yugoslavskiy
|
057c33354a
|
Merge pull request #1237 from alx1m1k/oscd-2
[OSCD] T1027.001: Binary Padding - Lin/macOS
|
2021-01-06 00:33:05 +03:00 |
|
yugoslavskiy
|
befcad2df7
|
Merge pull request #1234 from w0rk3r/oscd1
[OSCD] Update win_susp_replace_lolbin.yml
|
2021-01-06 00:32:55 +03:00 |
|
yugoslavskiy
|
6ebcb10abd
|
Merge pull request #1233 from V3T0/v3t0_oscd_lolbas_runonce_susp_execution
[OSCD] Added a rule to detect execution of runonce with suspicious parameters
|
2021-01-06 00:32:44 +03:00 |
|
yugoslavskiy
|
3bf1663503
|
Merge pull request #1232 from V3T0/v3t0_oscd_lolbas_tracker
[OSCD] Added a rule to detect the execution of tracker.exe with suspicious arguments
|
2021-01-06 00:32:35 +03:00 |
|
yugoslavskiy
|
e4c302bf6f
|
Merge pull request #1231 from vburov/patch-16
[OSCD] Detects LockerGoga Ransomware command line.
|
2021-01-06 00:30:08 +03:00 |
|
yugoslavskiy
|
2985836e36
|
Merge pull request #1140 from omkar72/oscd-5
[OSCD] adding shortened commands for Netsh in the existing rule
|
2021-01-06 00:24:43 +03:00 |
|
yugoslavskiy
|
d25ca9b280
|
Merge pull request #1229 from zinint/1009-19-1
[OSCD] Detects Obfuscated Powershell via COMPRESS OBFUSCATION #19 (4104, 4103 + Services + process_creation)
|
2021-01-06 00:24:08 +03:00 |
|
yugoslavskiy
|
7889df6644
|
Merge pull request #1227 from stvetro/oscd-runscripthelper
[OSCD] - Runscripthelper.exe runs script (LoLBin)
|
2021-01-06 00:24:00 +03:00 |
|
yugoslavskiy
|
0ed153237e
|
Merge pull request #1226 from stvetro/oscd-winword
[OSCD] - Force winword.exe to load DLL (LoLBin)
|
2021-01-06 00:23:52 +03:00 |
|
yugoslavskiy
|
1d2f027035
|
Merge pull request #1224 from stvetro/oscd
[OSCD] Verclsid.exe Runs COM Object (LOLBin)
|
2021-01-06 00:23:45 +03:00 |
|
yugoslavskiy
|
f4578b0698
|
Merge pull request #1223 from zinint/1009-23-1
[OSCD] Detects Obfuscated Powershell via RUNDLL Launcher #23 (4104, 4103 + Services + process_creation)
|
2021-01-06 00:23:33 +03:00 |
|
yugoslavskiy
|
23519e47cd
|
Merge pull request #1222 from feedb/oscd
[OSCD] zer0w
|
2021-01-06 00:23:25 +03:00 |
|
yugoslavskiy
|
93718975fb
|
Merge pull request #1221 from grikos/OSCD_117_128
[OSCD] suspicious csi.exe (rcsi.exe) LOLBAS detection rule
|
2021-01-06 00:23:13 +03:00 |
|
yugoslavskiy
|
cd62929bb0
|
Merge pull request #1220 from aw350m33d/PS_exec_via_redirected_input_stream
[OSCD] LOLBIN 5 PowerShell with redirection of the input stream.
