Daniel Masse
0489a50bd0
Change the selection from Command to CommandLine in a couple of rules
2020-07-15 15:55:26 -04:00
Florian Roth
3ab5eb97d8
Merge pull request #901 from brachera/master
...
rule: Leviathan registry key
2020-07-10 16:42:02 +02:00
Florian Roth
5de82628fa
Update sysmon_apt_leviathan.yml
2020-07-10 15:41:55 +02:00
Thomas Patzke
2032a1e7fd
Merge pull request #898 from rtkbkish/fix-uac-registry
...
Proposed fix for sysmon_uac_bypass_eventvwr
2020-07-07 22:29:39 +02:00
Aidan Bracher
90983dcc4b
add level field to rule
2020-07-07 14:28:18 +01:00
Aidan Bracher
f549a14d9a
rule: Leviathan registry key
2020-07-07 13:27:57 +01:00
Brad Kish
c758ca0eb9
Re-fix sysmon rules that are lost changes with category refactoring.
...
Several fixes for sysmon rules got lost when the rules were refactored to use
categories.
Re-add the fixes.
38afd8b5de
422b2bffd7
dfae2a6df6
2020-07-06 10:55:42 -04:00
Brad Kish
7e06fd80fd
Proposed fix for sysmon_uac_bypass_eventvwr
...
Issue: https://github.com/Neo23x0/sigma/issues/888
The rules were not merged correctly with the transition to sysmon categories.
Split the rule into separate documents: one for the registry_event and one for
the process_creation
2020-07-06 09:20:34 -04:00
Brad Kish
4b31633355
Fixes for rules in new sysmon registry_event category
...
To be consistent with the behaviour of the other rules, the eventID should not
be specified as part of the rule. The category defines the eventID.
2020-07-03 16:20:37 -04:00
Florian Roth
5f04fcccf5
fix: broken links
2020-07-03 11:22:06 +02:00
Florian Roth
4c4ed1a4a2
fix: duplicate IDs and rule titles
2020-07-01 16:37:27 +02:00
Florian Roth
9c0f9f398f
refactor: sysmon rule cleanup > generlization
2020-07-01 10:58:39 +02:00
Florian Roth
154181c6c8
fix: renamed files and lien break change
2020-07-01 09:48:48 +02:00
Florian Roth
d70b63b78c
rule: RedMimicry rules (modified)
2020-07-01 09:17:31 +02:00
Florian Roth
fe71d21d97
style: removed new lines
2020-07-01 09:11:00 +02:00
Florian Roth
3decee07ba
fix: bugfix and cosmetics
2020-06-24 18:10:58 +02:00
Florian Roth
f3fedef8f5
Changed category names and remove sysmon log source
2020-06-24 17:41:21 +02:00
Steven Goossens
e5f36dd146
Added rules files split into folders
2020-06-10 16:32:30 +02:00