02:00
Florian Roth
869162a5da
Merge pull request #840 from rtkbkish/remove-wrong-sysmon-id
...
Rule lists extra Sysmon ID (11). Should just match registry events (1…
2020-06-15 20:19:27 +02:00
Florian Roth
3482e048fb
Merge pull request #841 from rtkbkish/fix-rule-match
...
Rule needs endwith, not exact match.
2020-06-15 20:19:12 +02:00
Florian Roth
46bd56a708
Merge pull request #837 from rtkbkish/fix-win-invoke-obfuscation
...
Fix logsource field name from service->category
2020-06-15 20:18:53 +02:00
Florian Roth
3d962bdb47
Merge pull request #836 from rtkbkish/fix-escaping
...
Fix rules with incorrect escaping of wildcars
2020-06-15 20:18:34 +02:00
Brad Kish
dfae2a6df6
Rule needs endwith, not exact match.
...
Fix ImageLoaded filter to match with endswith, rather than exact match.
2020-06-15 13:54:02 -04:00
Brad Kish
a9c6fa904f
Rule lists extra Sysmon ID (11). Should just match registry events (12-14)
...
Remove extraneous event ID 11. It will never match.
2020-06-15 13:52:12 -04:00
Brad Kish
f196046b3d
Fix match for double-backslash
...
To match a double-backslash you actually need three backslashes, since two
backslashes gets reduced to one.
2020-06-15 13:39:50 -04:00
Brad Kish
422b2bffd7
Fix rules with incorrect escaping of wildcars
...
A backslash before a wildcard needs to be escaped with another backslash.
2020-06-15 13:38:18 -04:00
Brad Kish
8d58c8f5c8
Fix logsource field name from service->category
...
The rule win_invoke_obfuscation_obfuscated_iex_commandline has the
wrong field name for the "process_creation" tag. Rename from "service"
to "category"
2020-06-15 13:18:05 -04:00
Brad Kish
f5aa871e5d
Identifiers shared between global document and rule gets overwritten
...
The global document defines a "selection" identifier which is also defined the
individual rules. The rule identifier is getting overwritten by the global identifier.
Fix by giving unique names to the global identifier.
2020-06-15 13:14:31 -04:00
Florian Roth
d371fd864c
Merge pull request #834 from ebeahan/elastic-updates
...
Elastic section updates
2020-06-13 10:04:49 +02:00
Thomas Patzke
f907c49ab5
Improved test coverage
...
* Added test case
* Removed unused code
2020-06-13 01:11:08 +02:00
Thomas Patzke
05ced1a3d5
Exclude heatmap.json from versioning
2020-06-13 00:05:57 +02:00
Thomas Patzke
b129556388
Automatic inclusion of all configuration files
2020-06-13 00:04:45 +02:00
Thomas Patzke
80e8f0e5fa
Release 0.17.0
2020-06-12 23:52:06 +02:00
Thomas Patzke
24d83b80cd
Merge branch 'script_entry_points'
2020-06-12 23:13:11 +02:00
Eric Beahan
bba0b2d851
Elastic documentation improvements
2020-06-12 13:40:39 -05:00
Florian Roth
b48e7d8d71
Merge pull request #833 from neu5ron/sigmacs
...
typo and another example
2020-06-12 17:39:14 +02:00
Nate Guagenti
db6c9dc721
Merge remote-tracking branch 'neu5ron-sigma/sigmacs' into sigmacs
...
# Conflicts:
# tools/README.md
2020-06-12 11:37:39 -04:00
Nate Guagenti
aac1af1832
typo, was missing the = and *.
...
also, show option when using case insensitive for everything, how to "exclude" a field from that regex.
Signed-off-by: Nate Guagenti <neu5ron@users.noreply.github.com >
2020-06-12 11:37:32 -04:00
Nate Guagenti
db0292afd2
typo, was missing the = and *.
...
also, show option when using case insensitive for everything, how to "exclude" a field from that regex.
2020-06-12 11:36:19 -04:00
Florian Roth
52ff2e12ab
Merge pull request #832 from Iveco/master
...
Cmd.exe Path Traversal Detection / Argument Spoofing
2020-06-12 10:33:15 +02:00
Iveco
40f0fd989d
- moved to "process_creation" folder instead of "sysmon"
...
- renamed .yml file
2020-06-11 19:21:17 +02:00
Iveco
34d7ea2974
removed one field
2020-06-11 16:23:15 +02:00
Iveco
2081baafe5
updated to process_creation
2020-06-11 15:58:05 +02:00
Iveco
f56e2599b1
Cmd.exe Path Traversal Detection
2020-06-11 15:48:48 +02:00
Simen Lybekk
bbcbed4742
Add parentheses about field list groups in CB
...
This should address the grouping issue from #660 .
The grouping issue was solved by just slamming some parentheses around the fields in the listExpression field.
2020-06-11 15:33:02 +02:00
Florian Roth
a7136481f1
Update win_pcap_drivers.yml
2020-06-11 11:14:43 +02:00
Florian Roth
97c45f9d46
Merge pull request #812 from tliffick/master
...
added new rules for malware
2020-06-10 17:37:19 +02:00
Cian Heasley
9835c6d67d
add win_pcap_drivers.yml
2020-06-10 15:53:22 +01:00
Florian Roth
96309d247b
fix: cosmetic fault
2020-06-10 16:41:03 +02:00
Florian Roth
6e4aa01baa
Cosmetics
2020-06-10 16:36:17 +02:00
Florian Roth
13c7d40a22
Cosmetics
2020-06-10 16:35:41 +02:00
Florian Roth
f553fb2e33
Cosmetics
2020-06-10 16:35:14 +02:00
Florian Roth
48e4e31713
Merge pull request #826 from NVISO-BE/sysmon_susp_fax_dll
...
Fax Service DLL search order hijacking detection
2020-06-10 16:33:12 +02:00
Florian Roth
1a9da23611
Merge pull request #825 from NVISO-BE/sysmon_office_persistence
...
Office persistence by addin detection
2020-06-10 16:32:50 +02:00
Steven Goossens
e5f36dd146
Added rules files split into folders
2020-06-10 16:32:30 +02:00
Remco Hofman
8adaa2d672
Fixed bad indentation
2020-06-10 15:02:41 +02:00
Steven Goossens
423baafa2a
Added rules for different sysmon categories and added the category definition
2020-06-10 15:02:15 +02:00
Remco Hofman
83a6e25bcb
Fax Service DLL search order hijacking
2020-06-10 15:01:07 +02:00
Remco Hofman
cb8e478ac1
Sigma rule to detect Office persistence via addin.
2020-06-10 14:52:13 +02:00
Thomas Patzke
915ea1cc67
Merge branch 'script_entry_points' into master
2020-06-10 00:51:47 +02:00
Florian Roth
565febd39d
README updated
2020-06-09 23:25:09 +02:00
Florian Roth
51f28271a5
Merge pull request #824 from neu5ron/sigmacs
...
Sigmacs
2020-06-09 23:15:50 +02:00
Nate Guagenti
2b735494cd
Merge branch 'master' of https://github.com/Neo23x0/sigma into sigmacs
2020-06-09 16:54:02 -04:00
Nate Guagenti
f4fe425fa7
update readme for some analyzed field and keyword field examples
2020-06-09 16:53:50 -04:00
Thomas G
8c61dc9248
Add more Options for XPackWatcherBackend (Elasticsearch)
...
Add action_throttle_period, mail_from adn mail_profile to the XPackWatcherBackend (Elasticsearch)
2020-06-09 20:57:26 +02:00
Florian Roth
5c835cf1f2
Merge pull request #813 from ozirus/patch-1
...
Create sysmon_apt_muddywater_dnstunnel.yml
2020-06-09 18:44:45 +02:00
Florian Roth
7a334a8d8a
fix: missed line
2020-06-09 17:30:54 +02:00
Florian Roth
04913a4b95
Aligned indentation
2020-06-09 17:20:25 +02:00
Florian Roth
9b8f8b7e09
Merge pull request #822 from NVISO-BE/win_mal_flowcloud
...
TA410 FlowCloud malware detection
2020-06-09 17:18:39 +02:00
Florian Roth
ad5c0a6cf3
Merge pull request #821 from NVISO-BE/win_mal_octopus_scanner
...
Octopus Scanner malware rule
2020-06-09 17:18:04 +02:00
Remco Hofman
a9bf22750a
Fixed bad indentation
2020-06-09 16:30:17 +02:00
Remco Hofman
4ce3ea735e
TA410 FlowCloud malware detection
2020-06-09 16:21:46 +02:00
Remco Hofman
d14d391761
Octopus Scanner malware rule
2020-06-09 16:12:05 +02:00
Nate Guagenti
117ceac492
moved file to ecs-zeek-elastic-beats-implementation.yml
2020-06-09 08:56:01 -04:00
Christian Clauss
dff7efc173
Update collection.py
2020-06-08 13:55:52 +02:00
Christian Clauss
55c0a03564
Undefined name: from .exceptions import SigmaCollectionParseError
...
Discovered in #378 . `SigmaCollectionParseError()` is called on line 55 but it is never defined or imported which means that NameError will be raised instead of SigmaCollectionParseError.
2020-06-08 13:55:16 +02:00
Christian Clauss
3fdb355f2b
Undefined name: parser_print_help() --> parser.print_help()
...
Discovered in #378
https://docs.python.org/3.8/library/argparse.html#argparse.ArgumentParser.print_help
2020-06-08 13:49:44 +02:00
Florian Roth
6e349030d9
rule: suspicious camera and mic access
2020-06-08 10:18:44 +02:00
Nate Guagenti
ad9ada7a44
Merge branch 'master' of https://github.com/Neo23x0/sigma into sigmacs
...
Conflicts:
tools/sigma/backends/mdatp.py
2020-06-07 11:51:17 -04:00
Florian Roth
94b90adf10
docs: move Sigmac help from Wiki to repo
2020-06-07 12:18:37 +02:00
Thomas Patzke
36a7077648
Moved tool executables to new location
2020-06-07 01:14:04 +02:00
Thomas Patzke
a7d18c7ed9
Converted sigma2attack and added to entry points
2020-06-07 01:03:09 +02:00
Thomas Patzke
8688e8a2a1
Script entrypoint stubs
2020-06-07 00:22:59 +02:00
Florian Roth
0c2f2fe6df
Merge pull request #816 from Neo23x0/rule-devel
...
merged Cyb3rWarD0g's rules
2020-06-06 16:27:59 +02:00
Florian Roth
d3e261862d
merged Cyb3rWarD0g's rules
2020-06-06 15:42:22 +02:00
Florian Roth
72deaa98f5
Merge pull request #815 from Neo23x0/rule-devel
...
Rule devel
2020-06-06 14:19:37 +02:00
Florian Roth
3697186281
fix: fixed title
2020-06-06 14:04:40 +02:00
Florian Roth
246a95557b
fix: description over multiple lines
2020-06-06 13:56:48 +02:00
Florian Roth
d54209dcc5
rule: ETW disabled
2020-06-06 13:56:19 +02:00
Thomas Patzke
7d70cd95a4
Deduplicated backend list
2020-06-06 01:03:02 +02:00
Thomas Patzke
fb9855bd3b
Added description to es-rule backend
2020-06-06 01:02:44 +02:00
Thomas Patzke
1d211565fc
Moved backend options list to --backend-help
2020-06-06 00:56:00 +02:00
Thomas Patzke
c992dc5215
Improved test coverage
2020-06-05 23:33:51 +02:00
Thomas Patzke
5d88d97c73
Merge branch 'improvements/improved_mdatp_mappings' of https://github.com/wietze/sigma into wietze-improvements/improved_mdatp_mappings
2020-06-05 23:03:52 +02:00
Nate Guagenti
55beecac28
Squashed commit of the following:
...
commit d97d2ced82
Merge: 022d73f8 84dd8c39
Author: Florian Roth <venom14@gmail.com >
Date: Wed Jun 3 15:53:55 2020 +0200
Merge pull request #725 from WilliamBruneau/fix_null_list
Move null values out from list in rules
commit 84dd8c39c4
Author: William Bruneau <william.bruneau@epfedu.fr >
Date: Tue May 5 09:04:47 2020 +0200
Move null values out from list in rules
commit 022d73f842
Merge: 0cbc099d 4ed51201
Author: Florian Roth <venom14@gmail.com >
Date: Wed Jun 3 10:48:05 2020 +0200
Merge pull request #811 from svnscha/fix/field-TargetFileName-to-TargetFilename
All Rules use 'TargetFilename' instead of 'TargetFileName'.
commit 4ed512011a
Author: Sven Scharmentke <sven@vastlimits.com >
Date: Wed Jun 3 09:00:59 2020 +0200
All Rules use 'TargetFilename' instead of 'TargetFileName'.
