Cleanup selection name

This commit is contained in:
frack113 2021-10-10 10:17:24 +02:00
parent 2379907f26
commit 1337116d84
8 changed files with 17 additions and 17 deletions

View File

@ -19,21 +19,21 @@ logsource:
service: powershell
definition: PowerShell Module Logging must be enabled
detection:
selection_4:
selection_id:
EventID: 4103
selection_5:
selection_payload_1:
Payload|contains:
- 'del'
- 'Remove-Item'
- 'rm'
Payload|contains|all:
- '(Get-PSReadlineOption).HistorySavePath'
selection_6:
selection_payload_2:
Payload|contains|all:
- 'Set-PSReadlineOption'
- 'HistorySaveStyle'
- 'SaveNothing'
condition: selection_4 and ( selection_5 or selection_6 )
condition: selection_id and ( selection_payload_1 or selection_payload_2 )
falsepositives:
- Legitimate PowerShell scripts
level: medium

View File

@ -19,10 +19,10 @@ logsource:
service: powershell
definition: PowerShell Module Logging must be enabled
detection:
selection2:
selection_4103:
EventID: 4103
Payload|contains: 'Expand-Archive'
condition: selection2
condition: selection_4103
falsepositives:
- unknown
level: informational

View File

@ -19,10 +19,10 @@ logsource:
service: powershell
definition: PowerShell Module Logging must be enabled
detection:
selection2:
selection_4103:
EventID: 4103
Payload|contains: 'Get-Clipboard'
condition: selection2
condition: selection_4103
falsepositives:
- unknown
level: medium

View File

@ -19,9 +19,9 @@ logsource:
service: powershell
definition: PowerShell Module Logging must be enabled
detection:
selection_3:
selection_id:
EventID: 4103
selection_4:
selection_payload:
- Payload|re: '\$PSHome\[\s*\d{1,3}\s*\]\s*\+\s*\$PSHome\['
- Payload|re: '\$ShellId\[\s*\d{1,3}\s*\]\s*\+\s*\$ShellId\['
- Payload|re: '\$env:Public\[\s*\d{1,3}\s*\]\s*\+\s*\$env:Public\['
@ -29,7 +29,7 @@ detection:
- Payload|re: '\\\\*mdr\\\\*\W\s*\)\.Name'
- Payload|re: '\$VerbosePreference\.ToString\('
- Payload|re: '\String\]\s*\$VerbosePreference'
condition: selection_3 and selection_4
condition: selection_id and selection_payload
falsepositives:
- Unknown
level: high

View File

@ -16,12 +16,12 @@ logsource:
service: powershell
definition: Script block logging must be enabled
detection:
selection2:
selection:
EventID: 4104
ScriptBlockText|contains:
- 'CL_Invocation.ps1'
- 'SyncInvoke'
condition: selection2 | count(ScriptBlockText) by Computer > 2
condition: selection | count(ScriptBlockText) by Computer > 2
# PS > Import-Module c:\Windows\diagnostics\system\Audio\CL_Invocation.ps1
# PS > SyncInvoke c:\Evil.exe
falsepositives:

View File

@ -16,12 +16,12 @@ logsource:
service: powershell
definition: Script block logging must be enabled
detection:
selection2:
selection:
EventID: 4104
ScriptBlockText|contains:
- 'CL_Mutexverifiers.ps1'
- 'runAfterCancelProcess'
condition: selection2 | count(ScriptBlockText) by Computer > 2
condition: selection | count(ScriptBlockText) by Computer > 2
# PS > Import-Module c:\Windows\diagnostics\system\Audio\CL_Mutexverifiers.ps1
# PS > runAfterCancelProcess c:\Evil.exe
falsepositives:

View File

@ -23,7 +23,7 @@ detection:
ScriptBlockText|contains:
- MSAcpi_ThermalZoneTemperature
- Win32_ComputerSystem
condition: all of selection_*
condition: all of them
falsepositives:
- Unknown
level: medium

View File

@ -28,7 +28,7 @@ detection:
- '-Namespace root/subscription '
- '-ClassName CommandLineEventConsumer '
- '-Property ' #is a variable name
condition: all of them
condition: selection_id and selection_ioc
falsepositives:
- Unknown
level: medium