Commit Graph

7556 Commits

Author SHA1 Message Date
Nico
5f271bf334 add author field to elastic rule 2021-08-30 08:29:07 +02:00
frack113
970dfa2f92
Merge pull request #1938 from EvanYu0816/upstream-fixes
Fix Pass the Hash and NotPetya Ransomware rule
2021-08-28 21:02:04 +02:00
frack113
a7456d4d6c
Merge pull request #1940 from frack113/fix_ps_fp
Powershell correction
2021-08-28 20:48:07 +02:00
frack113
3e355c64db
Merge pull request #1939 from SigmaHQ/rule-devel
rule: UAC bypass by mocking dirs
2021-08-28 20:47:27 +02:00
frack113
68237dffc4 fix HostApplication 2021-08-28 08:18:47 +02:00
frack113
ef6e0c5a4c Fix error and FP 2021-08-28 08:02:16 +02:00
Florian Roth
f78225c394
rule: UAC bypass by mocking dirs 2021-08-27 18:12:21 +02:00
Evan Yu
178d82e9cd Fix NotPetya Ransomware rule 2021-08-27 11:53:50 -04:00
Evan Yu
8bdd3e3987 Simplify Pass the Pash rule 2021-08-27 11:53:28 -04:00
frack113
ff37a49dc0
Merge pull request #1930 from SigmaHQ/rule-devel
fix: FPs with whoami rule and 4688 event IDs without parent info
2021-08-27 06:27:30 +02:00
frack113
0de795b0a2
Merge pull request #1936 from austinsonger/gworkspace_application_remove.yml
add gworkspace_application_remove.yml
2021-08-27 06:25:15 +02:00
frack113
00cceb7be8
Merge pull request #1935 from austinsonger/gworkspace_mfa_disabled.yml
add gworkspace_mfa_disabled.yml
2021-08-27 06:24:26 +02:00
frack113
b10629f4d8
Merge pull request #1934 from OTRF/feature/AADHealth-Agent-HybridADFSServices
Feature/aad health agent hybrid adfs services
2021-08-27 06:22:18 +02:00
frack113
1baa678df0
Merge pull request #1933 from hazedav/lacework
new lacework backend
2021-08-27 06:15:09 +02:00
Austin Songer
72485a5619
Update gworkspace_application_removed.yml 2021-08-26 21:16:21 -05:00
Austin Songer
62cefcc028
Rename gworkspace_application_remove.dyml to gworkspace_application_removed.yml 2021-08-26 21:15:56 -05:00
Austin Songer
bc246ff59d
Rename gworkspace_application_remove.yml to gworkspace_application_remove.dyml 2021-08-26 20:58:22 -05:00
Austin Songer
55f5ff3d89 Application Removed 2021-08-26 20:55:07 -05:00
Austin Songer
1fffb7a3f5 Gworkspace MFA disabled. 2021-08-26 20:28:35 -05:00
Roberto Rodriguez
f05cf20b12 Merge branch 'master' into feature/AADHealth-Agent-HybridADFSServices 2021-08-26 16:12:38 -04:00
Roberto Rodriguez
f98970ef06 adding basic rules to detect behavior around AAD health agents and AAD Hybrid Health AD FS services in Azure 2021-08-26 16:10:42 -04:00
David Hazekamp
cc6e4381b2
feat(backend): introducing lacework backend
Adding authors
Removing todo
2021-08-26 14:12:47 -05:00
David Hazekamp
a5d175fbf7
feat(backend): introducing lacework backend 2021-08-26 14:05:44 -05:00
frack113
a6149462d8
Merge pull request #1931 from phantinuss/master
More malleable CobaltStrike C2 profiles from new source/reference
2021-08-26 17:18:19 +02:00
frack113
59000b993d
Merge pull request #1932 from mlp1515/french_user
Add French user
2021-08-26 17:12:39 +02:00
phantinuss
e59b8e1e3e
add applicable pipe names from regex rule 2021-08-26 14:53:20 +02:00
mlp1515
cce7cfc79a
Update win_tool_psexec.yml
French language settings
2021-08-26 12:51:45 +00:00
mlp1515
e1aa82b412
Update win_susp_tscon_localsystem.yml
French language settings
2021-08-26 12:50:24 +00:00
mlp1515
e9ed5f592c
Update sysmon_always_install_elevated_windows_installer.yml
French language settings
2021-08-26 12:48:59 +00:00
mlp1515
4f49f03460
Update sysmon_abusing_debug_privilege.yml
French language settings
2021-08-26 12:46:15 +00:00
mlp1515
a31422db74
Update win_susp_schtask_creation.yml
French language settings
2021-08-26 12:45:24 +00:00
mlp1515
5f419d6f35
Update win_susp_taskmgr_localsystem.yml
French language settings
2021-08-26 12:44:35 +00:00
mlp1515
5545403a9b
Update win_whoami_as_system.yml
French language settings
2021-08-26 12:43:33 +00:00
mlp1515
7ad927f28e
Update win_wmiprvse_spawning_process.yml
French language settings
2021-08-26 12:42:47 +00:00
mlp1515
644397e65c
Update win_exploit_cve_2019_1388.yml
French language settings
2021-08-26 12:41:36 +00:00
phantinuss
dc19268583
remove becasue of possible conflict
with a legitimate tool (https://labs.nettitude.com/blog/cve-2017-16245-cve-2017-16246-avecto-defendpoint-multiple-vulnerabilities/)
2021-08-26 14:25:12 +02:00
Florian Roth
6c7d355ef5
Try to add more pipe names to this non-regex rule 2021-08-26 14:00:57 +02:00
Florian Roth
c86bcf3d25
Merge pull request #1927 from frack113/check_date_order
check valid date order
2021-08-26 13:55:39 +02:00
Florian Roth
2d36d62e88
Merge pull request #1928 from frack113/fix_name_case
fix file name case
2021-08-26 13:55:12 +02:00
Florian Roth
24d8701f15
fix: null cannot be used in a list with other values 2021-08-26 13:54:18 +02:00
Florian Roth
a231aa73b3
fix: FPs with whoami rule and 4688 event IDs without parent info 2021-08-26 13:33:25 +02:00
Florian Roth
54997553ba
Merge pull request #1929 from SigmaHQ/rule-devel
refactor: Mimikatz keyword rule refactoring
2021-08-26 13:33:02 +02:00
phantinuss
217dbc768a
More malleable CobaltStrike C2 profiles from new source/reference 2021-08-26 12:53:43 +02:00
Florian Roth
8b318b9273
refactor: Mimikatz keyword rule refactoring 2021-08-26 12:51:45 +02:00
f.hubaut
e66007a43d fix file name case 2021-08-26 11:15:33 +02:00
frack113
3eb3377a7b check valid date order 2021-08-26 06:51:37 +02:00
frack113
f277ecbbeb
Merge pull request #1923 from frack113/fix_invalid_tags
Check invalid tags
2021-08-25 10:26:43 +02:00
frack113
a6767255c0
Merge pull request #1922 from frack113/missing
add gworkspace_user_granted_admin_privileges.yml
2021-08-25 09:16:44 +02:00
frack113
a4021842de Fix invalid tags 2021-08-25 09:15:57 +02:00
frack113
1d725e8519 add gworkspace_user_granted_admin_privileges.yml 2021-08-25 08:15:18 +02:00