This commit fixes the incorrect spelling.
commit 0cbc099def
Merge: 74e16fdc 3a6ac5bd
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 30 09:31:45 2020 +0200
Merge pull request #807 from forensicanalysis/master
Add sqlite backend
commit 3a6ac5bd5c
Author: Jonas Plum <git@cugu.eu >
Date: Sat May 30 01:57:06 2020 +0200
Remove unused function
commit 5cc82d0f05
Author: Jonas Plum <git@cugu.eu >
Date: Sat May 30 00:56:06 2020 +0200
Move testcase
commit 4a8ab88ade
Author: Jonas Plum <git@cugu.eu >
Date: Sat May 30 00:15:38 2020 +0200
Fix test path
commit 70935d26ce
Author: Jonas Plum <git@cugu.eu >
Date: Fri May 29 23:56:05 2020 +0200
Add license header
commit 74e16fdccd
Merge: e20b58c4 537bda44
Author: Florian Roth <venom14@gmail.com >
Date: Fri May 29 17:32:43 2020 +0200
Merge pull request #803 from gamma37/clear_cmd_history
Edit Clear Command History
commit e20b58c421
Merge: 7f2fa05e a00f7f19
Author: Florian Roth <venom14@gmail.com >
Date: Fri May 29 17:32:27 2020 +0200
Merge pull request #806 from SanWieb/sysmon_creation_system_file
Fixed wrong field & Improve rule
commit a00f7f19a1
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Fri May 29 16:25:54 2020 +0200
Add tagg Endswith
Prevent the trigger of {}.exe.log
commit 38afd8b5de
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Thu May 28 21:52:17 2020 +0200
Fixed wrong field
commit 7f2fa05ed3
Merge: ec313b6c 39b41b55
Author: Florian Roth <venom14@gmail.com >
Date: Thu May 28 11:16:44 2020 +0200
Merge pull request #802 from Neo23x0/rule-devel
ComRAT and KazuarRAT
commit 537bda4417
Author: gamma37 <marie.euler@polytechnique.edu >
Date: Thu May 28 10:56:35 2020 +0200
Update lnx_shell_clear_cmd_history.yml
commit 5a48934822
Author: gamma37 <marie.euler@polytechnique.edu >
Date: Thu May 28 10:52:17 2020 +0200
Edit Clear Command History
I suggest a new point of view to detect that bash_history has been cleared : Instead of trying to detect all the commands that can do that, we could monitor the size of the file and log whenever it has less than 1 line.
commit 39b41b5582
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Thu May 28 10:13:38 2020 +0200
rule: moved DebugView rule to process creation category
commit 76dcc1a16f
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Thu May 28 09:22:25 2020 +0200
rule: renamed debugview
commit ec313b6c8a
Merge: 5bb6770f d44fc43c
Author: Florian Roth <venom14@gmail.com >
Date: Wed May 27 08:49:20 2020 +0200
Merge pull request #801 from SanWieb/sysmon_creation_system_file
Rule: sysmon_creation_system_file
commit d44fc43c54
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Tue May 26 19:10:11 2020 +0200
Add extension
commit f6ec724d51
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Tue May 26 18:53:54 2020 +0200
Rule: sysmon_creation_system_file
commit 5bb6770f53
Merge: 0b398c5b 3681b8cb
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 26 14:28:47 2020 +0200
Merge pull request #800 from SanWieb/win_system_exe_anomaly
Extended Windows processes: win_system_exe_anomaly
commit 4ca81b896d
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Tue May 26 14:19:22 2020 +0200
rule: Turla ComRAT report
commit 3681b8cb56
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Tue May 26 13:56:51 2020 +0200
Extended Windows processes
commit 0b398c5bf0
Merge: c1f47875 b648998f
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 26 13:31:57 2020 +0200
Merge pull request #798 from Neo23x0/rule-devel
rule: confluence exploit CVE-2019-3398 & Turla ComRAT
commit c1f4787566
Merge: ce1f4634 48c5f2ed
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 26 13:21:04 2020 +0200
Merge pull request #797 from NVISO-BE/sysmon_cve-2020-1048
Changes to sysmon_cve-2020-1048
commit ce1f46346f
Merge: e131f347 1a598282
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 26 13:20:40 2020 +0200
Merge pull request #751 from zaphodef/fix/powershell_ntfs_ads_access
Add 'Add-Content' to powershell_ntfs_ads_access
commit e131f3476e
Merge: 30861b55 7037e775
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 26 13:20:23 2020 +0200
Merge pull request #796 from EccoTheFlintstone/fp
add more false positives
commit 30861b558c
Merge: a962bd1b f9f814f3
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 26 13:20:07 2020 +0200
Merge pull request #799 from SanWieb/susp_file_characteristics
Susp file characteristics: Reduce FP of legitime processes
commit b648998fd0
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Tue May 26 13:18:50 2020 +0200
rule: Turla ComRAT
commit f9f814f3b3
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Tue May 26 13:06:27 2020 +0200
Shortened title
commit a241792e10
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Tue May 26 12:58:15 2020 +0200
Reduce FP of legitime processes
A lot of Windows apps does not have any file characteristics. Some examples:
- Gamebar: C:\\Program Files\\WindowsApps\\Microsoft.XboxGamingOverlay_3.38.25003.0_x64__8wekyb3d8bbwe\\GameBarFT.exe
- YourPhone: C:\\Program Files\\WindowsApps\\Microsoft.YourPhone_1.20022.82.0_x64__8wekyb3d8bbwe\\YourPhoneServer/YourPhoneServer.exe
All C:\Windows\System32\OpenSSH (scp, sftp, ssh etc) does not have a description and company.
Python 2.7, 3.3 and 3.7 does not have any file characteristics.
So I don't think it is possible to whitelist all options, maybe it is worthwhile to check the \Downloads\ folder otherwise it would be better to just delete the rule. All other suspicious folders are covered by /rules/windows/process_creation/win_susp_exec_folder.yml
commit cdf1ade625
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Tue May 26 12:27:16 2020 +0200
fix: typo in selection
commit 91b4ee8d56
Merge: 4cd7c39e a962bd1b
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Tue May 26 12:24:21 2020 +0200
Merge pull request #2 from Neo23x0/master
Update repository
commit 828484d7c6
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Tue May 26 12:09:41 2020 +0200
rule: confluence exploit CVE-2019-3398
commit 48c5f2ed09
Author: Remco Hofman <rhofman@nviso.be >
Date: Tue May 26 11:20:21 2020 +0200
Update to sysmon_cve-2020-1048
Added .com executables to detection
Second TargetObject should have been Details
commit abf1a2c6d7
Author: Jonas Hagg <joy.hagg@web.de >
Date: Mon May 25 10:54:16 2020 +0200
Adjusted Makefile
commit dedfb65d63
Author: Jonas Hagg <joy.hagg@web.de >
Date: Mon May 25 10:44:14 2020 +0200
Implemented Aggregation for SQL, Added SQLite FullTextSearch
commit 7037e77569
Author: ecco <none@none.com >
Date: Mon May 25 04:50:22 2020 -0400
add more FP
commit a962bd1bc1
Merge: 0afe0623 d510e1aa
Author: Florian Roth <venom14@gmail.com >
Date: Mon May 25 10:48:36 2020 +0200
Merge pull request #747 from zaphodef/fix/win_susp_backup_delete_source
Fix 'source' value for win_susp_backup_delete
commit 0afe0623af
Merge: 92d0aa86 beb62dc1
Author: Florian Roth <venom14@gmail.com >
Date: Mon May 25 10:47:23 2020 +0200
Merge pull request #757 from tliffick/master
added rule for Blue Mockingbird (cryptominer)
commit 92d0aa8654
Merge: 0dda757c 6fcf3f9e
Author: Florian Roth <venom14@gmail.com >
Date: Mon May 25 10:46:39 2020 +0200
Merge pull request #795 from SanWieb/Rule-improvement-Netsh-program-allowed
Rule improvement: netsh Application or Port allowed
commit 6fcf3f9ebf
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Mon May 25 10:13:26 2020 +0200
Update win_netsh_fw_add.yml
commit 28652e4648
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Mon May 25 10:02:13 2020 +0200
Add Windows Server 2008 and Windows Vista support
It did not support the command `netsh advfirewall firewall add`
commit 2678cd1d3e
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Mon May 25 09:50:47 2020 +0200
Create win_netsh_fw_add_susp_image.yml
More critical version of the rule windows/process_creation/win_netsh_fw_add.yml with the suspicious image location check.
Combined the following rules for the suspicious locations:
https://github.com/Neo23x0/sigma//blob/master/rules/windows/sysmon/sysmon_susp_download_run_key.yml
https://github.com/Neo23x0/sigma/blob/master/rules/windows/sysmon/sysmon_susp_run_key_img_folder.yml
https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_run_locations.yml
commit 4cd7c39e9d
Merge: 6fbfa9df 0dda757c
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Mon May 25 08:48:16 2020 +0200
Merge pull request #1 from Neo23x0/master
Update repository
commit 0dda757ca5
Merge: 40f0beb5 daf7ab5f
Author: Thomas Patzke <thomas@patzke.org >
Date: Sun May 24 22:58:58 2020 +0200
Merge branch 'socprime-master'
commit daf7ab5ff7
Author: Thomas Patzke <thomas@patzke.org >
Date: Sun May 24 22:41:38 2020 +0200
Cleanup: removal of corelight_* backends
commit d45f8e19fe
Author: Thomas Patzke <thomas@patzke.org >
Date: Sun May 24 21:46:55 2020 +0200
Fixes
commit 32e4998c49
Author: Thomas Patzke <thomas@patzke.org >
Date: Sun May 24 21:45:37 2020 +0200
Removed dead code from ALA backend.
commit 24b08bbf30
Merge: 96fae4be e8b956f5
Author: Thomas Patzke <thomas@patzke.org >
Date: Sun May 24 17:06:32 2020 +0200
Merge branch 'master' of https://github.com/socprime/sigma into socprime-master
commit 40f0beb58d
Merge: 6fbfa9df b8ee736f
Author: Florian Roth <venom14@gmail.com >
Date: Sun May 24 16:30:10 2020 +0200
Merge pull request #794 from SanWieb/update_susp_run_key
Remove AppData folder as suspicious folder
commit b8ee736f44
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Sun May 24 15:16:07 2020 +0200
Remove AppData folder as suspicious folder
A lot of software is using the AppData folder for startup keys. Some examples:
- Microsoft Teams (\AppData\Local\Microsoft\Teams)
- Resilio (\AppData\Roaming\Resilio Sync\)
- Discord ( (\AppData\Local\Discord\)
- Spotify ( (\AppData\Roaming\Spotify\)
Too many to whitelist them all
commit 6fbfa9dfdd
Merge: d0da2810 3028a270
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 23:47:12 2020 +0200
Merge pull request #793 from Neo23x0/rule-devel
Esentutl rule and StrongPity Loader UA
commit f970d28f10
Author: ecco <none@none.com >
Date: Sat May 23 15:06:15 2020 -0400
add more false positives
commit 3028a27055
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Sat May 23 18:32:02 2020 +0200
fix: buggy rule
commit df715386b6
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Sat May 23 18:27:36 2020 +0200
rule: suspicious esentutl use
commit d0da2810c1
Merge: 8321cc7e 67faf4bd
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 18:13:16 2020 +0200
Merge pull request #792 from EccoTheFlintstone/fff
fix FP + remove powershell rule redundant with sysmon_in_memory_power…
commit 8321cc7ee1
Merge: 9cd9a301 e1a05dfc
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 18:11:32 2020 +0200
Merge pull request #772 from gamma37/suspicious_activities
Create a rule for "suspicious activities"
commit d1a5471d21
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Sat May 23 17:38:10 2020 +0200
rule: Strong Pity loader UA
commit 67faf4bd41
Author: ecco <none@none.com >
Date: Sat May 23 10:56:23 2020 -0400
fix FP + remove powershell rule redundant with sysmon_in_memory_powershell.yml
commit 9cd9a301c2
Merge: ee1ca77f d310805e
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 16:50:31 2020 +0200
Merge pull request #791 from SanWieb/master
added rule for Netsh RDP port opening
commit e1a05dfc1c
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 16:49:03 2020 +0200
Update lnx_auditd_susp_C2_commands.yml
commit ee1ca77fad
Merge: 895c8470 cbf06b1e
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 16:47:46 2020 +0200
Merge pull request #771 from gamma37/new_rules
Create a new rule to detect "Create Account"
commit 895c84703f
Merge: 12e1aeaf 327a53c1
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 16:47:01 2020 +0200
Merge pull request #790 from EccoTheFlintstone/fp_fix
fix false positive matching on every powershell process not run by SY…
commit 327a53c120
Author: ecco <none@none.com >
Date: Sat May 23 10:25:37 2020 -0400
add new test for sysmon rules without eventid
commit 10ca3006f5
Author: ecco <none@none.com >
Date: Sat May 23 10:07:55 2020 -0400
move rule where needed
commit 2b89e56054
Author: ecco <none@none.com >
Date: Sat May 23 10:03:13 2020 -0400
fix test
commit d9bc09c38c
Author: ecco <none@none.com >
Date: Sat May 23 10:02:58 2020 -0400
fix test
commit 78a7852a43
Author: ecco <none@none.com >
Date: Sat May 23 09:16:40 2020 -0400
renamed dbghelp rule with new ID and comment and removed a false positive
commit d310805ed9
Author: Sander Wiebing <45387038+SanWieb@users.noreply.github.com >
Date: Sat May 23 14:19:52 2020 +0200
rule: Netsh RDP port opening
commit 75ba5f989c
Author: ecco <none@none.com >
Date: Sat May 23 07:44:45 2020 -0400
add 1 more FP to wmi load
commit 9a7f462d79
Author: ecco <none@none.com >
Date: Sat May 23 07:17:56 2020 -0400
move renamed bnaries rule to process creation (they made a lot of false positives in sysmon as there was no event id specified in the rule)
commit cfde0625f5
Author: ecco <none@none.com >
Date: Sat May 23 07:05:09 2020 -0400
fix false positive matching on every powershell process not run by SYSTEM account
commit 12e1aeaf9f
Merge: 46f3a70a 34006d07
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 09:54:43 2020 +0200
Merge pull request #788 from Neo23x0/rule-devel
refactor: split up rule for CVE-2020-1048 into 2 rules
commit 46f3a70a7d
Merge: 96fae4be ec17c2ab
Author: Florian Roth <venom14@gmail.com >
Date: Sat May 23 09:54:28 2020 +0200
Merge pull request #786 from EccoTheFlintstone/perf_fix
various rules cleaning (slight perf improvements)
commit 34006d0794
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Sat May 23 09:16:19 2020 +0200
refactor: simplified and extended expression in CVE-2020-1048 rule
commit 57c8e63acd
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Sat May 23 09:09:58 2020 +0200
refactore: split up rule for CVE-2020-1048 into 2 rules
commit ec17c2ab56
Author: ecco <none@none.com >
Date: Fri May 22 10:37:00 2020 -0400
filter on createkey only when needed
commit 96fae4be68
Author: Thomas Patzke <thomas@patzke.org >
Date: Fri May 22 00:50:37 2020 +0200
Added CrachMapExec rules
commit 64e0e7ca72
Merge: bbf78374 91c4c4ec
Author: Florian Roth <venom14@gmail.com >
Date: Thu May 21 14:19:09 2020 +0200
Merge pull request #784 from Neo23x0/rule-devel
refactor: slightly improved Greenbug rule
commit 91c4c4ecc5
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Thu May 21 13:38:11 2020 +0200
refactor: slightly improved Greenbug rule
commit bbf78374b6
Merge: 8d9b706d 9a3b6c1c
Author: Florian Roth <venom14@gmail.com >
Date: Thu May 21 09:55:46 2020 +0200
Merge pull request #783 from Neo23x0/rule-devel
Greenbug Rule
commit 9a3b6c1c77
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Thu May 21 09:44:11 2020 +0200
docs: added MITRE ATT&CK group tag
commit 344eb713c5
Author: Florian Roth <florian.roth@nextron-systems.com >
Date: Thu May 21 09:39:57 2020 +0200
rule: Greenbug campaign
commit 8d9b706d6a
Merge: e7980bb4 06abd6e7
Author: Thomas Patzke <thomas@patzke.org >
Date: Wed May 20 19:11:56 2020 +0200
Merge pull request #727 from 3CORESec/master
Override Features
commit e7980bb434
Merge: af92a5bd 8963c0a6
Author: Florian Roth <venom14@gmail.com >
Date: Wed May 20 12:55:41 2020 +0200
Merge pull request #782 from ZikyHD/patch-1
Remove duplicate 'CommandLine' in fields
commit af92a5bd2c
Merge: 04dfe6c5 9ab65cd1
Author: Florian Roth <venom14@gmail.com >
Date: Wed May 20 12:55:29 2020 +0200
Merge pull request #780 from tatsu-i/master
Null field check to eliminate false positives
commit 8963c0a65e
Author: ZikyHD <ZikyHD@users.noreply.github.com >
Date: Wed May 20 11:54:47 2020 +0200
Remove duplicate 'CommandLine' in fields
commit e8b956f575
Author: vh <vh@socprime.com >
Date: Wed May 20 12:35:00 2020 +0300
Updated config
commit 9ab65cd1c7
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 19 14:50:22 2020 +0200
Update win_alert_ad_user_backdoors.yml
commit 04dfe6c5fc
Merge: df75bdd3 9e272d37
Author: Thomas Patzke <thomas@patzke.org >
Date: Tue May 19 13:18:40 2020 +0200
Merge pull request #778 from neu5ron/sigmacs
SIGMACs: Winlogbeat & Zeek
commit df75bdd3b6
Merge: 4446c4cd 7c3dea22
Author: Florian Roth <venom14@gmail.com >
Date: Tue May 19 13:10:56 2020 +0200
Merge pull request #779 from neu5ron/rules
Rules: Zeek
commit 7c3dea22b8
Author: neu5ron <>
Date: Tue May 19 05:13:48 2020 -0400
small T, big T
commit dd382848b4
Merge: 602c8917 e975d3fd
Author: neu5ron <>
Date: Tue May 19 05:09:05 2020 -0400
Merge remote-tracking branch 'neu5ron-sigma/rules' into rules
commit 602c8917ef
Author: neu5ron <>
Date: Tue May 19 04:41:08 2020 -0400
domain user enumeration via zeek rpc (dce_rpc) log.
