G Y
a60a2feb17
Update sysmon_susp_pfx_file_creation.yml
...
Fixed typo.
2021-07-04 10:38:53 +08:00
Bhabesh Rai
37d5d1c0ca
Added new path
2021-07-01 16:24:07 +05:45
Bhabesh Rai
206adbb2b6
Merging upstream updates
2021-07-01 12:18:30 +05:45
Bhabesh Rai
56eed19fba
Added rules for successful exploitation fo CVE-2021-26857/8 in Exchannge
2021-03-03 12:46:50 +05:45
Florian Roth
de5444a81e
Merge pull request #989 from oscd-initiative/master
...
[OSCD Initiative][ATT&CK tags update]
2020-09-08 13:27:58 +02:00
ecco
b9f7d58dbc
fix ADSI rule false positive
2020-09-06 09:17:53 -04:00
Yugoslavskiy Daniil
42c4079ed8
att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other
2020-08-25 01:09:17 +02:00
Poming huang
2b2bf34a64
add wmi persistence script event consumer false positive
2020-07-20 12:27:16 +08:00
Aidan Bracher
dcf20e580d
Updated tags to include sub-techniques
2020-07-18 02:50:57 +01:00
Aidan Bracher
23dd2e3cac
Updated to include sub-technique mapping
2020-07-18 02:29:58 +01:00
Brad Kish
c758ca0eb9
Re-fix sysmon rules that are lost changes with category refactoring.
...
Several fixes for sysmon rules got lost when the rules were refactored to use
categories.
Re-add the fixes.
38afd8b5de
422b2bffd7
dfae2a6df6
2020-07-06 10:55:42 -04:00
Brad Kish
1e9d0e9653
Fixes for rules in the sysmon file_event category
...
Fix a couple of typos
For sysmon_hack_dumpert:
Make sure the logsource is category file_event and not sysmon. Don't set
the category at the global level. Instead set in the individual document.
2020-07-03 16:22:29 -04:00
Florian Roth
abf5f799d6
docs: more references
2020-07-03 13:19:44 +02:00
Florian Roth
1f0b1e58a9
fix: bugs in rule and title
2020-07-03 09:54:10 +02:00
Florian Roth
33fef8bcf5
DesktopImgDownLdr rules
2020-07-03 09:45:48 +02:00
Florian Roth
9c0f9f398f
refactor: sysmon rule cleanup > generlization
2020-07-01 10:58:39 +02:00
Florian Roth
154181c6c8
fix: renamed files and lien break change
2020-07-01 09:48:48 +02:00
Florian Roth
d70b63b78c
rule: RedMimicry rules (modified)
2020-07-01 09:17:31 +02:00
Florian Roth
f3fedef8f5
Changed category names and remove sysmon log source
2020-06-24 17:41:21 +02:00