Austin Songer
|
1834324a16
|
Update
|
2021-08-23 17:33:57 +00:00 |
|
Austin Songer
|
7d211f2487
|
Data exfiltration to unsanctioned apps
|
2021-08-23 17:33:00 +00:00 |
|
Austin Songer
|
f5286905ff
|
Merge branch 'SigmaHQ:master' into microsoft365
|
2021-08-23 12:22:58 -05:00 |
|
Austin Songer
|
ae84559488
|
M365 - Risky IP Addresses
|
2021-08-23 17:18:16 +00:00 |
|
frack113
|
be316db84d
|
Merge pull request #1899 from secDre4mer/master
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 17:26:16 +02:00 |
|
SomeOne
|
037f33b5e2
|
Replace by default windows fieldnames
|
2021-08-23 15:24:48 +02:00 |
|
SomeOne
|
45f30cb2b4
|
Add fields to event log cleared
|
2021-08-23 15:00:07 +02:00 |
|
Max Altgelt
|
82dde594d1
|
feat: Add rule for malicious CSR export on Exchange
|
2021-08-23 11:20:30 +02:00 |
|
frack113
|
52595de85e
|
Merge pull request #1889 from rachelrice/update_aws_rules
Update AWS CloudTrail rules
|
2021-08-23 11:14:31 +02:00 |
|
frack113
|
fc9666fb4e
|
Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
|
2021-08-22 18:56:08 +02:00 |
|
frack113
|
0a410010a2
|
Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
|
2021-08-22 18:50:58 +02:00 |
|
SomeOne
|
295054dcbe
|
Replace old mitre techniques by new one
|
2021-08-22 13:57:56 +02:00 |
|
frack113
|
064c65cb1f
|
Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
|
2021-08-21 18:04:52 +02:00 |
|
frack113
|
07a87aa7f8
|
Merge pull request #1858 from frack113/fix_pr718
Replace pr718
|
2021-08-21 18:02:30 +02:00 |
|
frack113
|
a44206bfa0
|
Some cleanup
|
2021-08-21 17:33:39 +02:00 |
|
pbssubhash
|
eee497f656
|
Title modification
|
2021-08-21 20:04:03 +05:30 |
|
pbssubhash
|
a415463f5b
|
Modified rule
|
2021-08-21 19:37:28 +05:30 |
|
pbssubhash
|
fba54b8d69
|
First Rule commit
|
2021-08-21 17:47:56 +05:30 |
|
frack113
|
42c90b9d20
|
fix powershell_psattack error
|
2021-08-21 10:05:47 +02:00 |
|
frack113
|
2f683b9ab7
|
fix powershell_clear_powershell_history error
|
2021-08-21 10:00:48 +02:00 |
|
frack113
|
0fb6c35b1f
|
Cleanup PS rules
|
2021-08-21 09:58:58 +02:00 |
|
frack113
|
da839775fe
|
Update PS rules
|
2021-08-21 09:50:59 +02:00 |
|
frack113
|
6c529f7ab2
|
Update PS rules
|
2021-08-21 09:33:52 +02:00 |
|
frack113
|
cb95582077
|
Update PowerShell rule
|
2021-08-21 09:08:38 +02:00 |
|
frack113
|
dbbb422a42
|
Merge pull request #1885 from austinsonger/microsoft365_unusual_volume_of_file_deletion.yml
microsoft365_unusual_volume_of_file_deletion.yml
|
2021-08-20 17:20:43 +02:00 |
|
frack113
|
34ac3587e9
|
Merge pull request #1884 from austinsonger/microsoft365_potential_ransomware_activity.yml
microsoft365_potential_ransomware_activity.yml
|
2021-08-20 17:20:34 +02:00 |
|
frack113
|
73fee68d4b
|
Merge pull request #1883 from austinsonger/microsoft365_user_restricted_from_sending_email.yml
microsoft365_user_restricted_from_sending_email.yml
|
2021-08-20 17:20:22 +02:00 |
|
frack113
|
b9a355e3f4
|
cleanup falsepositives
|
2021-08-20 17:18:32 +02:00 |
|
Florian Roth
|
b92346ba5f
|
Merge pull request #1882 from austinsonger/win_susp_bitstransfer.yml
win_susp_bitstransfer.yml
|
2021-08-20 16:53:52 +02:00 |
|
Florian Roth
|
ecd0bb4576
|
Merge pull request #1890 from frack113/update_conti_ref
update ref from conti_leak