commit c815773b1a
Author: Tatsuya Ito <t_ito@cyberdefense.jp >
Date: Tue May 19 18:05:51 2020 +0900
enhancement rule
commit 49f68a327a
Author: Tatsuya Ito <t_ito@cyberdefense.jp >
Date: Tue May 19 18:00:50 2020 +0900
enhancement rule
commit e975d3fd14
Author: neu5ron <>
Date: Tue May 19 04:41:08 2020 -0400
domain user enumeration via zeek rpc (dce_rpc) log.
commit effb2a8337
Author: neu5ron <>
Date: Tue May 19 04:41:00 2020 -0400
add exe webdav download
commit 858ebcd3d3
Author: neu5ron <>
Date: Tue May 19 04:35:47 2020 -0400
author typo update
commit 2fc8d513d6
Author: neu5ron <>
Date: Tue May 19 04:35:30 2020 -0400
zeek, swap `path` and `name`
commit 0dd089db47
Author: ecco <none@none.com >
Date: Mon May 18 20:29:53 2020 -0400
various rules cleaning
commit 71c507d8a9
Author: gamma37 <marie.euler@polytechnique.edu >
Date: Mon May 18 11:34:53 2020 +0200
remove space bedore colon
commit 55eec46932
Author: gamma37 <marie.euler@polytechnique.edu >
Date: Mon May 18 11:25:18 2020 +0200
Create a rule for "suspicious activities"
commit cbf06b1e43
Author: gamma37 <marie.euler@polytechnique.edu >
Date: Mon May 18 10:11:32 2020 +0200
lowercased tag
commit 904716771a
Author: gamma37 <marie.euler@polytechnique.edu >
Date: Mon May 18 10:03:34 2020 +0200
Create a new rule to detect "Create Account"
commit beb62dc163
Author: Florian Roth <venom14@gmail.com >
Date: Fri May 15 12:06:34 2020 +0200
fix: condition location
commit 28dc2a2267
Author: Florian Roth <venom14@gmail.com >
Date: Fri May 15 11:33:36 2020 +0200
Minor changes
hints:
- contains doesn't require wildcards in the strings
- we can use 'endswith' instead of wildcard at the beginning of the string (it's the new way to describe it, we have to change all old rules that contain these wildcards some day)
- we can use "1 of them" to say that 1 of the conditions has to match
commit 40ab1b7247
Author: Trent Liffick <trent.liffick@outlook.com >
Date: Thu May 14 23:33:08 2020 -0400
added 'action: global'
commit 56a2747a70
Author: Trent Liffick <trent.liffick@outlook.com >
Date: Thu May 14 23:18:33 2020 -0400
Corrected missing condition
learning! fail fast & forward
commit fb1d8d7a76
Author: Trent Liffick <trent.liffick@outlook.com >
Date: Thu May 14 23:04:14 2020 -0400
Corrected typo
commit 8aff6b412e
Author: Trent Liffick <trent.liffick@outlook.com >
Date: Thu May 14 22:58:23 2020 -0400
added rule for Blue Mockingbird (cryptominer)
commit 06abd6e76a
Author: Tiago Faria <tiago.faria.backups@gmail.com >
Date: Thu May 14 14:03:23 2020 +0100
added ci tests for ecs-cloudtrail
commit 2893becf8c
Merge: 31ad8187 133319c4
Author: Tiago Faria <tiago.faria.backups@gmail.com >
Date: Thu May 14 14:02:20 2020 +0100
Merge remote-tracking branch 'upstream/master'
commit 1a598282f4
Author: zaphod <18658828+zaphodef@users.noreply.github.com >
Date: Wed May 13 11:57:10 2020 +0200
Add 'Add-Content' to powershell_ntfs_ads_access
commit d510e1aad4
Author: zaphod <18658828+zaphodef@users.noreply.github.com >
Date: Mon May 11 18:31:59 2020 +0200
Fix 'source' value for win_susp_backup_delete
commit fb9c5841f4
Author: vh <vh@socprime.com >
Date: Fri May 8 13:41:52 2020 +0300
Added Humio, Crowdstrike, Corelight
commit 31ad81874f
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Tue May 5 11:32:18 2020 +0100
capitalized titles
corrected capitalization of titles and removed literals from config
commit aa175a7d5b
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Mon May 4 18:02:27 2020 +0100
wip
wip
commit dd9e128a15
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Mon May 4 17:35:12 2020 +0100
kibana target update
kibana target now compatible with overrides
commit b32093e734
Merge: b3194e66 d298bb57
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Mon May 4 17:26:51 2020 +0100
Merge remote-tracking branch 'upstream/master'
Keeping up with the sigmas.
commit b3194e66c4
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Mon May 4 16:37:36 2020 +0100
Update base.py
commit dd85467a27
Author: Tiago Faria <tiago.faria.backups@gmail.com >
Date: Sat May 2 00:13:55 2020 +0100
Update aws_ec2_vm_export_failure.yml
commit bc0a2c7ab9
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Fri May 1 19:20:05 2020 +0100
wip
wip
commit 98391f985a
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Thu Apr 30 15:19:38 2020 +0100
wip
wip
commit adcc3766e3
Merge: 81422444 dfdb5b95
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Thu Apr 30 15:08:25 2020 +0100
Merge branch 'master' of https://github.com/3CORESec/sigma
commit 8142244449
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Thu Apr 30 15:08:20 2020 +0100
wip
wip
commit dfdb5b9550
Author: Tiago Faria <tiago.faria.backups@gmail.com >
Date: Wed Apr 29 23:59:26 2020 +0100
better description and event.outcome
commit ac4a2b1f26
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Wed Apr 29 22:55:46 2020 +0100
wip
wip
commit 9ce84a38e5
Author: pdr9rc <pedro.gracio@3coresec.com >
Date: Wed Apr 29 20:36:45 2020 +0100
overrides section support + one example rule + cloudtrail config
ditto
2020-06-05 13:18:03 -04:00
Florian Roth
2e77e65285
rule: Covenant launchers
2020-06-05 11:03:28 +02:00
Furkan ÇALIŞKAN
082696ee84
Added UUID
2020-06-04 18:38:42 +03:00
Furkan ÇALIŞKAN
e958a6a939
Date added
2020-06-04 18:34:44 +03:00
Furkan ÇALIŞKAN
5e373153eb
Title fix
2020-06-04 18:28:37 +03:00
Furkan ÇALIŞKAN
0744107fbb
Deleted EventID part
2020-06-04 18:19:08 +03:00
Furkan ÇALIŞKAN
1c677aa172
Fix title as in guideline
...
Fix title error as in guideline and other cosmetic changes
2020-06-04 18:13:32 +03:00
Furkan ÇALIŞKAN
bafd6bde5f
Convert to process_creation
...
Convert to process_creation
2020-06-04 14:45:10 +03:00
Furkan ÇALIŞKAN
09afae1e66
Create sysmon_apt_muddywater_dnstunnel.yml
...
Detecting DNS tunnel activity from MuddyWater as in https://www.virustotal.com/gui/file/5ad401c3a568bd87dd13f8a9ddc4e450ece61cd9ce4d1b23f68ce0b1f3c190b7/
2020-06-04 14:27:19 +03:00
Trent Liffick
6c8c0cd85d
Removed incorrect technique
2020-06-03 17:51:57 -04:00
Trent Liffick
3c89f46899
removed unwanted file
2020-06-03 17:43:12 -04:00
Trent Liffick
2af501c9f5
added rule for zLoader & Office
...
detects changes to Office macro settings & ZLoader malware
2020-06-03 17:40:05 -04:00
Trent Liffick
a2ca199e7d
added rules for Lazaurs and hhsgov
2020-06-03 17:38:03 -04:00
Florian Roth
d97d2ced82
Merge pull request #725 from WilliamBruneau/fix_null_list
...
Move null values out from list in rules
2020-06-03 15:53:55 +02:00
William Bruneau
84dd8c39c4
Move null values out from list in rules
2020-06-03 13:57:22 +02:00
Florian Roth
022d73f842
Merge pull request #811 from svnscha/fix/field-TargetFileName-to-TargetFilename
...
All Rules use 'TargetFilename' instead of 'TargetFileName'.
2020-06-03 10:48:05 +02:00
Sven Scharmentke
4ed512011a
All Rules use 'TargetFilename' instead of 'TargetFileName'.
...
This commit fixes the incorrect spelling.
2020-06-03 09:00:59 +02:00
ecco
b1c11cc345
add WMI module load false positive
2020-06-01 03:30:27 -04:00
Florian Roth
0cbc099def
Merge pull request #807 from forensicanalysis/master
...
Add sqlite backend
2020-05-30 09:31:45 +02:00
Jonas Plum
3a6ac5bd5c
Remove unused function
2020-05-30 01:57:06 +02:00
Jonas Plum
5cc82d0f05
Move testcase
2020-05-30 00:56:06 +02:00
Jonas Plum
4a8ab88ade
Fix test path
2020-05-30 00:15:38 +02:00
Jonas Plum
70935d26ce
Add license header
2020-05-29 23:56:05 +02:00
Florian Roth
74e16fdccd
Merge pull request #803 from gamma37/clear_cmd_history
...
Edit Clear Command History
2020-05-29 17:32:43 +02:00
Florian Roth
e20b58c421
Merge pull request #806 from SanWieb/sysmon_creation_system_file
...
Fixed wrong field & Improve rule
2020-05-29 17:32:27 +02:00
Sander Wiebing
a00f7f19a1
Add tagg Endswith
...
Prevent the trigger of {}.exe.log
2020-05-29 16:25:54 +02:00
Sander Wiebing
38afd8b5de
Fixed wrong field
2020-05-28 21:52:17 +02:00
Florian Roth
7f2fa05ed3
Merge pull request #802 from Neo23x0/rule-devel
...
ComRAT and KazuarRAT
2020-05-28 11:16:44 +02:00
gamma37
537bda4417
Update lnx_shell_clear_cmd_history.yml
2020-05-28 10:56:35 +02:00
gamma37
5a48934822
Edit Clear Command History
...
I suggest a new point of view to detect that bash_history has been cleared : Instead of trying to detect all the commands that can do that, we could monitor the size of the file and log whenever it has less than 1 line.
2020-05-28 10:52:17 +02:00
Florian Roth
39b41b5582
rule: moved DebugView rule to process creation category
2020-05-28 10:13:38 +02:00
Florian Roth
76dcc1a16f
rule: renamed debugview
2020-05-28 09:22:25 +02:00
Florian Roth
ec313b6c8a
Merge pull request #801 from SanWieb/sysmon_creation_system_file
...
Rule: sysmon_creation_system_file
2020-05-27 08:49:20 +02:00
Sander Wiebing
d44fc43c54
Add extension
2020-05-26 19:10:11 +02:00
Sander Wiebing
f6ec724d51
Rule: sysmon_creation_system_file
2020-05-26 18:53:54 +02:00
Florian Roth
5bb6770f53
Merge pull request #800 from SanWieb/win_system_exe_anomaly
...
Extended Windows processes: win_system_exe_anomaly
2020-05-26 14:28:47 +02:00
Florian Roth
4ca81b896d
rule: Turla ComRAT report
2020-05-26 14:19:22 +02:00
Sander Wiebing
3681b8cb56
Extended Windows processes
2020-05-26 13:56:51 +02:00
Florian Roth
0b398c5bf0
Merge pull request #798 from Neo23x0/rule-devel
...
rule: confluence exploit CVE-2019-3398 & Turla ComRAT
2020-05-26 13:31:57 +02:00
Florian Roth
c1f4787566
Merge pull request #797 from NVISO-BE/sysmon_cve-2020-1048
...
Changes to sysmon_cve-2020-1048
2020-05-26 13:21:04 +02:00
Florian Roth
ce1f46346f
Merge pull request #751 from zaphodef/fix/powershell_ntfs_ads_access
...
Add 'Add-Content' to powershell_ntfs_ads_access
2020-05-26 13:20:40 +02:00
Florian Roth
e131f3476e
Merge pull request #796 from EccoTheFlintstone/fp
...
add more false positives
2020-05-26 13:20:23 +02:00
Florian Roth
30861b558c
Merge pull request #799 from SanWieb/susp_file_characteristics
...
Susp file characteristics: Reduce FP of legitime processes
2020-05-26 13:20:07 +02:00
Florian Roth
b648998fd0
rule: Turla ComRAT
2020-05-26 13:18:50 +02:00
Sander Wiebing
f9f814f3b3
Shortened title
2020-05-26 13:06:27 +02:00
Sander Wiebing
a241792e10
Reduce FP of legitime processes
...
A lot of Windows apps does not have any file characteristics. Some examples:
- Gamebar: C:\\Program Files\\WindowsApps\\Microsoft.XboxGamingOverlay_3.38.25003.0_x64__8wekyb3d8bbwe\\GameBarFT.exe
- YourPhone: C:\\Program Files\\WindowsApps\\Microsoft.YourPhone_1.20022.82.0_x64__8wekyb3d8bbwe\\YourPhoneServer/YourPhoneServer.exe
All C:\Windows\System32\OpenSSH (scp, sftp, ssh etc) does not have a description and company.
Python 2.7, 3.3 and 3.7 does not have any file characteristics.
So I don't think it is possible to whitelist all options, maybe it is worthwhile to check the \Downloads\ folder otherwise it would be better to just delete the rule. All other suspicious folders are covered by /rules/windows/process_creation/win_susp_exec_folder.yml
2020-05-26 12:58:15 +02:00
Florian Roth
cdf1ade625
fix: typo in selection
2020-05-26 12:27:16 +02:00
Sander Wiebing
91b4ee8d56
Merge pull request #2 from Neo23x0/master
...
