Commit Graph

2664 Commits

Author SHA1 Message Date
yugoslavskiy
0188e45925
Update win_malware_script_dropper.yml 2020-12-01 02:12:53 +01:00
yugoslavskiy
30ecc8bd26
Update win_malware_script_dropper.yml 2020-12-01 02:08:52 +01:00
yugoslavskiy
6494103839
Update win_susp_powershell_enc_cmd.yml 2020-12-01 01:54:51 +01:00
yugoslavskiy
d1b625d080
Update win_susp_powershell_enc_cmd.yml 2020-12-01 01:51:47 +01:00
yugoslavskiy
3cbc2f0aec
Update win_susp_powershell_enc_cmd.yml 2020-12-01 01:47:23 +01:00
yugoslavskiy
816ce5937c
Update win_susp_crackmapexec_execution.yml 2020-12-01 01:29:35 +01:00
Yugoslavskiy Daniil
50623544a2 remove possible duplicate filter 2020-11-29 22:03:19 +01:00
Jonhnathan
a9fde0117b
Merge branch 'oscd' into oscd_rules_improvement 2020-11-28 14:52:31 -03:00
yugoslavskiy
7dc5233dd9
Update win_susp_commands_recon_activity.yml 2020-11-28 18:43:04 +01:00
yugoslavskiy
5196926d60
Update sysmon_stickykey_like_backdoor.yml 2020-11-28 18:33:21 +01:00
yugoslavskiy
39c2258848
Update sysmon_registry_persistence_search_order.yml 2020-11-28 18:30:41 +01:00
yugoslavskiy
9f8ef95571
Update win_webshell_detection.yml 2020-11-28 18:25:09 +01:00
yugoslavskiy
c761d05a17
Update win_system_exe_anomaly.yml 2020-11-28 18:03:19 +01:00
yugoslavskiy
258334d6d1
Update win_susp_wmi_execution.yml 2020-11-28 18:01:06 +01:00
Jonhnathan
95eb7424aa
Update sysmon_susp_run_key_img_folder.yml 2020-11-28 13:54:59 -03:00
Jonhnathan
f504ccc33f
Update sysmon_susp_reg_persist_explorer_run.yml 2020-11-28 13:52:36 -03:00
Jonhnathan
986800056c
Update sysmon_stickykey_like_backdoor.yml 2020-11-28 13:50:13 -03:00
yugoslavskiy
c0c74a05df
Update win_susp_sysvol_access.yml 2020-11-28 17:49:21 +01:00
Jonhnathan
ef34c94e6a
Update sysmon_registry_persistence_search_order.yml 2020-11-28 13:49:18 -03:00
yugoslavskiy
3c75bc922a
Update win_susp_squirrel_lolbin.yml 2020-11-28 17:47:16 +01:00
Jonhnathan
06cc5049a4
Update sysmon_dns_serverlevelplugindll.yml 2020-11-28 13:46:02 -03:00
yugoslavskiy
42f27a41cb
Update win_susp_rundll32_by_ordinal.yml 2020-11-28 17:44:30 +01:00
yugoslavskiy
ca0a6547fb
Update win_susp_run_locations.yml 2020-11-28 17:42:47 +01:00
Jonhnathan
f1455e0c38
Update win_win10_sched_task_0day.yml 2020-11-28 13:42:30 -03:00
Jonhnathan
fe3ed329ef
Update win_webshell_recon_detection.yml 2020-11-28 13:41:11 -03:00
yugoslavskiy
ea550cf551
Update win_susp_regsvr32_anomalies.yml 2020-11-28 17:40:40 +01:00
Jonhnathan
f0bf3d13b5
Update win_webshell_detection.yml 2020-11-28 13:38:34 -03:00
Jonhnathan
9f4bbb7e65
Update win_webshell_detection.yml 2020-11-28 13:35:50 -03:00
yugoslavskiy
bcf62fba72
Update win_susp_ps_appdata.yml 2020-11-28 17:34:34 +01:00
yugoslavskiy
2ed4b26291
Update win_susp_procdump.yml 2020-11-28 17:33:02 +01:00
Jonhnathan
0d0f58c830
Update win_system_exe_anomaly.yml 2020-11-28 13:32:44 -03:00
yugoslavskiy
a3e436363e
Update win_susp_powershell_parent_combo.yml 2020-11-28 17:31:37 +01:00
Jonhnathan
c9b5ba10f8
Update win_susp_wmi_execution.yml 2020-11-28 13:30:34 -03:00
yugoslavskiy
c01c05b826
Update win_susp_powershell_enc_cmd.yml 2020-11-28 17:29:15 +01:00
Jonhnathan
f6117eebc7
Update win_susp_sysvol_access.yml 2020-11-28 13:27:28 -03:00
Jonhnathan
88b4d4c4e5
Update win_susp_sysvol_access.yml 2020-11-28 13:26:22 -03:00
yugoslavskiy
66a504078b
Update win_susp_ping_hex_ip.yml 2020-11-28 17:25:52 +01:00
Jonhnathan
7aa831eac3
Remove additional backslash 2020-11-28 13:25:28 -03:00
Jonhnathan
0357472635
Update win_susp_squirrel_lolbin.yml 2020-11-28 13:24:38 -03:00
Jonhnathan
f70bd415a3
Update win_susp_run_locations.yml 2020-11-28 13:21:04 -03:00
Jonhnathan
5cbefe3737
Update win_susp_regsvr32_anomalies.yml 2020-11-28 13:18:38 -03:00
Jonhnathan
e99f63f811
Update win_susp_ps_appdata.yml 2020-11-28 13:15:24 -03:00
Jonhnathan
fc842c22b2
Update win_susp_prog_location_process_starts.yml 2020-11-28 13:11:15 -03:00
Jonhnathan
a78eb61d92
Remove additional backslash 2020-11-28 13:08:51 -03:00
Jonhnathan
27f47a8ffc
Update win_susp_procdump.yml 2020-11-28 13:08:21 -03:00
Jonhnathan
b61707e7f3
Remove additional backslash 2020-11-28 13:07:06 -03:00
Jonhnathan
c9461506f2
Update win_susp_powershell_enc_cmd.yml 2020-11-28 13:06:10 -03:00
Jonhnathan
2364e9870d
Update win_susp_powershell_enc_cmd.yml 2020-11-28 13:05:47 -03:00
Jonhnathan
f4f8174199
Update win_susp_powershell_enc_cmd.yml 2020-11-28 13:04:36 -03:00
Jonhnathan
53e1201bea
Update win_susp_ping_hex_ip.yml 2020-11-28 13:01:42 -03:00