mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
commit
6780182c37
@ -15,3 +15,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- unknown
|
- unknown
|
||||||
level: high
|
level: high
|
||||||
|
tags:
|
||||||
|
- attack.command_and_control
|
||||||
|
- attack.t1219
|
@ -17,4 +17,7 @@ detection:
|
|||||||
condition: selection
|
condition: selection
|
||||||
falsepositives:
|
falsepositives:
|
||||||
- unlikely
|
- unlikely
|
||||||
level: high
|
level: high
|
||||||
|
tags:
|
||||||
|
- attack.execution
|
||||||
|
- attack.t1059
|
@ -20,3 +20,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- unlikely
|
- unlikely
|
||||||
level: high
|
level: high
|
||||||
|
tags:
|
||||||
|
- attack.execution
|
||||||
|
- attack.t1059
|
@ -23,3 +23,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Some rare backup scenarios
|
- Some rare backup scenarios
|
||||||
level: medium
|
level: medium
|
||||||
|
tags:
|
||||||
|
- attack.impact
|
||||||
|
- attack.t1490
|
@ -21,3 +21,6 @@ fields:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Unlikely
|
- Unlikely
|
||||||
level: critical
|
level: critical
|
||||||
|
tags:
|
||||||
|
- attack.impact
|
||||||
|
- attack.t1490
|
@ -17,3 +17,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Some rare backup scenarios
|
- Some rare backup scenarios
|
||||||
level: medium
|
level: medium
|
||||||
|
tags:
|
||||||
|
- attack.impact
|
||||||
|
- attack.t1490
|
@ -20,3 +20,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Unknown
|
- Unknown
|
||||||
level: high
|
level: high
|
||||||
|
tags:
|
||||||
|
- attack.defense_evasion
|
||||||
|
- attack.t1055
|
@ -21,3 +21,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Legitimate use by administrative staff
|
- Legitimate use by administrative staff
|
||||||
level: high
|
level: high
|
||||||
|
tags:
|
||||||
|
- attack.initial_access
|
||||||
|
- attack.t1133
|
@ -24,3 +24,6 @@ fields:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Administrative scripts
|
- Administrative scripts
|
||||||
level: medium
|
level: medium
|
||||||
|
tags:
|
||||||
|
- attack.defense_evasion
|
||||||
|
- attack.t1055
|
@ -29,3 +29,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- Unknown
|
- Unknown
|
||||||
level: high
|
level: high
|
||||||
|
tags:
|
||||||
|
- attack.persistence
|
||||||
|
- attack.t1547.001
|
@ -25,4 +25,6 @@ detection:
|
|||||||
falsepositives:
|
falsepositives:
|
||||||
- "Administrators or users that actually use the selected keyboard layouts (heavily depends on the organisation's user base)"
|
- "Administrators or users that actually use the selected keyboard layouts (heavily depends on the organisation's user base)"
|
||||||
level: medium
|
level: medium
|
||||||
|
tags:
|
||||||
|
- attack.resource_development
|
||||||
|
- attack.t1588.002
|
||||||
|
@ -11,6 +11,9 @@ falsepositives:
|
|||||||
- Legitimate use of SysInternals tools
|
- Legitimate use of SysInternals tools
|
||||||
- Programs that use the same Registry Key
|
- Programs that use the same Registry Key
|
||||||
level: low
|
level: low
|
||||||
|
tags:
|
||||||
|
- attack.resource_development
|
||||||
|
- attack.t1588.002
|
||||||
---
|
---
|
||||||
logsource:
|
logsource:
|
||||||
product: windows
|
product: windows
|
||||||
|
Loading…
Reference in New Issue
Block a user