|
2021-01-06 00:23:06 +03:00 |
|
yugoslavskiy
|
70eff4b1fc
|
Merge pull request #1219 from ryanplasma/rplas-SIGMA-547-page-37
[OSCD] Add Files Dropped to Program Files by Non-Priviledged Process Rule
|
2021-01-06 00:22:57 +03:00 |
|
yugoslavskiy
|
a5bbccf16c
|
Merge pull request #1214 from tas-kmanager/mt-oscd-sigma547-48-alternative
[OSCD] Always Install Elevated Alternative
|
2021-01-06 00:22:37 +03:00 |
|
yugoslavskiy
|
a217a3cfc7
|
Merge pull request #1213 from alx1m1k/oscd
[OSCD] T1552.003: Suspicious history file operations - Linux/macOS
|
2021-01-06 00:21:19 +03:00 |
|
yugoslavskiy
|
066be03c19
|
Merge pull request #1212 from aleqs4ndr/oscd-2020
[OSCD] Added a rule to detect possible Zerologon exploitation
|
2021-01-06 00:21:12 +03:00 |
|
yugoslavskiy
|
29fe6e46d8
|
Merge pull request #1211 from zipa-original/win_persistence_telemetry
[OSCD] Added a rule to detect abusing windows telemetry for persistence
|
2021-01-06 00:20:51 +03:00 |
|
yugoslavskiy
|
c71e0ae0ea
|
Merge pull request #1209 from vburov/patch-15
[OSCD] Create win_susp_multiple_files_renamed_or_deleted.yml
|
2021-01-06 00:19:41 +03:00 |
|
yugoslavskiy
|
38661bbc10
|
Merge pull request #1208 from NikitaStormwind/RTT(17)
[OSCD] Atomic Red Team: Detected Windows Software Discovery (T1518)
|
2021-01-06 00:19:20 +03:00 |
|
yugoslavskiy
|
2cf1994763
|
Merge pull request #1206 from w0rk3r/oscd5
[OSCD] Windows - Suspicious Service DACL Modification
|
2021-01-06 00:18:53 +03:00 |
|
yugoslavskiy
|
aad2838f58
|
Merge pull request #1198 from tas-kmanager/mt-oscd-sigma547-50-rule2
[OSCD] Always Install Elevated - Slide 50 - Rule 2
|
2021-01-06 00:18:44 +03:00 |
|
yugoslavskiy
|
e0286abb62
|
Merge pull request #1197 from w0rk3r/oscd_rules_improvement2
[OSCD] Small improvements on others rules
|
2021-01-06 00:18:36 +03:00 |
|
yugoslavskiy
|
0b7babaa84
|
Merge pull request #1196 from tas-kmanager/mt-oscd-sigma547-50-rule1
[OSCD] Always Install Elevated - Slide 50 - Rule 1
|
2021-01-06 00:18:26 +03:00 |
|
yugoslavskiy
|
fc1fa23440
|
Merge pull request #1191 from vburov/patch-14
[OSCD] Create powershell_cmdline_special_characters.yml
|
2021-01-06 00:18:12 +03:00 |
|
yugoslavskiy
|
8e50eeb4a9
|
Merge pull request #1187 from nsaddler/lolbas108
[OSCD] LOLBAS Manage-bde.yml
|
2021-01-06 00:18:02 +03:00 |
|
yugoslavskiy
|
cfbd10ab8b
|
Merge pull request #1186 from nsaddler/lolbas107_2
[OSCD] LOLBAS CL_Mutexverifiers - powershell
|
2021-01-06 00:17:54 +03:00 |
|
yugoslavskiy
|
e91d48cc93
|
Merge pull request #1185 from nsaddler/lolbas107_1
[OSCD] LOLBAS CL_Mutexverifiers - process_creation
|
2021-01-06 00:17:46 +03:00 |
|
yugoslavskiy
|
9d1c695204
|
Merge pull request #1184 from nsaddler/lolbas106_1
[OSCD] LOLBAS CL_Invocation - powershell
|
2021-01-06 00:17:10 +03:00 |
|
yugoslavskiy
|
def4a7dbb9
|
Merge pull request #1183 from nsaddler/lolbas106
[OSCD] LOLBAS CL_Invocation - process_creation
|