Update repository
2020-05-26 12:24:21 +02:00
Florian Roth
828484d7c6
rule: confluence exploit CVE-2019-3398
2020-05-26 12:09:41 +02:00
Remco Hofman
48c5f2ed09
Update to sysmon_cve-2020-1048
...
Added .com executables to detection
Second TargetObject should have been Details
2020-05-26 11:20:21 +02:00
Jonas Hagg
abf1a2c6d7
Adjusted Makefile
2020-05-25 11:58:55 +02:00
Jonas Hagg
dedfb65d63
Implemented Aggregation for SQL, Added SQLite FullTextSearch
2020-05-25 11:58:55 +02:00
ecco
7037e77569
add more FP
2020-05-25 04:50:22 -04:00
Florian Roth
a962bd1bc1
Merge pull request #747 from zaphodef/fix/win_susp_backup_delete_source
...
Fix 'source' value for win_susp_backup_delete
2020-05-25 10:48:36 +02:00
Florian Roth
0afe0623af
Merge pull request #757 from tliffick/master
...
added rule for Blue Mockingbird (cryptominer)
2020-05-25 10:47:23 +02:00
Florian Roth
92d0aa8654
Merge pull request #795 from SanWieb/Rule-improvement-Netsh-program-allowed
...
Rule improvement: netsh Application or Port allowed
2020-05-25 10:46:39 +02:00
Sander Wiebing
6fcf3f9ebf
Update win_netsh_fw_add.yml
2020-05-25 10:13:26 +02:00
Sander Wiebing
28652e4648
Add Windows Server 2008 and Windows Vista support
...
It did not support the command `netsh advfirewall firewall add`
2020-05-25 10:02:13 +02:00
Sander Wiebing
2678cd1d3e
Create win_netsh_fw_add_susp_image.yml
...
More critical version of the rule windows/process_creation/win_netsh_fw_add.yml with the suspicious image location check.
Combined the following rules for the suspicious locations:
https://github.com/Neo23x0/sigma//blob/master/rules/windows/sysmon/sysmon_susp_download_run_key.yml
https://github.com/Neo23x0/sigma/blob/master/rules/windows/sysmon/sysmon_susp_run_key_img_folder.yml
https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_run_locations.yml
2020-05-25 09:50:47 +02:00
Sander Wiebing
4cd7c39e9d
Merge pull request #1 from Neo23x0/master
...
Update repository
2020-05-25 08:48:16 +02:00
Thomas Patzke
0dda757ca5
Merge branch 'socprime-master'
2020-05-24 22:58:58 +02:00
Thomas Patzke
daf7ab5ff7
Cleanup: removal of corelight_* backends
2020-05-24 22:41:38 +02:00
Thomas Patzke
d45f8e19fe
Fixes
2020-05-24 21:46:55 +02:00
Thomas Patzke
32e4998c49
Removed dead code from ALA backend.
2020-05-24 21:45:37 +02:00
Thomas Patzke
24b08bbf30
Merge branch 'master' of https://github.com/socprime/sigma into socprime-master
2020-05-24 17:06:32 +02:00
Florian Roth
40f0beb58d
Merge pull request #794 from SanWieb/update_susp_run_key
...
Remove AppData folder as suspicious folder
2020-05-24 16:30:10 +02:00
Sander Wiebing
b8ee736f44
Remove AppData folder as suspicious folder
...
A lot of software is using the AppData folder for startup keys. Some examples:
- Microsoft Teams (\AppData\Local\Microsoft\Teams)
- Resilio (\AppData\Roaming\Resilio Sync\)
- Discord ( (\AppData\Local\Discord\)
- Spotify ( (\AppData\Roaming\Spotify\)
Too many to whitelist them all
2020-05-24 15:16:07 +02:00
Florian Roth
6fbfa9dfdd
Merge pull request #793 from Neo23x0/rule-devel
...
Esentutl rule and StrongPity Loader UA
2020-05-23 23:47:12 +02:00
ecco
f970d28f10
add more false positives
2020-05-23 15:06:15 -04:00
Florian Roth
3028a27055
fix: buggy rule
2020-05-23 18:32:02 +02:00
Florian Roth
df715386b6
rule: suspicious esentutl use
2020-05-23 18:27:36 +02:00
Florian Roth
d0da2810c1
Merge pull request #792 from EccoTheFlintstone/fff
...
fix FP + remove powershell rule redundant with sysmon_in_memory_power…
2020-05-23 18:13:16 +02:00
Florian Roth
8321cc7ee1
Merge pull request #772 from gamma37/suspicious_activities
...
Create a rule for "suspicious activities"
2020-05-23 18:11:32 +02:00
Florian Roth
d1a5471d21
rule: Strong Pity loader UA
2020-05-23 17:38:10 +02:00
ecco
67faf4bd41
fix FP + remove powershell rule redundant with sysmon_in_memory_powershell.yml
2020-05-23 10:56:23 -04:00
Florian Roth
9cd9a301c2
Merge pull request #791 from SanWieb/master
...
added rule for Netsh RDP port opening
2020-05-23 16:50:31 +02:00
Florian Roth
e1a05dfc1c
Update lnx_auditd_susp_C2_commands.yml
2020-05-23 16:49:03 +02:00
Florian Roth
ee1ca77fad
Merge pull request #771 from gamma37/new_rules
...
Create a new rule to detect "Create Account"
2020-05-23 16:47:46 +02:00
Florian Roth
895c84703f
Merge pull request #790 from EccoTheFlintstone/fp_fix
...
fix false positive matching on every powershell process not run by SY…
2020-05-23 16:47:01 +02:00
ecco
327a53c120
add new test for sysmon rules without eventid
2020-05-23 10:25:37 -04:00
ecco
10ca3006f5
move rule where needed
2020-05-23 10:07:55 -04:00
ecco
2b89e56054
fix test
2020-05-23 10:03:13 -04:00
ecco
d9bc09c38c
fix test
2020-05-23 10:02:58 -04:00
ecco
78a7852a43
renamed dbghelp rule with new ID and comment and removed a false positive
2020-05-23 09:16:40 -04:00
Sander Wiebing
d310805ed9
rule: Netsh RDP port opening
2020-05-23 14:19:52 +02:00
ecco
75ba5f989c
add 1 more FP to wmi load
2020-05-23 07:44:45 -04:00
ecco
9a7f462d79
move renamed bnaries rule to process creation (they made a lot of false positives in sysmon as there was no event id specified in the rule)
2020-05-23 07:17:56 -04:00
ecco
cfde0625f5
fix false positive matching on every powershell process not run by SYSTEM account
2020-05-23 07:05:09 -04:00
Florian Roth
12e1aeaf9f
Merge pull request #788 from Neo23x0/rule-devel
...
refactor: split up rule for CVE-2020-1048 into 2 rules
2020-05-23 09:54:43 +02:00
Florian Roth
46f3a70a7d
Merge pull request #786 from EccoTheFlintstone/perf_fix
...
various rules cleaning (slight perf improvements)
2020-05-23 09:54:28 +02:00
Florian Roth
34006d0794
refactor: simplified and extended expression in CVE-2020-1048 rule
2020-05-23 09:16:19 +02:00
Florian Roth
57c8e63acd
refactore: split up rule for CVE-2020-1048 into 2 rules
2020-05-23 09:09:58 +02:00
ecco
ec17c2ab56
filter on createkey only when needed
2020-05-22 10:37:00 -04:00
4A616D6573
879ad6f206
Update win_susp_ntlm_rdp.yml
2020-05-22 13:32:02 +10:00
4A616D6573
daa3c5e053
Update win_susp_ntlm_rdp.yml
2020-05-22 13:28:56 +10:00
4A616D6573
0f8f5fb29c
Create win_susp_ntlm_rdp.yml
2020-05-22 13:24:27 +10:00
Thomas Patzke
96fae4be68
Added CrachMapExec rules
2020-05-22 00:50:37 +02:00
Florian Roth
64e0e7ca72
Merge pull request #784 from Neo23x0/rule-devel
...
refactor: slightly improved Greenbug rule
2020-05-21 14:19:09 +02:00
Florian Roth
91c4c4ecc5
refactor: slightly improved Greenbug rule
2020-05-21 13:38:11 +02:00
Florian Roth
bbf78374b6
Merge pull request #783 from Neo23x0/rule-devel
...
Greenbug Rule
2020-05-21 09:55:46 +02:00
Florian Roth
9a3b6c1c77
docs: added MITRE ATT&CK group tag
2020-05-21 09:44:11 +02:00
Florian Roth
344eb713c5
rule: Greenbug campaign
2020-05-21 09:39:57 +02:00
Thomas Patzke
8d9b706d6a
Merge pull request #727 from 3CORESec/master
...
Override Features
2020-05-20 19:11:56 +02:00
Florian Roth
e7980bb434
Merge pull request #782 from ZikyHD/patch-1
...
Remove duplicate 'CommandLine' in fields
2020-05-20 12:55:41 +02:00
Florian Roth
af92a5bd2c
Merge pull request #780 from tatsu-i/master
...
Null field check to eliminate false positives
2020-05-20 12:55:29 +02:00
ZikyHD
8963c0a65e
Remove duplicate 'CommandLine' in fields
2020-05-20 11:54:47 +02:00
vh
e8b956f575
Updated config
2020-05-20 12:35:00 +03:00
Florian Roth
9ab65cd1c7
Update win_alert_ad_user_backdoors.yml
2020-05-19 14:50:22 +02:00
Thomas Patzke
04dfe6c5fc
Merge pull request #778 from neu5ron/sigmacs
...
SIGMACs: Winlogbeat & Zeek
2020-05-19 13:18:40 +02:00
Florian Roth
df75bdd3b6
Merge pull request #779 from neu5ron/rules
...
Rules: Zeek
2020-05-19 13:10:56 +02:00
neu5ron
7c3dea22b8
small T, big T
2020-05-19 05:13:48 -04:00
neu5ron
dd382848b4
Merge remote-tracking branch 'neu5ron-sigma/rules' into rules
2020-05-19 05:09:05 -04:00
neu5ron
602c8917ef
domain user enumeration via zeek rpc (dce_rpc) log.
2020-05-19 05:08:26 -04:00
Tatsuya Ito
c815773b1a
enhancement rule
2020-05-19 18:05:51 +09:00
neu5ron
9e272d37b7
zeek category update and minor field updates
2020-05-19 05:02:45 -04:00
Tatsuya Ito
49f68a327a
enhancement rule
2020-05-19 18:00:50 +09:00
neu5ron
177f0a783b
winlogbeat forward (at a snails pace) ECS field names
2020-05-19 04:58:51 -04:00
neu5ron
e975d3fd14
domain user enumeration via zeek rpc (dce_rpc) log.
2020-05-19 04:41:08 -04:00
neu5ron
effb2a8337
add exe webdav download
2020-05-19 04:41:00 -04:00
neu5ron
858ebcd3d3
author typo update
2020-05-19 04:35:47 -04:00
neu5ron
2fc8d513d6
zeek, swap path and name
2020-05-19 04:35:30 -04:00
ecco
0dd089db47
various rules cleaning
2020-05-18 20:29:53 -04:00
Florian Roth
4446c4cd4e
Merge pull request #773 from EccoTheFlintstone/fix_fp
...
add some false positives checks
2020-05-18 21:33:48 +02:00
Florian Roth
4bb44f02e1
Merge pull request #776 from Neo23x0/rule-devel
...
docs: missed the reference
2020-05-18 18:35:30 +02:00
Florian Roth
63238fd661
docs: missed the reference
2020-05-18 18:34:30 +02:00
Florian Roth
482c9e5449
Merge pull request #775 from Neo23x0/rule-devel
...
Godmode Sigma Rule
2020-05-18 17:21:34 +02:00
Florian Roth
8819da51c5
Merge branch 'master' into rule-devel
2020-05-18 17:05:25 +02:00
Florian Roth
08c32c9dfc
rule: godmode rule v0.3
2020-05-18 17:04:59 +02:00
ecco
1aa97fe577
flake 8
2020-05-18 10:03:18 -04:00
ecco
088800cd18
fix rule due to sigmac bug?
2020-05-18 09:39:48 -04:00
ecco
e89613aee0
add some false positives checks
2020-05-18 07:19:06 -04:00
Florian Roth
8154ca355a
Merge pull request #768 from maximelb/master
...
Remove "condition" from global rule in CVE-2020-1048.
2020-05-18 12:52:49 +02:00
Florian Roth
ad50b5f3bb
Merge pull request #769 from jaegeral/patch-2
...
replace --target-list with --lists
2020-05-18 12:50:07 +02:00
Florian Roth
f7ef96c077
Merge pull request #770 from EccoTheFlintstone/various_fix
...
standardize rules with Image and CommandLine instead of NewProcessNam…
2020-05-18 12:49:22 +02:00
gamma37
71c507d8a9
remove space bedore colon
2020-05-18 11:34:53 +02:00
gamma37
55eec46932
Create a rule for "suspicious activities"
2020-05-18 11:25:18 +02:00
gamma37
cbf06b1e43
lowercased tag
2020-05-18 10:11:32 +02:00
gamma37
904716771a
Create a new rule to detect "Create Account"
2020-05-18 10:03:34 +02:00
Alexander J
a7176d4811
replace --target-list with --lists
...
The description in the readme is outdated
````
sigmac --target-list
usage: sigmac [-h] [--recurse] [--filter FILTER]
[--target {kibana,ala-rule,splunk,ala,splunkxml,fieldlist,graylog,es-rule,qualys,arcsight-esm,mdatp,netwitness,arcsight,elastalert-dsl,sql,carbonblack,xpack-watcher,limacharlie,qradar,logiq,powershell,grep,ee-outliers,elastalert,es-qs,es-dsl,logpoint,sumologic}]
[--lists] [--config CONFIG] [--output OUTPUT]
[--backend-option BACKEND_OPTION]
[--backend-config BACKEND_CONFIG] [--defer-abort]
[--ignore-backend-errors] [--verbose] [--debug]
[inputs [inputs ...]]
sigmac: error: unrecognized arguments: --target-list
````
2020-05-18 08:11:16 +02:00
Maxime Lamothe-Brassard
25d3a5a893
Remove "condition" from global rule.
...
The condition field in this rule was in the global section which overwrote the condition in sub-rules and generated FPs. For example, once Sigma read the rule, the bottom sub-rule's "condition" was overwritten with "1 of them".
2020-05-17 12:44:57 -07:00
~noyan
2b72ee7b84
partial(?) fix of #762
2020-05-16 14:51:58 +03:00
Florian Roth
5d1605bba2
Merge pull request #765 from Neo23x0/rule-devel
...
