Florian Roth
|
1f0b1e58a9
|
fix: bugs in rule and title
|
2020-07-03 09:54:10 +02:00 |
|
Florian Roth
|
01ed87186f
|
Copy From System Root rule
|
2020-07-03 09:45:58 +02:00 |
|
Florian Roth
|
33fef8bcf5
|
DesktopImgDownLdr rules
|
2020-07-03 09:45:48 +02:00 |
|
Florian Roth
|
4c4ed1a4a2
|
fix: duplicate IDs and rule titles
|
2020-07-01 16:37:27 +02:00 |
|
Florian Roth
|
9c0f9f398f
|
refactor: sysmon rule cleanup > generlization
|
2020-07-01 10:58:39 +02:00 |
|
Florian Roth
|
4231fe2efc
|
fix: remove duplicate rules in sysmon (generic rule cleanup)
|
2020-07-01 10:23:30 +02:00 |
|
Florian Roth
|
154181c6c8
|
fix: renamed files and lien break change
|
2020-07-01 09:48:48 +02:00 |
|
Florian Roth
|
d70b63b78c
|
rule: RedMimicry rules (modified)
|
2020-07-01 09:17:31 +02:00 |
|
Florian Roth
|
fe71d21d97
|
style: removed new lines
|
2020-07-01 09:11:00 +02:00 |
|
Florian Roth
|
b7ac36e6ab
|
Merge branch 'master' into rule-devel
|
2020-07-01 09:04:46 +02:00 |
|
Florian Roth
|
f2587791f2
|
rule: suspicious rar flags
|
2020-07-01 09:04:26 +02:00 |
|
Florian Roth
|
ba682c5de6
|
Merge pull request #863 from qwerty1q2w/feature
add win_not_allowed_rdp_access.yml rule
|
2020-06-30 10:03:11 +02:00 |
|
Florian Roth
|
77553e11e8
|
Update win_not_allowed_rdp_access.yml
|
2020-06-30 10:03:00 +02:00 |
|
Florian Roth
|
2e3669a5a4
|
Merge pull request #865 from j91321/defender-rules
Windows Defender logsource and rules
|
2020-06-30 10:01:17 +02:00 |
|
Florian Roth
|
eb3a6e86af
|
Merge pull request #867 from HarishHary/suspicious_powershell_parent_process
New Rule: Suspicious powershell parent process
|
2020-06-30 10:00:28 +02:00 |
|
Harish SEGAR
|
9c74018e12
|
Added new rule for pwsh_xor_cmd (sysmon)
|
2020-06-29 22:18:25 +02:00 |
|
Harish SEGAR
|
5e740fd7b2
|
Added new rule for pwsh_xor_cmd (sysmon)
|
2020-06-29 22:13:49 +02:00 |
|
Harish SEGAR
|
649e4eaa63
|
Added new rule for pwsh_xor_cmd
|
2020-06-29 22:09:58 +02:00 |
|
Florian Roth
|
5a11ef90d0
|
rule reorganized
|
2020-06-29 21:24:47 +02:00 |
|
Harish SEGAR
|
1a088425f9
|
Fix rules.
|
2020-06-29 20:42:35 +02:00 |
|
Florian Roth
|
bb214f5832
|
rule: Explorer Root Flag Process Tree Break
|
2020-06-29 12:07:15 +02:00 |
|
j91321
|
24029d998a
|
FIX: lint error for title
|
2020-06-28 11:05:19 +02:00 |
|
j91321
|
ae842a65cb
|
Windows Defender rules and logsource
|
2020-06-28 10:55:32 +02:00 |
|
Thomas Patzke
|
d1f37bdbd4
|
Merge pull request #828 from stevengoossensB/master
Split rules based on Sysmon event ID
|
2020-06-28 00:00:32 +02:00 |
|
Pushkarev Dmitry
|
502ec4b417
|
add win_not_allowed_rdp_access.yml rule
|
2020-06-26 22:15:53 +00:00 |
|
Florian Roth
|
3decee07ba
|
fix: bugfix and cosmetics
|
2020-06-24 18:10:58 +02:00 |
|
Florian Roth
|
f3fedef8f5
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
|
Florian Roth
|
4224a6517d
|
Merge pull request #859 from Neo23x0/rule-devel
fix: duplicate IDs
|
2020-06-24 17:23:13 +02:00 |
|
Florian Roth
|
c3ffa0b9d3
|
fix: duplicate IDs
|
2020-06-24 17:04:04 +02:00 |
|
Brad Kish
|
d385cbfa69
|
Fix quoting for AD Object WriteDAC Access
The AccessMask field needs to be quoted so that it is compared correctly.