2021-01-06 00:17:01 +03:00 |
|
yugoslavskiy
|
6f2e8c56b2
|
Merge pull request #1182 from nsaddler/lolbas80
[OSCD] LOLBAS wab.yml
|
2021-01-06 00:16:53 +03:00 |
|
yugoslavskiy
|
e1fd69f548
|
Merge pull request #1179 from SanWieb/OSCD_regedit_3
[OSCD] regedit.exe LOLbas 72 [3]
|
2021-01-06 00:16:45 +03:00 |
|
yugoslavskiy
|
8e6b77fc4f
|
Merge pull request #1177 from OpalSec/oscd
[OSCD] Tasks 24, 25 & 26: Detection for Invoke-Obfuscation CLIP+, STDIN+ & VAR+ Launchers
|
2021-01-06 00:16:34 +03:00 |
|
yugoslavskiy
|
95d8a9daf0
|
Merge pull request #1174 from uncleAntik/update
[OSCD] LOLBin vsjitdebugger.exe #136
|
2021-01-06 00:16:20 +03:00 |
|
yugoslavskiy
|
252345ca00
|
Merge pull request #1173 from uncleAntik/fix
[OSCD] LOLBin te.exe #133
|
2021-01-06 00:16:12 +03:00 |
|
yugoslavskiy
|
aeb448cd4d
|
Merge pull request #1171 from alejandroortuno/network-sniffing
[OSCD] MacOS Network Sniffing
|
2021-01-06 00:15:52 +03:00 |
|
yugoslavskiy
|
ebc6451b86
|
Merge pull request #1170 from alejandroortuno/startup-items
[OSCD] MacOS Startup Items
|
2021-01-06 00:15:45 +03:00 |
|
yugoslavskiy
|
ad739f7f29
|
Merge pull request #1169 from remotephone/oscd_t1113
[OSCD] - T1113 - macOS Screencapture via builtin screencapture utility
|
2021-01-06 00:15:37 +03:00 |
|
yugoslavskiy
|
d50c081f3f
|
Merge pull request #1168 from remotephone/oscd_t1056_002
[OSCD] macOS - T1056.002 - GUI Input capture
|
2021-01-06 00:15:30 +03:00 |
|
yugoslavskiy
|
1fd0afc58e
|
Merge pull request #1167 from tas-kmanager/mt-oscd-sigma547-43
[OSCD] Add Accesschk tool usage rule
|
2021-01-06 00:14:08 +03:00 |
|
yugoslavskiy
|
5ade9208d5
|
Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
|
2021-01-06 00:12:34 +03:00 |
|
yugoslavskiy
|
46eb01f3c5
|
Merge pull request #1164 from GlebSukhodolskiy/oscd_reg
[OSCD] Modified Rule "Autorun Keys Modification"
|
2021-01-06 00:11:58 +03:00 |
|
yugoslavskiy
|
4c8e0b201d
|
Merge pull request #1162 from uncleAntik/131
[OSCD] LOLBin sqltoolsps.exe #131
|
2021-01-06 00:11:33 +03:00 |
|
yugoslavskiy
|
b56a7181ce
|
Merge pull request #1157 from invrep-de/oscd
[OSCD] Bad Opsec Powershell Artifacts
|
2021-01-06 00:11:24 +03:00 |
|
yugoslavskiy
|
319ebd158c
|
Merge pull request #1155 from sn0w0tter/oscd2
[OSCD] LOLBAS atbroker suspicious creation of ATs
|
2021-01-06 00:11:13 +03:00 |
|
yugoslavskiy
|
d2087c276c
|
Merge pull request #1151 from zinint/1009-27-2
[OSCD] Detects Obfuscated Powershell via VAR++ Launcher #27 (Services)
|
2021-01-06 00:10:55 +03:00 |
|
yugoslavskiy
|
0bd955f097
|
Merge branch 'oscd' into oscd-5
|
2021-01-06 00:09:47 +03:00 |
|
yugoslavskiy
|
1f0d081c01
|
Merge pull request #1144 from NikitaStormwind/regular28(3)
[OSCD] Detects Obfuscated Powershell via Stdin in Scripts #28 (Services)
|
2021-01-05 23:23:00 +03:00 |
|
yugoslavskiy
|
1cfc0d17ef
|
Merge pull request #1141 from omkar72/oscd-6
[OSCD] suspicious clr logs creation
|
2021-01-05 23:22:36 +03:00 |
|