Rule devel
2020-05-16 09:16:19 +02:00
Florian Roth
a46e357874
Merge branch 'master' into rule-devel
2020-05-16 08:59:34 +02:00
Florian Roth
d5e7d4e302
fix: missing condition in CVE-2020-1048 rule
2020-05-16 08:59:05 +02:00
Florian Roth
4e1991cfee
Merge pull request #761 from EccoTheFlintstone/cve-2020-1048-fix
...
fix CVE 2020-1048 rule
2020-05-16 08:58:31 +02:00
ecco
fd386fe8eb
standardize rules with Image and CommandLine instead of NewProcessName and ProcessCommandLine
2020-05-15 12:35:32 -04:00
Florian Roth
7b713fbe7f
rule: OpenSSHd rule adjusted
2020-05-15 17:19:32 +02:00
ecco
0575fa8d81
fix CVE 2020-1048 rule
2020-05-15 07:25:05 -04:00
Florian Roth
b672d7aeb4
Merge pull request #759 from Neo23x0/rule-devel
...
Rule devel
2020-05-15 12:25:46 +02:00
Florian Roth
cc26b26377
Merge branch 'master' into rule-devel
...
# Conflicts:
# rules/windows/sysmon/sysmon_cve-2020-1048.yml
2020-05-15 12:09:47 +02:00
Florian Roth
8e7caf0e4d
rule: CVE-2020-1048
2020-05-15 12:08:31 +02:00
Florian Roth
8e082283f0
Merge pull request #754 from Neo23x0/rule-devel
...
Rule devel
2020-05-15 12:07:04 +02:00
Florian Roth
beb62dc163
fix: condition location
2020-05-15 12:06:34 +02:00
Florian Roth
5854cc4677
fix: small bug in new CVE-2020-1048 rule
2020-05-15 11:37:46 +02:00
Florian Roth
2282432b6f
Merge pull request #753 from hieuttmmo/master
...
New Sigma rule to detect possible CVE-2020-1048 exploitation and Suspicious network connection from Notepad
2020-05-15 11:35:12 +02:00
Florian Roth
28dc2a2267
Minor changes
...
hints:
- contains doesn't require wildcards in the strings
- we can use 'endswith' instead of wildcard at the beginning of the string (it's the new way to describe it, we have to change all old rules that contain these wildcards some day)
- we can use "1 of them" to say that 1 of the conditions has to match
2020-05-15 11:33:36 +02:00
Florian Roth
d8cd396697
Merge pull request #758 from EccoTheFlintstone/fix_fp
...
remove false positives with cmd as child of services.exe (not specifi…
2020-05-15 11:28:05 +02:00
ecco
54cf535dbc
remove false positives with cmd as child of services.exe (not specifically related to meterpreter/cobaltstrike)
2020-05-15 04:45:25 -04:00
Trent Liffick
40ab1b7247
added 'action: global'
2020-05-14 23:33:08 -04:00
Trent Liffick
56a2747a70
Corrected missing condition
...
learning! fail fast & forward
2020-05-14 23:18:33 -04:00
Trent Liffick
fb1d8d7a76
Corrected typo
2020-05-14 23:04:14 -04:00
Trent Liffick
8aff6b412e
added rule for Blue Mockingbird (cryptominer)
2020-05-14 22:58:23 -04:00
Florian Roth
d25b8a0492
docs: remove GPL reference, DRL in README
2020-05-14 15:56:39 +02:00
Florian Roth
ab950fb89d
fix: removed rules missing in master
2020-05-14 15:53:09 +02:00
Tiago Faria
06abd6e76a
added ci tests for ecs-cloudtrail
2020-05-14 14:03:23 +01:00
Tiago Faria
2893becf8c
Merge remote-tracking branch 'upstream/master'
2020-05-14 14:02:20 +01:00
Tran Trung Hieu
e53a97fa2f
Update condition to filter out printer port
2020-05-14 18:22:49 +07:00
Tran Trung Hieu
443bf09d27
Add author
2020-05-14 18:10:16 +07:00
Tran Trung Hieu
e74970cea0
Suspicious network connection from notepad.exe
2020-05-14 18:08:30 +07:00
Tran Trung Hieu
97b690d340
Change level from Critical to High
2020-05-14 09:02:54 +07:00
Thomas Patzke
133319c417
Merge pull request #737 from NVISO-BE/backend-ee-outliers
...
ee-outliers backend
2020-05-13 22:38:02 +02:00
Florian Roth
7652813c2c
Merge pull request #752 from zaphodef/fix/win_susp_script_execution_false_negatives
...
Widen the search as it gives too many false negatives
2020-05-13 21:02:12 +02:00
Tran Trung Hieu
d0b1c98d5a
Reformat rule
2020-05-14 00:39:41 +07:00
Tran Trung Hieu
3e5b33388b
New rule to detect possible CVE-2020-1048 exploitation
2020-05-14 00:24:36 +07:00
zaphod
78a5c743f2
Widen the search as it gives too many false negatives
2020-05-13 16:20:23 +02:00
Florian Roth
78a8266a1b
Merge pull request #749 from teddy-ROxPin/patch-6
...
Create win_advanced_ip_scanner.yml
2020-05-13 14:09:12 +02:00
hieuttmmo
9ad3427d68
Merge pull request #1 from Neo23x0/master
...
Update
2020-05-13 18:36:52 +07:00
Florian Roth
220a14f31c
fix: typo in contains
2020-05-13 12:38:54 +02:00
zaphod
1a598282f4
Add 'Add-Content' to powershell_ntfs_ads_access
2020-05-13 11:57:10 +02:00
Florian Roth
a1856c5743
Update win_advanced_ip_scanner.yml
2020-05-13 11:56:25 +02:00
Florian Roth
904a31103d
Merge pull request #750 from zaphodef/fix/win_bootconf_mod_bad_commandline
...
Fix a bad CommandLine search
2020-05-13 11:55:16 +02:00
zaphod
a9ef7ef382
Fix a bad CommandLine search
2020-05-13 11:32:05 +02:00
teddy_ROxPin
bb17fd74ee
Create win_advanced_ip_scanner.yml
...
Detects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
2020-05-12 21:43:01 -06:00
Florian Roth
e01734fda1
rule: proxy UA hidden cobra
2020-05-12 17:43:54 +02:00
zaphod
d510e1aad4
Fix 'source' value for win_susp_backup_delete
2020-05-11 18:31:59 +02:00
Rettila
6ec74364f2
Create win_global_catalog_enumeration.yml
2020-05-11 17:40:47 +02:00
Rettila
ccacedf621
Merge pull request #3 from Neo23x0/master
...
merge
2020-05-11 17:38:27 +02:00
Florian Roth
37c33cb6d9
Merge pull request #743 from tliffick/master
...
Registry entry for Azorult malware
2020-05-11 16:37:15 +02:00
Remco Hofman
37b08543ac
Updated author reference in license
2020-05-11 11:47:56 +02:00
Florian Roth
1104044f53
fix: delete duplicate rules
2020-05-11 10:55:02 +02:00
Florian Roth
2b18b66c16
Merge branch 'master' into rule-devel
2020-05-11 10:50:10 +02:00
Florian Roth
4366a95024
rule: Maze ransomware
2020-05-11 10:46:26 +02:00
Florian Roth
f96c3a5fd4
Merge branch 'master' into rule-devel
...
# Conflicts:
# rules/proxy/proxy_ua_suspicious.yml
# rules/windows/process_creation/win_install_reg_debugger_backdoor.yml
# rules/windows/process_creation/win_susp_csc_folder.yml
2020-05-11 10:44:19 +02:00
Florian Roth
09d1b00459
Changed level to ciritcal
2020-05-11 10:40:23 +02:00
tliffick
c98be55d21
Update mal_azorult_reg.yml
2020-05-08 21:31:33 -04:00
tliffick
61f061333b
Registry entry for Azorult malware
...
Detects registry keys used by Azorult malware
2020-05-08 21:26:24 -04:00
Remco Hofman
c5c5e1b79b
Added ee-outliers test to Makefile
2020-05-08 17:51:35 +02:00
Florian Roth
fd7968d4f8
Merge pull request #734 from NVISO-BE/win_susp_failed_logon_source
...
New rule: Failed Logon From Public IP
2020-05-08 16:24:12 +02:00
vh
fb9c5841f4
Added Humio, Crowdstrike, Corelight
2020-05-08 13:41:52 +03:00
Florian Roth
64a5ad0d07
Merge pull request #735 from nl5887/master
...
fix incorrect use of action global
2020-05-08 12:20:33 +02:00
Florian Roth
24c0765694
Merge branch 'master' into devel
2020-05-08 12:17:14 +02:00
Florian Roth
7cc1b300d2
rule: maze ransomware patterns
2020-05-08 11:42:06 +02:00
Remco Hofman
dc96b7ffb3
Removed dependency on slugify
2020-05-08 11:40:16 +02:00
Remco Hofman
2d3ee85c46
README updates
2020-05-08 10:40:41 +02:00
Remco Hofman
c5be83eb01
Added ee-outliers backend
2020-05-08 10:18:35 +02:00
Rettila
07a50edf89
Update win_metasploit_authentication.yml
2020-05-07 14:42:00 +02:00
Thomas Patzke
3b96b5e497
Merge pull request #723 from neu5ron/socprime_add_zeek_and_corelight
...
sigmacs for Zeek and Corelight(Zeek)
2020-05-06 23:22:14 +02:00
Remco Verhoef
2d38cb7b52
fix incorrect use of global
2020-05-06 23:00:45 +02:00
Remco Verhoef
40539a0c0e
fix incorrect use of action global
2020-05-06 22:53:02 +02:00
Remco Hofman
123a23adae
win_susp_failed_logon_source rule
2020-05-06 22:24:02 +02:00
Thomas Patzke
1797a1e56b
Merge pull request #733 from NVISO-BE/fix-732
...
Fix for broken endswith modifier
2020-05-06 22:17:08 +02:00
Remco Hofman
24029a8f27
Fix for broken endswith modifier
2020-05-06 17:10:54 +02:00
Rettila
6aed82a039
Update win_metasploit_authentication.yml
2020-05-06 17:04:47 +02:00
Rettila
2beb65076c
Update win_metasploit_authentication.yml
2020-05-06 16:44:19 +02:00
Rettila
7371ce234b
Create win_metasploit_authentication.yml
2020-05-06 16:42:27 +02:00
Rettila
ddb02c6820
Merge pull request #1 from Neo23x0/master
2020-05-06 11:24:26 +02:00
Florian Roth
1ce527c9be
Merge pull request #729 from Rettila/master
...
Rule correction and enhancement
2020-05-05 19:25:49 +02:00
Florian Roth
473c31232e
add additional reference
2020-05-05 19:25:33 +02:00
Rettila
0e1fa5c135
Update win_possible_dc_shadow.yml
2020-05-05 18:14:32 +02:00
Rettila
55d018255c
Update win_possible_dc_shadow.yml
2020-05-05 16:52:08 +02:00
Rettila
3302c63e0c
Update and rename win_possible_dc_sync.yml to win_possible_dc_shadow.yml
2020-05-05 16:51:35 +02:00
Rettila
f27aa4bfee
Update win_possible_dc_sync.yml
2020-05-05 16:50:13 +02:00
Rettila
db810b342f
Delete win_possible_dc_shadow.yml
2020-05-05 16:48:39 +02:00
Rettila
e3f21805f3
Update win_possible_dc_shadow.yml
2020-05-05 16:43:56 +02:00
Rettila
0f4cc9d365
Create win_possible_dc_shadow.yml
2020-05-05 16:40:52 +02:00
pdr9rc
31ad81874f
capitalized titles
...
corrected capitalization of titles and removed literals from config
2020-05-05 11:32:18 +01:00
neu5ron
a01a85cf9b
CI/CD check fixes (missing ID's)
2020-05-04 15:22:18 -04:00
neu5ron
90730508f0
Merge remote-tracking branch 'neu5ron-sigma/socprime_add_zeek_and_corelight' into socprime_add_zeek_and_corelight
2020-05-04 15:17:54 -04:00
neu5ron
a61b1da47a
fixed yaml space causing condition to not be found
2020-05-04 15:17:43 -04:00
neu5ron
98f163e752
fixed yaml space causing condition to not be found
2020-05-04 15:10:48 -04:00
pdr9rc
aa175a7d5b
wip
...
wip
2020-05-04 18:02:27 +01:00
pdr9rc
dd9e128a15
kibana target update
...
kibana target now compatible with overrides
2020-05-04 17:35:12 +01:00
pdr9rc
b32093e734
Merge remote-tracking branch 'upstream/master'
...
Keeping up with the sigmas.
2020-05-04 17:26:51 +01:00
pdr9rc
b3194e66c4
Update base.py
2020-05-04 16:37:36 +01:00
Florian Roth
d298bb5714
Merge pull request #480 from hillu/override-coverage
...
Make coverage binary overridable
2020-05-02 18:50:58 +02:00
Wietze
2b3828730c
Reversed disabling FileDelete
2020-05-02 17:31:50 +01:00
Wietze
e5574e07f2
Disabled FileDelete event (Sysmon 11 - no rules available yet)
2020-05-02 16:21:56 +01:00
Wietze
5abf4cbea9
Reordered fields
2020-05-02 14:46:55 +01:00
Wietze
661108903b
Minor consistency fix
2020-05-02 14:37:37 +01:00
Wietze
46737cbfd3
Improved Microsoft ATP mapping, using Advanced Hunting Schema
...
See https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-schema-reference
2020-05-02 14:31:02 +01:00
Florian Roth
030898ba9c
Merge branch 'master' into override-coverage
2020-05-02 14:22:03 +02:00
Florian Roth
c71e10a7f3
Merge pull request #717 from Karneades/renamedbinary
...
Add netsh to renamed binary rule
2020-05-02 14:12:34 +02:00
Florian Roth
b4b9b0155f
Merge pull request #716 from Karneades/patch-1
...
Add rule to detect wifi creds harvesting using netsh
2020-05-02 14:12:10 +02:00
Florian Roth
7f8baee10d
Merge pull request #720 from 0xThiebaut/specification
...
Update rules to follow the Sigma state specification
2020-05-02 14:11:45 +02:00
neu5ron
d300027848
on behalf of @socprime [SOC Prime Inc.]( https://my.socprime.com/en/tdm/ )
...
add rules for Zeek. This includes Windows Event Channel Security EventID:5145 that have same fields as Zeek SMB
Also, converted some of (MITRE ATT&CK BZAR)[https://github.com/mitre-attack/bzar ] which are Zeek (sensor) scripts.
2020-05-02 07:27:51 -04:00
neu5ron
c66540c029
on behalf of @socprime [SOC Prime Inc.]( https://my.socprime.com/en/tdm/ )
...
create `zeek` folder to store Zeek rules
2020-05-02 07:25:21 -04:00
neu5ron
cbe5af01a1
on behalf of @socprime [SOC Prime Inc.]( https://my.socprime.com/en/tdm/ )
...
add a total of 5 sigmac's (sigma configs) for 3 different backends. full git message to follow in PR.