|
2020-06-22 15:31:03 -04:00 |
|
Furkan ÇALIŞKAN
|
b091e3b1c4
|
Update for new method
Update for method mentioned in https://ired.team/offensive-security/code-execution/code-execution-through-control-panel-add-ins
|
2020-06-22 01:06:34 +03:00 |
|
Florian Roth
|
e1225784f7
|
fix: fixed indentation
|
2020-06-19 09:54:08 +02:00 |
|
Florian Roth
|
62632db818
|
refactor: added variant to IE rule
|
2020-06-19 09:53:35 +02:00 |
|
Florian Roth
|
5cb6f5da9d
|
fix: title adjusted
|
2020-06-19 09:39:11 +02:00 |
|
Florian Roth
|
b8a5cd4787
|
Disabled IE Security Features
|
2020-06-19 09:37:10 +02:00 |
|
Florian Roth
|
da060bfb90
|
Ke3chang rule
|
2020-06-19 09:36:54 +02:00 |
|
Florian Roth
|
b675c4c706
|
Merge branch 'master' into rule-devel
|
2020-06-19 09:24:26 +02:00 |
|
Florian Roth
|
4b0c80885f
|
Merge pull request #810 from EccoTheFlintstone/fp
add WMI module load false positives
|
2020-06-18 12:50:40 +02:00 |
|
Florian Roth
|
32ecb81630
|
Merge pull request #845 from ikiril01/att&ck_subtechniques_v2
ATT&CK subtechniques v2
|
2020-06-18 09:10:09 +02:00 |
|
Ivan Kirillov
|
b343df2225
|
Further subtechnique updates
|
2020-06-17 11:31:40 -06:00 |
|
ecco
|
99bfa14ae0
|
add 1 more FP
|
2020-06-17 12:49:27 -04:00 |
|
Florian Roth
|
0022705373
|
fix: filter not functional
since `UsrLogon.cmd` does appear only in `C:\Windows\system32\cmd.exe /c UsrLogon.cmd` command line
|
2020-06-17 16:09:44 +02:00 |
|
Ivan Kirillov
|
5c0bb0e94f
|
Fixed indentation
|
2020-06-16 15:01:13 -06:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
Florian Roth
|
d24ec665fd
|
Merge pull request #838 from rtkbkish/fix-identifier
Identifiers shared between global document and rule gets overwritten
|
2020-06-15 20:20:23 +02:00 |
|
Florian Roth
|
87053502a3
|
Merge pull request #839 from rtkbkish/fix-double-backslash
Fix match for double-backslash
|
2020-06-15 20:19:56 +02:00 |
|
Florian Roth
|
869162a5da
|
Merge pull request #840 from rtkbkish/remove-wrong-sysmon-id
Rule lists extra Sysmon ID (11). Should just match registry events (1…
|
2020-06-15 20:19:27 +02:00 |
|
Florian Roth
|
3482e048fb
|
Merge pull request #841 from rtkbkish/fix-rule-match
Rule needs endwith, not exact match.
|
2020-06-15 20:19:12 +02:00 |
|
Florian Roth
|
46bd56a708
|
Merge pull request #837 from rtkbkish/fix-win-invoke-obfuscation
Fix logsource field name from service->category
|
2020-06-15 20:18:53 +02:00 |
|
Brad Kish
|
dfae2a6df6
|
Rule needs endwith, not exact match.
Fix ImageLoaded filter to match with endswith, rather than exact match.
|
2020-06-15 13:54:02 -04:00 |
|