|
2021-08-20 16:53:12 +02:00 |
|
Florian Roth
|
700b8e440f
|
Merge pull request #1868 from d4rk-d4nph3/master
Added rule for zero day CVE-2021-22123 in Fortinet WAFs
|
2021-08-20 16:52:49 +02:00 |
|
Rachel Rice
|
f037f5b0a9
|
Add filter3 back for vm export failure, without consolelogin
Signed-off-by: Rachel Rice <rachel.rice@lacework.net>
|
2021-08-20 15:42:49 +01:00 |
|
Austin Songer
|
a25f6e196f
|
Update microsoft365_unusual_volume_of_file_deletion.yml
|
2021-08-20 08:17:25 -05:00 |
|
Austin Songer
|
360b936357
|
Update microsoft365_potential_ransomware_activity.yml
|
2021-08-20 08:17:09 -05:00 |
|
Austin Songer
|
ae36804935
|
Update microsoft365_user_restricted_from_sending_email.yml
|
2021-08-20 08:16:48 -05:00 |
|
Rachel Rice
|
f09b3ea4b1
|
Update AWS CloudTrail rules
aws_ec2_disable_encryption.yml
Remove `status: success` from selection criteria, not required
aws_ec2_vm_export_failure.yml
Remove filter3:
```
eventName: 'ConsoleLogin'
responseElements|contains: 'Failure'
```
Incompatible with selection criteria `eventName: 'CreateInstanceExportTask'`
aws_ec2_download_userdata.yml, aws_iam_backdoor_users_keys.yml, aws_rds_change_master_password.yml, aws_rds_public_db_restore.yml
Update reference
aws_sts_assumedrole_misuse.yml
Rename to aws_sts_assumerole_misuse.yml
Update references to "AssumedRole" to "AssumeRole"
Update selection criteria of `userIdentity.sessionContext: Role` to `userIdentity.sessionContext.sessionIssuer.type: Role`
|
2021-08-20 13:43:00 +01:00 |
|
frack113
|
7ebd411190
|
update ref from conti_leak
|
2021-08-20 14:22:17 +02:00 |
|
frack113
|
4e29dc9c45
|
fix title
|
2021-08-20 09:06:16 +02:00 |
|
frack113
|
9b106dcc7d
|
Merge pull request #1880 from austinsonger/azure_suppression_rule_created.yml
azure_suppression_rule_created.yml
|
2021-08-20 09:04:48 +02:00 |
|
frack113
|
d58b1e8e40
|
Merge pull request #1879 from austinsonger/azure_application_gateway_modified_or_deleted.yml
azure_application_gateway_modified_or_deleted.yml
|
2021-08-20 09:03:57 +02:00 |
|
frack113
|
4b08aac47f
|
Merge pull request #1878 from austinsonger/azure_application_security_group_modified_or_deleted.yml
azure_application_security_group_modified_or_deleted.yml
|
2021-08-20 09:01:39 +02:00 |
|
Austin Songer
|
853c2eb41d
|
Update microsoft365_potential_ransomware_activity.yml
|
2021-08-20 01:19:01 -05:00 |
|
Austin Songer
|
f745593e80
|
Update microsoft365_potential_ransomware_activity.yml
|
2021-08-20 00:33:42 -05:00 |
|
Austin Songer
|
42fbc0cbfc
|
Update aws_eks_cluster_created_or_deleted.yml
|
2021-08-19 23:13:35 -05:00 |
|
Austin Songer
|
bcb43cf728
|
Update aws_eks_cluster_created_or_deleted.yml
|
2021-08-19 23:13:06 -05:00 |
|
Austin Songer
|
b89910a38a
|
Update aws_eks_cluster_created_or_deleted.yml
|
2021-08-19 23:09:38 -05:00 |
|
frack113
|
f882ebda35
|
fix status
|
2021-08-20 06:08:28 +02:00 |
|
Austin Songer
|
54bda90685
|
Create microsoft365_user_restricted_from_sending_email.yml
|
2021-08-19 23:08:25 -05:00 |
|
Austin Songer
|
9b19190ea7
|
Create microsoft365_potential_ransomware_activity.yml
|
2021-08-19 23:05:05 -05:00 |
|
Austin Songer
|
99fbd4ef44
|
Create microsoft365_unusual_volume_of_file_deletion.yml
|
2021-08-19 23:00:23 -05:00 |
|