2020-05-02 07:23:11 -04:00
Tiago Faria
dd85467a27
Update aws_ec2_vm_export_failure.yml
2020-05-02 00:13:55 +01:00
Thomas Patzke
2fafff3278
Fixed: escaping of backslashes before added *
...
Fixes issue #722 .
2020-05-02 00:13:15 +02:00
pdr9rc
bc0a2c7ab9
wip
...
wip
2020-05-01 19:20:05 +01:00
pdr9rc
98391f985a
wip
...
wip
2020-04-30 15:19:38 +01:00
pdr9rc
adcc3766e3
Merge branch 'master' of https://github.com/3CORESec/sigma
2020-04-30 15:08:25 +01:00
pdr9rc
8142244449
wip
...
wip
2020-04-30 15:08:20 +01:00
Tiago Faria
dfdb5b9550
better description and event.outcome
2020-04-29 23:59:26 +01:00
pdr9rc
ac4a2b1f26
wip
...
wip
2020-04-29 22:55:46 +01:00
pdr9rc
9ce84a38e5
overrides section support + one example rule + cloudtrail config
...
ditto
2020-04-29 20:36:45 +01:00
Maxime Thiebaut
4600bf73dc
Update rules to follow the Sigma state specification
...
The [Sigma specification's status component](https://github.com/Neo23x0/sigma/wiki/Specification#status-optional ) states the following:
> Declares the status of the rule:
> - stable: the rule is considered as stable and may be used in production systems or dashboards.
> - test: an almost stable rule that possibly could require some fine tuning.
> - experimental: an experimental rule that could lead to false results or be noisy, but could also identify interesting events.
However the Sigma Rx YAML specification states the following:
> ```yaml
> status:
> type: //any
> of:
> - type: //str
> value: stable
> - type: //str
> value: testing
> - type: //str
> value: experimental
> ```
The specification confuses the `test` and `testing` state. This commit changes the `test` state into the `testing` state which is already used in the code-base:
- [`sigma/sigma-schema.rx.yml`](https://github.com/Neo23x0/sigma/blob/a805d18bbae60d3e4f291c8a18304104ed2e71c7/sigma-schema.rx.yml#L49 )
- [`sigma/tools/sigma/filter.py`](https://github.com/Neo23x0/sigma/blob/f3c60a63099f80296c8750aaba667e98ac71a4f7/tools/sigma/filter.py#L26 )
- [`sigma/tools/sigmac`](https://github.com/Neo23x0/sigma/blob/4e42bebb3480720966a59528cd8482c6271e603c/tools/sigmac#L98 )
Although not modifyable through a PR, the specification should furthermore be updated to use the `testing` state.
2020-04-24 20:50:31 +02:00
Andreas Hunkeler
7d437c2969
Add netsh to renamed binary rule
2020-04-20 17:12:25 +02:00
Andreas Hunkeler
d4e9606266
Improve netsh wifi rule another time due to arg shortcut
2020-04-20 16:40:03 +02:00
Andreas Hunkeler
af498d8a8c
Improve rule to detect argument shortcut in netsh wlan rule
2020-04-20 16:32:25 +02:00
Andreas Hunkeler
ba541c3952
Fix title for new netsh wifi rule
2020-04-20 16:20:45 +02:00
Andreas Hunkeler
d9e5274c9e
Add rule to detect wifi creds harvesting using netsh
2020-04-20 16:14:44 +02:00
Florian Roth
e67dddcc35
rule: PwnDrp access
2020-04-17 08:55:54 +02:00
Florian Roth
514bd8657b
Merge pull request #704 from Iveco/master
...
Detect Ghost-In-The-Logs (disabling/bypassing ETW)
2020-04-14 14:11:27 +02:00
Florian Roth
2e0e170058
Merge pull request #708 from teddy-ROxPin/patch-4
...
Create powershell_create_local_user.yml
2020-04-14 14:11:15 +02:00
Florian Roth
3175a48bdc
Casing
2020-04-14 13:40:34 +02:00
Florian Roth
ecdec93800
Casing
2020-04-14 13:39:58 +02:00
Florian Roth
5cbe008350
Casing
2020-04-14 13:39:22 +02:00
Florian Roth
5ee0808619
Merge pull request #706 from vesche/update_win_susp_netsh_dll_persistence
...
Update win_susp_netsh_dll_persistence.yml
2020-04-14 13:37:53 +02:00
Florian Roth
4f469c0e39
Adjusted level
2020-04-14 13:37:10 +02:00
Florian Roth
8f40c0a1c8
Merge pull request #710 from vesche/update_win_GPO_scheduledtasks
...
Update win_GPO_scheduledtasks.yml
2020-04-14 13:36:17 +02:00
Florian Roth
b2754af46b
Merge pull request #711 from 0xThiebaut/sysmon_registry_persistence_search_order
...
Add Windows Registry Persistence COM Search Order Hijacking
2020-04-14 13:35:56 +02:00
Maxime Thiebaut
86c6891427
Add Windows Registry Persistence COM Search Order Hijacking
2020-04-14 12:59:29 +02:00
vesche
1f918253e8
Add additional reference
2020-04-13 11:09:36 -05:00
vesche
9cdb3a4a64
Fix typo
2020-04-13 11:09:00 -05:00
alm8i
7ac685882c
comments for usage
2020-04-11 15:47:23 +02:00
teddy-ROxPin
1501331f77
Create powershell_create_local_user.yml
...
Adds coverage for creating a local account via PowerShell from https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1136/T1136.md#atomic-test-4---create-a-new-user-in-powershell
2020-04-11 02:51:05 -06:00
Danijel Grah
6312f381bf
C# backend
...
Converts Sigma rule into C# Regex in LINQ query
2020-04-10 16:12:05 +02:00
vesche
3889be6255
Replace reference link for win_susp_netsh_dll_persistence
2020-04-10 01:05:10 -05:00
vesche
82db80bee6
Remove wrong mitre technique
2020-04-10 01:02:43 -05:00
vesche
72b821e046
Update win_susp_netsh_dll_persistence.yml
2020-04-09 11:16:18 -05:00
Iveco
61b9234d7f
Update win_user_driver_loaded.yml
...
removed internal field
2020-04-09 11:28:19 +02:00
Thomas Patzke
1c5c8047fd
Fixes
...
* Removed commented debug print statements
* Defined nullExpression
* Removed unneeded generateMapItemNode method
* Value cleaning bug on matching of wildcard at first character
2020-04-08 23:43:46 +02:00
Thomas Patzke
72c2241bb4
Cleanup
...
* Added CI test
* Added changelog entry
2020-04-08 23:39:38 +02:00
Thomas Patzke
3277cec7aa
Reverted list sorting
...
This was already implemented meanwhile in a previous commit.
2020-04-08 23:23:44 +02:00
Thomas Patzke
cf896c3093
Merge branch 'master' of https://github.com/abhikhnvasara/sigma into pr-630
2020-04-08 23:16:39 +02:00
Thomas Patzke
551a94af04
Merge branch 'master' of https://github.com/tileo/sigma into pr-658
2020-04-08 22:43:48 +02:00
Thomas Patzke
7224af54b2
Merge pull request #664 from j91321/es-rule-options
...
es-rule backend options for index-patterns and time interval
2020-04-08 22:39:45 +02:00
Thomas Patzke
1b7f33f5e2
Fixed undefined value in exception handling
...
Fixes issue #702 .
2020-04-08 22:28:47 +02:00
Iveco
e913db0dca
Update win_user_driver_loaded.yml
...
CI
2020-04-08 18:54:59 +02:00
Iveco
c5211eb94a
Update sysmon_susp_service_installed.yml
...
CI
2020-04-08 18:54:46 +02:00
Iveco
4520082ef7
Update sysmon_susp_procexplorer_driver_created_in_tmp_folder.yml
...
CI
2020-04-08 18:54:37 +02:00
Iveco
6d85650390
Update sysmon_susp_procexplorer_driver_created_in_tmp_folder.yml
...
Fixed Author
2020-04-08 18:41:33 +02:00
Iveco
fc1febdebe
Update sysmon_susp_service_installed.yml
...
Fixed Author
2020-04-08 18:41:25 +02:00
Iveco
d0746b50f4
Update win_user_driver_loaded.yml
...
Fixed author
2020-04-08 18:41:16 +02:00
Iveco
3280a1dfb0
Update sysmon_susp_procexplorer_driver_created_in_tmp_folder.yml
...
Fixed CI
2020-04-08 18:23:29 +02:00
Iveco
5e724a0a54
Update sysmon_susp_service_installed.yml
...
Fixed CI
2020-04-08 18:22:51 +02:00
Iveco
d1b9c0c34a
Update win_user_driver_loaded.yml
...
Fixed CI
2020-04-08 18:21:59 +02:00
iveco
e87f2705a7
Detect Ghost-In-The-Logs (disabling/bypassing ETW)
2020-04-08 18:01:04 +02:00
Florian Roth
f50767c400
Merge pull request #703 from 0xThiebaut/downgrade
...
Update the NTLM downgrade registry paths
2020-04-07 18:13:29 +02:00
Maxime Thiebaut
73a6428345
Update the NTLM downgrade registry paths
...
Recent windows versions rely on the ["MSV1_0" authentication package](https://docs.microsoft.com/en-us/windows/win32/secauthn/msv1-0-authentication-package ). Production environment tests have shown that NTLM downgrade attacks can be performed as detected by this rule although some of the registry keys are located in an "Lsa" subkey ("MSV1_0"). This commit introduces additionnal wildcards to handle these cases to ensure the previous detection rules are still included.
2020-04-07 17:14:45 +02:00
j91321
3470011ac3
Revert time interval, use index values provided by sigmaparser
2020-04-05 20:30:57 +02:00
Thomas Patzke
693830fa83
Merge pull request 659
2020-04-03 23:46:53 +02:00
Florian Roth
2a579a0a1b
Merge pull request #699 from mpavlunin/patch-2
...
Create new rule T1223
2020-04-03 19:32:50 +02:00
Florian Roth
4e3985866b
Update and rename sysmon_win_chm.yml to win_html_help_spawn.yml
2020-04-03 16:50:48 +02:00
mpavlunin
81d0f82272
Create new rule T1223
...
Suspicious Compiled HTML File
2020-04-03 16:56:26 +03:00
Florian Roth
0ea2db8b9e
Merge pull request #484 from hieuttmmo/master
...
New sigma rules to detect new MITRE technique in last update (T1502)
2020-04-03 09:59:36 +02:00
Florian Roth
f4928e95bc
Update powershell_suspicious_profile_create.yml
2020-04-03 09:36:17 +02:00
Florian Roth
c0ab9c5745
Merge pull request #671 from HarishHary/powershell_downgrade_attack
...
Powershell downgrade attack (small improvements)
2020-04-03 09:31:33 +02:00
Florian Roth
6cf0edc076
Merge pull request #685 from teddy-ROxPin/patch-1
...
Typo fix for powershell_suspicious_invocation_generic.yml
2020-04-03 09:30:32 +02:00
Florian Roth
aa73c39a35
Merge pull request #692 from Neo23x0/ci-deploy
...
PyPI deployment via GitHub Actions
2020-04-03 09:29:49 +02:00
Florian Roth
eef8531a72
Merge pull request #697 from refractionPOINT/lc-remove-timeframe
...
Remove generation of LC rules with timeframe.
2020-04-03 09:29:12 +02:00
Maxime Lamothe-Brassard
f92c5e9b18
Remove generation of LC rules with timeframe.
2020-04-02 15:25:30 -07:00
Florian Roth
ee7babd8cb
fix: security vulnerability with pyyaml < 4.2b1
2020-04-02 12:27:53 +02:00
Florian Roth
dec0c108f9
Merge pull request #683 from NVISO-BE/powershell_wmimplant
...
WMImplant detection rule
2020-04-02 11:54:09 +02:00
Florian Roth
1196f8d60f
Merge pull request #695 from cobsec/master
...
Date typos
2020-04-02 10:20:18 +02:00
Chris O'Brien
fe5dbece3d
Date typos...more than I thought...
2020-04-02 10:00:00 +02:00
Chris O'Brien
97c0872c81
Date typo.
2020-04-02 09:53:09 +02:00
Thomas Patzke
0db3bbb097
Merge pull request #693 from Neo23x0/dependabot/pip/pyyaml-5.1
...
Bump pyyaml from 3.13 to 5.1
2020-04-01 23:25:57 +02:00
Florian Roth
af49c24419
Merge pull request #694 from cobsec/master
...
Fixed date typo - by the looks of the commit date the month/date were…
2020-04-01 18:28:14 +02:00
Chris O'Brien
95e0b12d88
Fixed date typo - by the looks of the commit date the month/date were swapped.
2020-04-01 18:18:13 +02:00
Thomas Patzke
13dbb4cdbd
Moved tools into sigma namespace
2020-03-31 23:46:58 +02:00
dependabot[bot]
c9c73bec3f
Bump pyyaml from 3.13 to 5.1
...
Bumps [pyyaml](https://github.com/yaml/pyyaml ) from 3.13 to 5.1.
- [Release notes](https://github.com/yaml/pyyaml/releases )
- [Changelog](https://github.com/yaml/pyyaml/blob/master/CHANGES )
- [Commits](https://github.com/yaml/pyyaml/compare/3.13...5.1 )
Signed-off-by: dependabot[bot] <support@github.com >
2020-03-31 20:40:52 +00:00
Thomas Patzke
2bda0e097f
Merge pull request #691 from Neo23x0/cleanup
...
Cleanup
2020-03-31 22:37:04 +02:00
Thomas Patzke
8c69c7bb02
PyPI deployment via GitHub Actions
2020-03-31 22:36:16 +02:00
Florian Roth
6aba430de6
fix: sigma_uuid occurances
2020-03-31 16:29:58 +02:00
Florian Roth
8e39b09ba5
Merge pull request #690 from cnotin/patch-1
...
Small typo
2020-03-31 16:27:21 +02:00
Clément Notin
18cdddb09e
Small typo
2020-03-31 15:22:00 +02:00
Florian Roth
4d67dff89a
fix: renamed tools to allow for console_scripts list entries
2020-03-31 14:07:34 +02:00
Florian Roth
18e505c458
fix: list_configurations default values
2020-03-31 12:42:02 +02:00
Florian Roth
c82156a3c9
fix: second list_configurations function params
2020-03-31 11:46:05 +02:00
Florian Roth
23ce69eaae
fix: functions parameters outside of main
2020-03-31 11:42:16 +02:00
Florian Roth
bb50571b13
fix: print_verbose scope
2020-03-31 11:35:21 +02:00
Florian Roth
c83b4fd37c
fix: fixing script install for Windows end systems
2020-03-31 11:30:47 +02:00
Florian Roth
536ad78fc2
refactor: following best practices reg main functions in Python
...
https://realpython.com/python-main-function/
2020-03-31 11:30:14 +02:00
Florian Roth
6a70bdb126
Merge pull request #689 from 0xThiebaut/win_ad_enumeration
...
