Cyb3rEng
49df2358de
Completed changes to selection1
...
completed changes to selection1 to comply with rule creation guide with no ( * ) or ( \\ )
- Image|endswith: '\wbem\WMIC.exe'
- ProcessCommandLine|contains: 'wmic '
2021-09-08 21:12:27 -06:00
Cyb3rEng
a3236e62a2
Changed selection2 conditions
...
replaced *\wbem\WMIC.exe with Image|endswith: '\wbem\WMIC.exe' and ProcessCommandLine: *wmic * with ProcessCommandLine|contains: 'wmic '
2021-09-08 21:10:47 -06:00
Cyb3rEng
1f577174f9
Changed endswith condition
...
removed double // from "\wbem\WmiPrvSE.exe"
2021-09-08 21:06:41 -06:00
Cyb3rEng
6ddc83901b
Changed Category
...
Category Changed from process_creation to file_event
2021-09-08 20:38:07 -06:00
Cyb3rEng
5ac0fded26
Merge branch 'SigmaHQ:master' into master
2021-09-08 20:26:59 -06:00
Florian Roth
72ffe99b20
Merge pull request #2001 from SigmaHQ/rule-devel
...
filter: empty thumbprint, PetitPotam rule
2021-09-08 09:09:58 +02:00
frack113
993112c7eb
Merge pull request #2002 from frack113/missing_tag
...
Add missing Tags #1974
2021-09-08 06:26:55 +02:00
frack113
e712d9696b
Merge pull request #2000 from frack113/split_global
...
Split frack113 global rules
2021-09-08 06:26:35 +02:00
Cyb3rEng
e3b376e945
Completed Changes Based on Comments
...
Removed :
unnecessary event ID
2021-09-07 21:26:42 -06:00
Cyb3rEng
4130ceb208
Completed Changes Based on Comments
...
Removed :
unnecessary event ID
2021-09-07 21:25:52 -06:00
Cyb3rEng
8d47f9531b
Completed Changes Based on Comments
...
Removed :
unnecessary event ID
2021-09-07 21:22:01 -06:00
Cyb3rEng
13e6262055
Completed Changes Based on Comments
...
Removed :
unnecessary event ID
2021-09-07 21:20:51 -06:00
Cyb3rEng
8dc1b03fef
Completed Changes Based on Comments
...
Removed :
unnecessary event ID
2021-09-07 21:19:43 -06:00
Cyb3rEng
bd4d21c41c
Completed changes based on comments
...
Removed :
unnecessary event ID
2021-09-07 21:17:12 -06:00
Cyb3rEng
75a6e5c95b
Completed Changes as per comments
...
Removed :
unnecessary event ID
2021-09-07 21:14:06 -06:00
Cyb3rEng
3b2ebe1580
Completed changes
...
Removed :
unnecessary event ID
2021-09-07 21:12:02 -06:00
Cyb3rEng
8467d5a65a
Modified Rule
...
Removed :
unnecessary event ID
2021-09-07 21:09:07 -06:00
Cyb3rEng
f0f3ecfe2f
Converted to LF
...
Removed :
unnecessary event ID
2021-09-07 21:00:35 -06:00
Cyb3rEng
932b7cf2ba
Merge branch 'SigmaHQ:master' into master
2021-09-07 19:58:09 -06:00
Thomas Patzke
d9edc9f0e3
Merge branch 'fix'
2021-09-08 00:19:09 +02:00
Thomas Patzke
143744bc12
Various fixes
...
* Backslashes in regular expressions
* Casing of condition operators
* Further small errors
2021-09-07 23:38:07 +02:00
frack113
4c3f8821c4
add missing tags
2021-09-07 18:16:46 +02:00
frack113
4e394d83a1
add missing tags
2021-09-07 17:45:41 +02:00
Rachel Rice
be5351947c
Unset date update
...
Signed-off-by: Rachel Rice <rachel.rice@lacework.net>
2021-09-07 16:36:59 +01:00
Florian Roth
1a55f4a294
filter: empty thumbprint, PetitPotam rule
2021-09-07 14:37:03 +02:00
Rachel Rice
eef6e71e2e
Update AWS Update Login Profile Rule fields
...
Missed updating field from `responseElements.accessKey.userName` to `requestParameters.userName` on last update.
2021-09-07 12:39:56 +01:00
frack113
0e5e4fa19d
Split global rules
2021-09-07 13:30:32 +02:00
Florian Roth
cfbde22d2d
rule: PRIVATELOG image load
2021-09-07 10:10:14 +02:00
Florian Roth
3a305e82b9
fix: remove renamed files
2021-09-07 09:28:20 +02:00
Florian Roth
a8d8d878a0
remove uppercase files
2021-09-07 09:27:11 +02:00
Florian Roth
8b4fce3473
removed unneeded upper ticks
2021-09-07 09:21:44 +02:00
Florian Roth
c082ce0fe0
Merge branch 'master' into rule-devel
2021-09-07 09:20:47 +02:00
Florian Roth
57bfdc7a02
fix: more upper case chars
2021-09-07 09:19:23 +02:00
Florian Roth
0cce1c0245
fix: missing lowercase chars
2021-09-07 09:17:25 +02:00
Florian Roth
33be089ea2
fix: filename to lowercase
2021-09-07 09:16:35 +02:00
frack113
4f6b87fed5
Merge pull request #1997 from zakibro/master
...
New Rule - Linux Hidden Files and Directories
2021-09-07 09:12:04 +02:00
zakibro
bba66ca762
Update lnx_auditd_hidden_files_directories.yml
...
Updating arguments section
2021-09-07 07:57:50 +02:00
frack113
be442182fe
convert to LF
2021-09-06 21:10:08 +02:00
frack113
9ef299c4f4
Change to LF
2021-09-06 21:07:49 +02:00
frack113
3b95b0c913
Remove useless Eventid
...
Use tools/config/generic/windows-audit.yml to convert for security 4688
2021-09-06 20:56:41 +02:00
zakibro
e9fa5bde2b
Update lnx_auditd_hidden_files_directories.yml
...
Correction of tag
2021-09-06 18:55:58 +02:00
Pawel Mazur
7c2895c73f
New Rule - Linux Hidden Files and Directories
2021-09-06 18:43:49 +02:00
Pawel Mazur
59eb7ce032
Merge branch 'master' of https://github.com/zakibro/sigma
2021-09-06 18:41:19 +02:00
Pawel Mazur
9f5f25e480
New Rule - Linux Hidden Files and Directories
2021-09-06 18:40:39 +02:00
zakibro
f52860d6ab
Merge branch 'SigmaHQ:master' into master
2021-09-06 18:40:02 +02:00
Pawel Mazur
3eb354e34c
Merge branch 'master' of https://github.com/zakibro/sigma
2021-09-06 18:37:45 +02:00
Pawel Mazur
ef3efd8fd3
New Rule Linux - Hidden Files and Directories
2021-09-06 18:37:02 +02:00
Austin Songer
0de95e355a
Update azure_federation_modified.yml
2021-09-06 11:31:52 -05:00
Austin Songer
e6e3fc2eec
Update azure_federation_modified.yml
2021-09-06 11:16:35 -05:00
Austin Songer
6025df63ee
Create azure_federation_modified.yml
2021-09-06 11:06:58 -05:00