yugoslavskiy
|
4443870577
|
Delete win_odbcconf_execution.yml
merged with rules/windows/process_creation/win_odbcconf_execution.yml
|
2019-11-08 01:36:03 +03:00 |
|
yugoslavskiy
|
6083d70975
|
Update sysmon_registry_persistence_key_linking.yml
|
2019-11-07 04:23:20 +03:00 |
|
yugoslavskiy
|
82b185db6a
|
Update win_sysmon_driver_unload.yml
|
2019-11-07 04:11:26 +03:00 |
|
yugoslavskiy
|
404a6d9915
|
Update win_netsh_packet_capture.yml
|
2019-11-07 03:37:41 +03:00 |
|
yugoslavskiy
|
ddf24819ed
|
Update silenttrinity_stage_use.yml
|
2019-11-07 03:33:12 +03:00 |
|
yugoslavskiy
|
0d8c64da86
|
duplicate rule deleted
this rule already present in Sigma repo — [./rules/windows/process_creation/win_susp_comsvcs_procdump.yml](https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_comsvcs_procdump.yml)
|
2019-11-07 03:21:09 +03:00 |
|
alexpetrov12
|
8c2b7e9f85
|
fix
|
2019-10-25 18:30:40 +03:00 |
|
alexpetrov12
|
7aa804fe90
|
added new rules
Packet capture Windows command prompt, ODBCCONF execution dll, Windows Registry Persistence - COM key linking
|
2019-10-25 18:01:36 +03:00 |
|
alexpetrov12
|
cc998aa667
|
fix
|
2019-10-24 00:48:43 +03:00 |
|
alexpetrov12
|
f1ccf296f4
|
fix
|
2019-10-24 00:40:58 +03:00 |
|
alexpetrov12
|
d3715a508b
|
fix
|
2019-10-23 18:15:46 +03:00 |
|
alexpetrov12
|
4c84412944
|
added new rule
silenttrinity_stage_ use, sysmon_mimikatz_сreds_dump, sysmon_registry_persistence_key_linking, sysmon_сreds_dump
|
2019-10-23 18:08:30 +03:00 |
|
alexpetrov12
|
bc943343df
|
update win_sysmon_driver_unload
|
2019-10-23 15:41:14 +03:00 |
|
alexpetrov12
|
215e500894
|
fix
|
2019-10-23 14:43:01 +03:00 |
|
alexpetrov12
|
193c95a11a
|
add new rule1
|
2019-10-23 14:27:52 +03:00 |
|
alexpetrov12
|
043e3f7ca6
|
fix
|
2019-10-23 13:48:44 +03:00 |
|
alexpetrov12
|
e38540a37f
|
fix
|
2019-10-23 13:28:04 +03:00 |
|
alexpetrov12
|
c1cfbacd24
|
fix
|
2019-10-23 13:18:57 +03:00 |
|
alexpetrov12
|
ad9b98541c
|
fix
|
2019-10-23 13:05:38 +03:00 |
|
alexpetrov12
|
fa4a8c974d
|
fix
|
2019-10-23 12:45:06 +03:00 |
|
alexpetrov12
|
f4ea01217e
|
fix
|
2019-10-23 02:47:04 +03:00 |
|
alexpetrov12
|
ebe4fe0377
|
fix
|
2019-10-23 02:42:37 +03:00 |
|
alexpetrov12
|
29cd7fed3e
|
fix
|
2019-10-23 02:39:40 +03:00 |
|
alexpetrov12
|
5a260db459
|
fix
|
2019-10-23 02:27:14 +03:00 |
|
alexpetrov12
|
6c4f4ce309
|
fix
|
2019-10-23 02:25:04 +03:00 |
|
alexpetrov12
|
8d0c89b598
|
added new rules
add rule MiniDumpWriteDump via COM+, renamed_binary_description, cobalt_execute_assembly, win_sysmon_driver_onload
|
2019-10-23 01:55:03 +03:00 |
|
Florian Roth
|
3d4ce9d175
|
rule: another reference link for 'execution by ordinal'
|
2019-10-22 15:18:19 +02:00 |
|
Florian Roth
|
b3654947bc
|
rule: suspicious call by ordinal (rundll32)
|
2019-10-22 12:40:26 +02:00 |
|
Florian Roth
|
0f02f2bdfc
|
rule: adjusted very noisy rule on AppLocker whitelist bypass
|
2019-10-22 12:32:37 +02:00 |
|
Florian Roth
|
deb3ecf404
|
fix: relevant fields in lsass dll load rule
|
2019-10-16 19:09:20 +02:00 |
|
Florian Roth
|
ab292a4029
|
rule: simplified Emotet rule
|
2019-10-16 15:29:42 +02:00 |
|
Florian Roth
|
c396526f40
|
rule: LSASS DLL load via undocumented Registry key
https://twitter.com/SBousseaden/status/1183745981189427200
|
2019-10-16 13:18:44 +02:00 |
|
Florian Roth
|
5d143f4f22
|
rule: emotet rule references extended
|
2019-10-16 13:18:44 +02:00 |
|
Florian Roth
|
d46154da5c
|
rule: extending Emotet rule
|
2019-10-16 10:22:48 +02:00 |
|
Florian Roth
|
4ea469d138
|
rule: suspicious compression tool parameters
|
2019-10-15 16:38:53 +02:00 |
|
Florian Roth
|
e870c86fb0
|
rule: keyboad layout preloads extended with '
|
2019-10-15 15:11:00 +02:00 |
|
Florian Roth
|
52fef7ae10
|
Merge pull request #468 from 2d4d/lsass_without_exe
remove .exe from lsass
|
2019-10-14 18:03:13 +02:00 |
|
Florian Roth
|
8db1cac910
|
fix: made rule compatible with event id 4688
|
2019-10-14 18:01:24 +02:00 |
|
Florian Roth
|
0e2284a176
|
rule: modified the default
|
2019-10-14 17:50:48 +02:00 |
|
Florian Roth
|
312311494d
|
rule: suspicious code page switch using chcp
|
2019-10-14 17:45:25 +02:00 |
|
2d4d
|
cf5d7f11ad
|
remove .exe from lsass
|
2019-10-14 17:26:33 +02:00 |
|
Florian Roth
|
7ee3974428
|
rule: suspicious keyboard layout load
|
2019-10-14 16:25:27 +02:00 |
|
Florian Roth
|
5583684efd
|
rule: extended suspicious procdump rule
|
2019-10-14 16:21:37 +02:00 |
|
Florian Roth
|
98f0d01b2e
|
rule: mimikatz use extended
|
2019-10-11 18:50:33 +02:00 |
|
Florian Roth
|
60af1f5a4b
|
rule: WMI Backdoor Exchange Transport Agent
|
2019-10-11 12:12:44 +02:00 |
|
Florian Roth
|
ec5bb71049
|
fix: Mimikatz DC Sync rule FP description and level
|
2019-10-08 17:45:10 +02:00 |
|
Florian Roth
|
14971a7b9c
|
fix: FPs with Mimikatz DC Sync rule
|
2019-10-08 17:44:00 +02:00 |
|
Thomas Patzke
|
60ef593a6f
|
Fixed wrong backslash escaping of *
Fixes issue #466
|
2019-10-07 22:14:44 +02:00 |
|
Florian Roth
|
d096ab0e21
|
rules: AV rules updated to reflect 1.7.2 auf AV cheat sheet
|
2019-10-04 16:17:34 +02:00 |
|
Florian Roth
|
3eaf4d6e94
|
fix: fixed typo in bluemashroom rule
|
2019-10-02 15:45:55 +02:00 |
|