Add AD User Enumeration
2020-03-31 10:56:48 +02:00
Maxime Thiebaut
8dcbfd9aca
Add AD User Enumeration
...
When the "Read all properties" permission of a user object is set to be
audited in the AD, an event of ID 4662 (An operation was performed on an
object) is triggered whenever a property is accessed.
This rule detects these events by flagging any non-machine
`SubjectUserName` (i.e. another user) which accesses an object of the
`User` AD schema class.
Advantages of this rule include the detection of insider-enumeration
through automated tools such as BloodHound or manually through the usage
of the PowerShell ActiveDirectory module. Although this rule qualifies
as a medium severity one, this event could be qualified as high/critical
one if flagged on non-used canary user-accounts.
False positives may include administrators performing the initial
configuration of new users.
2020-03-31 09:40:07 +02:00
Remco Hofman
b791d599ee
Disabled keywords that could cause FPs
2020-03-30 08:53:52 +02:00
Thomas Patzke
d33f4b290d
Dependency cleanup
...
* Consolidated dependencies into main and development (MISP and test
intergrated).
* Splitted Pipfile dependencies into main and development
* Specified compatible dependencies
2020-03-29 22:55:09 +02:00
Thomas Patzke
38a5fe3a29
Removed Travis CI configuration
2020-03-29 22:20:04 +02:00
Florian Roth
f2a2420e24
Merge pull request #687 from Neo23x0/ci-testing
...
Ci testing
2020-03-29 17:25:28 +02:00
Thomas Patzke
4dbe5e2f17
Moved Elasticsearch dependencies to generic dependencies
...
Omitting waiting for Elasticsearch as it should be started at this time.
2020-03-29 15:19:13 +02:00
Thomas Patzke
5e258efbe7
Improved Elasticsearch waiting process
2020-03-29 14:57:34 +02:00
Thomas Patzke
d68b900077
Wait for Elasticsearch before running tests
2020-03-29 14:37:27 +02:00
Thomas Patzke
821a631325
Run Elasticsearch installation as root
2020-03-29 14:00:15 +02:00
Thomas Patzke
fbe40bd1e8
Fixed Elasticsearch test
...
* Splitted into separate action
* Install dependencies
2020-03-29 13:41:03 +02:00
Thomas Patzke
d24c1e2800
CI testing with GitHub Actions
2020-03-29 13:25:04 +02:00
teddy-ROxPin
1a3731f7ae
Typo fix for powershell_suspicious_invocation_generic.yml
...
' - windowstyle hidden ' changed to ' -windowstyle hidden '
2020-03-29 04:16:15 -06:00
Florian Roth
8ea6b12eed
Merge pull request #670 from 0xThiebaut/sysmon_susp_desktop_ini
...
Add "Suspicious desktop.ini Action" rule
2020-03-28 13:34:01 +01:00
Florian Roth
fe5b5a7782
Merge pull request #673 from j91321/rules-minor-fixes
...
Minor fixes to several rules
2020-03-28 13:27:05 +01:00
Florian Roth
5f0250bff5
Merge pull request #669 from 0xThiebaut/winlogbeat-rulename
...
Add Winlogbeat's RuleName field to mapping
2020-03-28 13:20:08 +01:00
Florian Roth
e2b90220a2
Update sysmon_susp_desktop_ini.yml
2020-03-28 13:19:10 +01:00
Florian Roth
bbb10a51f4
Update win_powershell_downgrade_attack.yml
2020-03-28 13:17:58 +01:00
Florian Roth
0e94eb9e86
Update win_powershell_downgrade_attack.yml
2020-03-28 13:12:07 +01:00
Florian Roth
2426b39d83
Merge pull request #678 from justintime/title_collision
...
Eliminate title collision
2020-03-28 12:57:55 +01:00
Florian Roth
597d914b71
Merge pull request #679 from Iveco/master
...
add LDAPFragger detections
2020-03-28 12:57:33 +01:00
Remco Hofman
f52ed4150d
WMImplant parameter detection
2020-03-27 15:08:35 +01:00
Iveco
55258e1799
Title capitalized
2020-03-26 17:04:08 +01:00
Iveco
3f577c98e7
Title capalized
2020-03-26 17:03:33 +01:00
Iveco
68c20dca20
Fixed title length
2020-03-26 16:56:46 +01:00
Iveco
39a3af04ce
Fixed title length
2020-03-26 16:56:06 +01:00
Justin Ellison
dabc759136
Eliminate title collision
...
Fixing the problem described in HELK here: https://github.com/Cyb3rWard0g/HELK/issues/442 where when running sigmac to generate elastalert rules, this rule has a title collision with another rule in the same directory and causes elastalert to fail to start.
2020-03-26 09:13:52 -05:00
iveco
ddacde9e6b
add LDAPFragger detections
2020-03-26 15:13:36 +01:00
Florian Roth
0e973d1454
Merge pull request #677 from Neo23x0/devel
...
Devel
2020-03-25 19:14:03 +01:00
Florian Roth
28953a2942
fix: MITRE tags in rule
2020-03-25 18:11:04 +01:00
Florian Roth
6584729a0d
rule: powershell downloadfile
2020-03-25 14:58:14 +01:00
Florian Roth
e206cbda7f
Merge pull request #676 from Neo23x0/devel
...
Devel
2020-03-25 14:54:56 +01:00
Florian Roth
35e43db7a7
fix: converted CRLF line break to LF
2020-03-25 14:36:34 +01:00
Florian Roth
17297193c7
Merge branch 'master' into devel
2020-03-25 14:18:11 +01:00
Florian Roth
0e1ff440db
fix: updated MITRE tags in test
2020-03-25 14:04:22 +01:00
Florian Roth
50b0d04ee8
rule: Exploited CVE-2020-10189 Zoho ManageEngine
2020-03-25 14:02:53 +01:00
Florian Roth
28d8b87a0f
rule: extended web shell spawn rule
2020-03-25 14:02:39 +01:00
Thomas Patzke
004eaf0615
Revert "do not escape u"
...
This reverts commit aa112cbd44 .
This was a fix for a previous bug.
2020-03-24 23:36:12 +01:00
j91321
1d86e0b4a5
Change falsepositives to array
2020-03-24 19:59:54 +01:00
j91321
c784adb10b
Wrong indentation falsepositives
2020-03-24 19:55:41 +01:00
j91321
98a633e54c
Add missing status and falsepositives
2020-03-24 19:53:41 +01:00
j91321
3c74d8b87d
Add correct Source to detection to avoid FP
2020-03-24 19:49:24 +01:00
j91321
bc442d3021
Add path with lowercase system32
2020-03-24 19:48:24 +01:00
j91321
78bfa950d7
Add WinPrvSE.exe to detection
2020-03-24 19:47:10 +01:00
Thomas Patzke
5ea623506f
Merge pull request #667 from opflep/master
...
Upgrade CarbonBlack backend
2020-03-22 00:24:57 +01:00
Thomas Patzke
c10332b06c
Merge pull request #663 from neu5ron/updates_sigmac_and_rules
...
Updates sigmac and rules
2020-03-22 00:22:31 +01:00
Harish SEGAR
ba3994f319
Fix of '1 of x' condition
2020-03-21 12:19:01 +01:00
Harish SEGAR
81b277ba1a
suspicious powershell parent process...
2020-03-21 00:26:30 +01:00
Harish SEGAR
a88b22a1bd
Fix namefield.
2020-03-20 23:34:15 +01:00
Harish SEGAR
67694e4ba7
Restructure new improvement to process_creation folder.
2020-03-20 23:29:32 +01:00
Harish SEGAR
b9a916ceb4
Removed useless condition.
2020-03-20 22:50:26 +01:00
Harish SEGAR
30fac9545a
Fixed author field.
2020-03-20 22:49:07 +01:00
Harish SEGAR
1f251cec07
Added missing action field
2020-03-20 22:46:19 +01:00
Harish SEGAR
293018a9e7
Added conditions...
2020-03-20 22:33:14 +01:00
Harish SEGAR
74b81120e4
Usage of value modifiers...
2020-03-20 22:03:48 +01:00
Harish SEGAR
b129f09fee
Improvement detection on downgrade of powershell
2020-03-20 21:48:19 +01:00
Maxime Thiebaut
dce18b23b7
Add "Suspicious desktop.ini Action" rule
2020-03-19 21:43:03 +01:00
Maxime Thiebaut
c5bdd18d8d
Add Winlogbeat's RuleName field to mapping
...
When Sysmon logs a "RegistryEvent" event of ID 13, the event might contain a field named "RuleName" as shown in the following excerpt.
```xml
<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<Events>
<Event
xmlns='http://schemas.microsoft.com/win/2004/08/events/event '>
<System>
<Provider Name='Microsoft-Windows-Sysmon' Guid='{5770385f-c22a-43e0-bf4c-06f5698ffbd9}'/>
<EventID>13</EventID>
<Version>2</Version>
<Level>4</Level>
<Task>13</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime='2020-03-18T03:52:07.173448000Z'/>
<EventRecordID>160631</EventRecordID>
<Correlation/>
<Execution ProcessID='2156' ThreadID='3628'/>
<Channel>Microsoft-Windows-Sysmon/Operational</Channel>
<Computer>win10.sec699-40.lab</Computer>
<Security UserID='S-1-5-18'/>
</System>
<EventData>
<Data Name='RuleName'>Context,ProtectedModeExitOrMacrosUsed</Data>
<Data Name='EventType'>SetValue</Data>
<Data Name='UtcTime'>2020-03-18 03:52:07.129</Data>
<Data Name='ProcessGuid'>{36aa6401-9acb-5e71-0000-0010e3ed6803}</Data>
<Data Name='ProcessId'>5064</Data>
<Data Name='Image'>C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE</Data>
<Data Name='TargetObject'>HKU\S-1-5-21-1850752718-2055233276-2633568556-1126\Software\Microsoft\Office\16.0\Word\Security\Trusted Documents\TrustRecords\%USERPROFILE%/Documents/sec699.docm</Data>
<Data Name='Details'>Binary Data</Data>
</EventData>
</Event>
</Events>
```
When used in combination with Elastic's Winlogbeat, the resulting field is named `winlog.event_data.RuleName`.
This commit introduces a mapping between the Sigma `RuleName` field (pre-existing in the `arcsight.yml` config) and Elastic's `winlog.event_data.RuleName`.
The presence of this field could be leveraged to build Sigma rules detecting events such as the above where a malicious macro was executed.
2020-03-19 19:40:18 +01:00
Florian Roth
6040b1f1f8
Merge pull request #668 from Neo23x0/devel
...
Devel
2020-03-19 18:36:31 +01:00
vunx2
be6519e35d
merge
2020-03-19 11:07:39 +07:00
vunx2
1025930e04
merge
2020-03-19 11:05:52 +07:00
vunx2
c627f6b381
merge
2020-03-19 11:02:10 +07:00
vunx2
2107d86900
merge
2020-03-19 10:58:30 +07:00
vunx2
f3e642f340
merge
2020-03-19 10:54:48 +07:00
vunx2
b9e9408d34
Merge branch 'master' of https://github.com/Neo23x0/sigma
2020-03-19 10:51:37 +07:00
vunx2
0356178c50
eventdict
2020-03-19 10:49:40 +07:00
vunx2
1b12a6b261
modified: tools/sigma/backends/carbonblack.py
2020-03-19 09:00:24 +07:00
neu5ron
aa112cbd44
do not escape u
2020-03-18 08:51:38 -04:00
neu5ron
17318b48bf
- fix agg_option keyword
...
- remove (now) unnecessary other hardcoded `.keyword` locations
2020-03-18 08:50:37 -04:00
vunx2
e228d42b97
clean IP subnet
2020-03-18 16:49:44 +07:00
vunx2
1df5620a14
fix cleanValue + leading wildcard + EventID Intergration
2020-03-18 16:02:44 +07:00
Florian Roth
8454f60a8e
fix: reduced level due to false positives
2020-03-17 20:40:28 +01:00
Florian Roth
4fb42ffaf7
docs: changed wording in license
2020-03-17 20:38:42 +01:00
j91321
f0c83ae3b4
Added es-rule backend options
2020-03-15 13:03:20 +01:00
neu5ron
b575df8cd7
use the taxonomy for http response which is sc-status
2020-03-14 15:02:33 -04:00
neu5ron
4cd99e71bf
use the taxonomy which states to use c-uri instead of c-uri-path
2020-03-14 15:02:06 -04:00
neu5ron
4c94906d53
rule should be wildcard AND had a prepended ^ in one of the CommandLine conditions that would have caused to not trigger
2020-03-14 15:00:42 -04:00
neu5ron
4b572f3ccb
newline in description - typo
2020-03-14 14:58:58 -04:00
neu5ron
d212d43acf
spelling
2020-03-14 14:58:25 -04:00
neu5ron
58ac26e531
more ECS to sigmac taxonomy for web/proxy
2020-03-14 14:57:38 -04:00
neu5ron
213cf895b9
Merge remote-tracking branch 'neu5ron-sigma/elastic-keyword_and_analyzed' into elastic-keyword_and_analyzed
2020-03-11 11:40:17 -04:00
neu5ron
55bf39a2ac
keyword, analyzed field, case insensitivity
2020-03-11 11:38:56 -04:00
neu5ron
398e4527ea
keyword, analyzed field, case insensitivity
2020-03-11 11:29:05 -04:00
Florian Roth
cbf0f43934
Merge pull request #655 from msec1203/msec1203-patch-1
...
add rule for suspicious use of csharp console by scripting utility
2020-03-09 18:01:12 +01:00
Florian Roth
6845fa21b3
fix: fixed several issues
2020-03-09 17:43:16 +01:00
Florian Roth
8a2033aaf9
Merge pull request #657 from EccoTheFlintstone/fix_registry
...
sysmon registry events fix
2020-03-09 17:38:58 +01:00
David Szili
0947538228
MDATP schema changes
...
WDATP was renamed to MDATP (Microsoft Defendre ATP).
MDATP also had schema changes recently: https://techcommunity.microsoft.com/t5/microsoft-defender-atp/advanced-hunting-data-schema-changes/ba-p/1043914
The updates reflect these changes
2020-03-09 17:12:41 +01:00
ecco
2489b8534c
sysmon registry events fix
2020-03-09 12:02:04 -04:00
Florian Roth
c4671f2225
docs: coverage illustration
2020-03-08 13:06:35 +01:00
msec1203
f833407265
Initial upload
2020-03-08 19:06:10 +09:00
Florian Roth
3c3917c1d5
Merge pull request #654 from Neo23x0/devel
...
Minor changes
2020-03-07 11:20:45 +01:00
Florian Roth
ddefb3bc58
Merge branch 'master' into devel
2020-03-07 11:06:25 +01:00
Florian Roth
54d3706a7f
docs: removed outdated section from info graphic
2020-03-07 11:05:53 +01:00
Florian Roth
07914c2783
Merge pull request #652 from 2XXE-SRA/patch-1
...
MMC Lateral Movement Rule 1
2020-03-07 11:02:16 +01:00
Florian Roth
2e184382f5
fix: eventid in process_creation rules
2020-03-07 10:43:47 +01:00
Florian Roth
60279c7501
Merge pull request #610 from axi0m/patch-1
...
Update proxy_raw_paste_service_access.yml
2020-03-07 10:39:56 +01:00
Florian Roth
7e8b59abe6
Merge pull request #643 from grumo35/patch-2
...
Update sysmon_cred_dump_tools_dropped_files.yml
2020-03-07 10:39:35 +01:00
Florian Roth
c609de4f27
Merge pull request #648 from NVISO-BE/patch-azure-ad-replication
...
Exclude Azure AD sync accounts from AD Replication rule
2020-03-07 10:39:04 +01:00
Florian Roth
b040c129be
fix: author field starting with an '@' symbol
2020-03-07 10:38:02 +01:00
Abhijit Khinvasara
07b553daa1
Merge branch 'master' of github.com:abhikhnvasara/sigma
2020-03-04 15:22:17 -08:00
Abhijit Khinvasara
46bc843e51
sort the list of backends presented in sigmac help
2020-03-04 15:21:28 -08:00
Abhijit Khinvasara
6a1f97b69e
Merge branch 'master' of github.com:abhikhnvasara/sigma
2020-03-04 15:11:18 -08:00
Abhijit Khinvasara
9cb395823c
Rework according to review comments.
2020-03-04 14:54:49 -08:00
2XXE (SRA)
ae56db97ff
mmc lateral movement detection 1
...
see https://github.com/Neo23x0/sigma/issues/576
2020-03-04 14:57:41 -05:00
Florian Roth
02d256b3b6
Merge pull request #651 from EccoTheFlintstone/fix_sysmon_registry
...
fix sysmon registry rules with HKLM/HKU format as used since 02/2017 in sysmon
2020-03-04 20:25:11 +01:00
ecco
b9e4734087
fix sysmon registry rules with HKLM/HKU format as used since 02/2017 in sysmon
2020-03-04 12:47:42 -05:00
Florian Roth
6bbb166f3d
rule: extended webshell rule with tomcat.exe
2020-03-04 14:25:57 +01:00
Florian Roth
53278c2a46
Merge pull request #649 from Neo23x0/devel
...
fix: avoiding FPs with Citrix software
2020-03-03 11:35:02 +01:00
Florian Roth
f98ad7a8df
fix: wrong identifier
2020-03-03 11:25:02 +01:00
Florian Roth
be4242aca8
fix avoiding FPs with MpCmdRun
...
ParentImage: C:\Windows\System32\services.exe
CommandLine: C:\Program Files\Microsoft Security Client\\MpCmdRun.exe
2020-03-03 11:16:59 +01:00
Florian Roth
7139bfb0cb
fix: avoiding FPs with Citrix software
...
writing C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\__PSScriptPolicyTest_r23phtye.jsp.ps1
2020-03-03 11:01:42 +01:00
vunx2
b070ffab74
Merge branch 'master' of https://github.com/Neo23x0/sigma
2020-03-03 10:08:31 +07:00
Remco Hofman
d4b5dd5749
Exclude Azure AD sync accounts from AD Replication rule
2020-03-02 16:43:20 +01:00
Thomas Patzke
b63889af75
Fixed rules that likely will cause false negatives by fix
2020-03-01 23:14:53 +01:00
Thomas Patzke
01bd5cf0e0
Merge branch 'issue-645'
2020-03-01 22:41:13 +01:00
Thomas Patzke
0a62b8747e
Merge pull request #634 from EccoTheFlintstone/fp_fix3
...
Rule: restore initial behaviour matching single word with spaces on each side
2020-03-01 22:40:24 +01:00
Thomas Patzke
a0f7da8c03
Splunk XML backend rule title
...
Fixes #645
2020-03-01 22:23:35 +01:00
Florian Roth
a557c727dd
Merge pull request #644 from Neo23x0/devel
...
Devel
2020-02-29 16:17:12 +01:00
Florian Roth
19d383989c
fix: keyword expression in rule
2020-02-29 16:03:31 +01:00
Florian Roth
15a400ac51
fix: fixing bug in rule
2020-02-29 15:51:00 +01:00
Florian Roth
fa6458b70f
rule: two rules to detect CVE-2020-0688 exploitation
2020-02-29 15:45:45 +01:00
Florian Roth
fdcba84fc8
fix: escaped backslash
2020-02-29 10:12:59 +01:00
grumo35
0d932810b5
Update sysmon_cred_dump_tools_dropped_files.yml
...
Adding sysinternal's procdump utility more about this on : https://en.hackndo.com/remote-lsass-dump-passwords/
2020-02-28 15:16:18 +01:00
vunx2
58f5fa1b8e
change to github
2020-02-28 16:56:48 +07:00
vunx2
139600009b
conflict
2020-02-28 16:50:30 +07:00
Florian Roth
9e86170d79
Merge pull request #641 from NVISO-BE/web_exchange_cve_2020_0688_exploit
...
CVE 2020-0688 Exploit attempt rule
2020-02-27 13:34:05 +01:00
Remco Hofman
4f45e14a56
Match on c-uri instead of c-uri-path
2020-02-27 13:23:25 +01:00
Remco Hofman
ff35eb0052
Title capitalization
2020-02-27 12:56:56 +01:00
Remco Hofman
72e34d2aa5
CVE 2020-0688 Exploit attempt rule
2020-02-27 12:51:10 +01:00
Florian Roth
f88225dd2a
Merge pull request #640 from Neo23x0/devel
...
fix: broader exclusion for rule - OneDrive false positives
2020-02-26 18:41:52 +01:00
Florian Roth
6bbd80a8ee
fix: broader exclusion for rule - OneDrive false positives
2020-02-26 18:31:58 +01:00
Florian Roth
ada0edb822
Merge pull request #621 from wagga40/new_koadic_rule
...
New Koadic detection rule
2020-02-26 13:25:03 +01:00
Florian Roth
0ba6874645
Merge pull request #638 from Neo23x0/devel
...
Several false positives with new rules
2020-02-26 09:46:02 +01:00
Florian Roth
ca2cc87f0c
fixed regex syntax to wildcard syntax
2020-02-26 09:43:29 +01:00
Florian Roth
1c90d6badd
level increased
2020-02-26 09:42:31 +01:00
Florian Roth
c8afd4a16b
Merge pull request #637 from tjgeorgen/patch-1
...
fix missing status & description in status field
2020-02-26 09:40:55 +01:00
Florian Roth
031e6d3ee6
Merge pull request #635 from EccoTheFlintstone/fix_fp4
...
wmiprvse subprocess: add fallback check on username instead of only l…
2020-02-26 09:40:34 +01:00
Florian Roth
4f3e3166d3
fixing false positives
2020-02-26 09:33:55 +01:00
Florian Roth
82d2b1e6f0
Merge branch 'master' into devel
...
# Conflicts:
# rules/windows/process_creation/win_susp_squirrel_lolbin.yml
2020-02-26 09:27:48 +01:00
Florian Roth
e7aff17e72
FP: OneDrive setup
2020-02-26 09:26:19 +01:00
Tom Georgen
74f3fe70cc
fix missing status & description in status field
2020-02-25 16:30:41 -05:00
Florian Roth
8f7ee21d5c
docs: detection rule license
2020-02-25 11:09:10 +01:00
ecco
3247d5692a
wmiprvse subprocess: add fallback check on username instead of only logonid
2020-02-24 09:25:20 -05:00
ecco
df7356e829
Rule: restore initial behaviour matching single word with spaces on each side
2020-02-24 08:00:06 -05:00
Abhijit Khinvasara
8ad346362c
remove print statements.
2020-02-22 20:59:56 -08:00
Abhijit Khinvasara
612df1666b
add LOGIQ backend.
2020-02-22 20:50:30 -08:00
Florian Roth
ab1dda7685
fix: non-ascii rule
2020-02-21 16:21:39 +01:00
Wagga
b9c745a1b2
New Koadic detection rule
2020-02-16 16:48:49 +01:00
vunx2
d0e9af171f
cleanIPRange
2020-02-06 17:20:52 +07:00
vunx2
627f46abc2
backslash fix
2020-02-06 16:28:27 +07:00
vunx2
bc4c6ce8db
cleanValue
2020-02-06 11:02:22 +07:00
vunx2
19d9e4856e
clean Value + config
2020-02-05 17:47:35 +07:00
vunx2
579e7481c7
cleanValue + eventID list
2020-02-04 18:14:40 +07:00
Kevin Dienst
98471bc53c
Update proxy_raw_paste_service_access.yml
...
Add another paste provider website, ghostbin.co to the list. Note that saved pastes generate pseudo random 5 character strings before being suffixed with `/raw` at the end of the URL. e.g. `https://ghostbin.co/paste/y4e9a/raw `
Thus, I've added a regex match between /paste and /raw. I'm unsure if this is supported, I skimmed the Sigma specification wiki but didn't see anything other than that contains adds '*' to end and beginning of each selection. If this regex isn't going to work then I'd imagine we just have to remove the `.+/raw/` from the URI.
2020-02-03 07:29:42 -06:00
vunx2
2930df17d6
update sigma
2020-02-03 09:47:06 +07:00
Lep
60997b47b2
moreEventID
2019-11-28 21:34:52 +07:00
Lep
412dfc4f05
Merge branch 'master' of http://git.security.fis.vn/VuNX2/sigma
2019-11-28 17:38:57 +07:00
Lep
738008b52b
requiment
2019-11-28 17:38:05 +07:00
Nguyen Xuan Vu
042d078ee1
Update requirements.txt
2019-11-28 05:26:09 -05:00
Lep
158ffd2f0c
requiment
2019-11-28 17:23:05 +07:00
Nguyen Xuan Vu
f1ae6fa1ed
Update README.md
2019-11-28 04:56:05 -05:00
Nguyen Xuan Vu
6ce5a2554f
Update README.md
2019-11-28 04:41:58 -05:00
Nguyen Xuan Vu
1fcdf6e5d0
Update README.md
2019-11-28 04:40:52 -05:00
Nguyen Xuan Vu
cd1866b30f
Update README.md
2019-11-28 04:38:03 -05:00
Nguyen Xuan Vu
6fa6cba16d
Update README.md
2019-11-28 04:32:34 -05:00
Nguyen Xuan Vu
31cf40e0e8
Update README.md
2019-11-28 04:31:52 -05:00
Nguyen Xuan Vu
2da7f36e48
Update README.md
2019-11-28 04:31:04 -05:00
Lep
37257170dd
postAPI
2019-11-28 16:01:24 +07:00
Lep
d08ff35222
postAPI
2019-11-28 11:45:49 +07:00
4A616D6573
c8e5fc4e6d
Revert "Create win_susp_local_anon_logon_created.yml"
...
This reverts commit d174e172b0 .
2019-10-31 21:49:57 +11:00
4A616D6573
d174e172b0
Create win_susp_local_anon_logon_created.yml
2019-10-31 21:44:47 +11:00
hieuttmmo
0c07c5ea16
convention
2019-10-25 11:00:05 +07:00
hieuttmmo
e86ab608f2
Update powershell_suspicious_profile_create.yml
2019-10-25 10:53:21 +07:00
hieuttmmo
edb698c7f7
Update powershell_suspicious_profile_create.yml
2019-10-25 00:28:11 +07:00
hieuttmmo
73b10807d8
Rename powershell_susp_profile_create.yml to powershell_suspicious_profile_create.yml
2019-10-25 00:14:39 +07:00
hieuttmmo
0e4cd397ef
Create new rules for T1502
2019-10-25 00:14:21 +07:00
4A616D6573
fdbdca003b
Create win_powershell_web_request.yml
...
Broader rule for detecting web requests via various methods using Windows PowerShell, slightly crosses over the below rules but caters for different methods:
https://github.com/Neo23x0/sigma/blob/99b15edf8add183543ca5738ec93f87416c34bd9/rules/windows/process_creation/win_powershell_download.yml
https://github.com/Neo23x0/sigma/blob/0fa914139ca85966b49f0a8eda40a3f26608e86b/rules/windows/powershell/powershell_suspicious_download.yml
2019-10-24 11:57:37 +11:00
Hilko Bengen
d759896e07
Make coverage binary overridable
...
This makes it possible to pass a different coverage program to make
test, e.g.:
make test COVERAGE=python3-coverage
2019-10-23 15:42:25 +02:00
gsanm
150afd816d
IP Clean
2019-10-22 17:49:50 +07:00
lep
1c5816b214
update carbonblack module
2019-10-18 17:51:31 +07:00
lep
7219e0b0f1
module carbonblack
2019-10-18 14:04:38 +07:00
Florian Roth
afcbf4226d
fix: duplicate rule - issue #441
2019-09-06 10:22:27 +02:00
Florian Roth
e85c204404
fix: removed event id
2019-09-06 10:20:36 +02:00
Florian Roth
01d5e3882f
fix: log source category
2019-09-06 10:17:32 +02:00
Florian Roth
e9fc8d3d09
rule: split up registry debugger registration rule into two
2019-09-06 10:13:21 +02:00
Florian Roth
27f875755f
rule: debugger registration
2019-09-06 10:08:09 +02:00
Florian Roth
c81d3bf56c
rule: emissary panda activity
2019-09-03 15:31:25 +02:00
Florian Roth
d9606067a6
rule: MuddyWater script execution
2019-08-31 08:50:59 +02:00
Florian Roth
a3349823e5
rule: implant teardown
2019-08-30 11:48:51 +02:00
Florian Roth
8a078b6c86
rule: APT28 UA
2019-08-30 11:48:38 +02:00
Lep
dfe6b968c0
addins
2019-08-29 15:48:42 +07:00
Lep
af264c049b
end space
2019-08-29 15:43:36 +07:00
Lep
c95a17b061
process_creation
2019-08-28 17:30:13 +07:00
Lep
ba30b4929c
process_creation update
2019-08-28 17:13:54 +07:00
Florian Roth
f2c44c80b6
Merge branch 'master' into rule-devel
...
# Conflicts:
# rules/windows/process_creation/win_encoded_frombase64string.yml
# rules/windows/process_creation/win_susp_csc_folder.yml
2019-08-28 09:21:25 +02:00
Florian Roth
f71dc41531
rule: extended csc rule
2019-08-28 09:00:43 +02:00
Florian Roth
406b40af11
rule: suspicious msbuild folder
2019-08-28 09:00:35 +02:00
Lep
8b6bd45b0b
rules for APT32
2019-08-28 10:12:01 +07:00
Florian Roth
1dfd560299
rule: csc.exe suspicious source folder
2019-08-24 13:49:40 +02:00
Florian Roth
a137a1380b
rules: encoded FromBase64String keyword
2019-08-24 12:38:51 +02:00
Florian Roth
c9a4e6fe8a
rule: process creations in env var folders
2019-08-24 08:26:37 +02:00