Commit Graph

7414 Commits

Author SHA1 Message Date
Nate Guagenti
78c667fda1
Update zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
shorten title
2021-08-23 11:15:30 -04:00
Nate Guagenti
96e77eb8db
Create zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml 2021-08-23 11:06:44 -04:00
frack113
52595de85e
Merge pull request #1889 from rachelrice/update_aws_rules
Update AWS CloudTrail rules
2021-08-23 11:14:31 +02:00
frack113
8f29075129
Merge pull request #1897 from yugoslavskiy/master
add ATC to the "Projects or Products that use Sigma" section
2021-08-23 06:30:16 +02:00
Yugoslavskiy Daniil
9b30b487c3 add ATC to the Projects or Products that use Sigma section 2021-08-23 04:25:29 +02:00
frack113
fc9666fb4e
Merge pull request #1896 from ZikyHD/fix_old_technics
Replace old mitre techniques by new one
2021-08-22 18:56:08 +02:00
frack113
0a410010a2
Merge pull request #1877 from frack113/red_back
Add t1546 redcanary rules
2021-08-22 18:50:58 +02:00
SomeOne
295054dcbe Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
Thomas Patzke
3396d72d81
Merge pull request #1887 from frack113/fix_NodeSubexpression_len
fix sigmac error "has no len()"
2021-08-22 12:11:16 +02:00
Thomas Patzke
cbf1fd213b
Merge pull request #1856 from theoguidoux/sql-sqlite-fields-selection
[Ready] SQL & SQLite rule fields selection
2021-08-22 12:09:07 +02:00
Thomas Patzke
b97a47c32a
Merge pull request #1895 from frack113/fix_sigma2attack.py
sigma2attack.py fix yaml error
2021-08-22 12:05:54 +02:00
Thomas Patzke
ac8cf2b2c7
Merge pull request #1783 from iChenLei/update-ci-badge
chore: update sigma ci badge
2021-08-22 12:05:23 +02:00
frack113
7cd71b2240 fix yaml error 2021-08-22 08:57:07 +02:00
frack113
b84b301add
Merge pull request #1894 from austinsonger/master
Update m365.yml
2021-08-22 07:52:58 +02:00
Austin Songer
579a80411d
Update m365.yml 2021-08-21 15:03:31 -05:00
Austin Songer
645492cef5
Update m365.yml
just working on expanding this.
2021-08-21 14:57:38 -05:00
frack113
064c65cb1f
Merge pull request #1892 from frack113/clean_PS
Powershell Cleanup
2021-08-21 18:04:52 +02:00
frack113
07a87aa7f8
Merge pull request #1858 from frack113/fix_pr718
Replace pr718
2021-08-21 18:02:30 +02:00
frack113
16347e77e4
Merge pull request #1893 from pbssubhash/master
Adding a rule to detect WriteHijack DLL exploitation by PowerUp
2021-08-21 18:00:40 +02:00
frack113
a44206bfa0
Some cleanup 2021-08-21 17:33:39 +02:00
pbssubhash
7bcb6494b7 Merge branch 'master' of https://github.com/pbssubhash/sigma 2021-08-21 20:04:15 +05:30
pbssubhash
eee497f656 Title modification 2021-08-21 20:04:03 +05:30
frack113
73c953d633
Fix title 2021-08-21 16:18:16 +02:00
pbssubhash
a415463f5b Modified rule 2021-08-21 19:37:28 +05:30
pbssubhash
fba54b8d69 First Rule commit 2021-08-21 17:47:56 +05:30
frack113
42c90b9d20 fix powershell_psattack error 2021-08-21 10:05:47 +02:00
frack113
2f683b9ab7 fix powershell_clear_powershell_history error 2021-08-21 10:00:48 +02:00
frack113
0fb6c35b1f Cleanup PS rules 2021-08-21 09:58:58 +02:00
frack113
da839775fe Update PS rules 2021-08-21 09:50:59 +02:00
frack113
6c529f7ab2 Update PS rules 2021-08-21 09:33:52 +02:00
frack113
cb95582077 Update PowerShell rule 2021-08-21 09:08:38 +02:00
frack113
dbbb422a42
Merge pull request #1885 from austinsonger/microsoft365_unusual_volume_of_file_deletion.yml
microsoft365_unusual_volume_of_file_deletion.yml
2021-08-20 17:20:43 +02:00
frack113
34ac3587e9
Merge pull request #1884 from austinsonger/microsoft365_potential_ransomware_activity.yml
microsoft365_potential_ransomware_activity.yml
2021-08-20 17:20:34 +02:00
frack113
73fee68d4b
Merge pull request #1883 from austinsonger/microsoft365_user_restricted_from_sending_email.yml
microsoft365_user_restricted_from_sending_email.yml
2021-08-20 17:20:22 +02:00
frack113
b9a355e3f4
cleanup falsepositives 2021-08-20 17:18:32 +02:00
Florian Roth
b92346ba5f
Merge pull request #1882 from austinsonger/win_susp_bitstransfer.yml
win_susp_bitstransfer.yml
2021-08-20 16:53:52 +02:00
Florian Roth
ecd0bb4576
Merge pull request #1890 from frack113/update_conti_ref
update ref from conti_leak
2021-08-20 16:53:12 +02:00
Florian Roth
700b8e440f
Merge pull request #1868 from d4rk-d4nph3/master
Added rule for zero day CVE-2021-22123 in Fortinet WAFs
2021-08-20 16:52:49 +02:00
Rachel Rice
f037f5b0a9
Add filter3 back for vm export failure, without consolelogin
Signed-off-by: Rachel Rice <rachel.rice@lacework.net>
2021-08-20 15:42:49 +01:00
frack113
5cfadf5d64
Merge pull request #1891 from frack113/fix_sigma_similarity_backend_error
sigma_similarity fix when backend support error
2021-08-20 15:38:28 +02:00
Austin Songer
a25f6e196f
Update microsoft365_unusual_volume_of_file_deletion.yml 2021-08-20 08:17:25 -05:00
Austin Songer
360b936357
Update microsoft365_potential_ransomware_activity.yml 2021-08-20 08:17:09 -05:00
Austin Songer
ae36804935
Update microsoft365_user_restricted_from_sending_email.yml 2021-08-20 08:16:48 -05:00
Rachel Rice
f09b3ea4b1
Update AWS CloudTrail rules
aws_ec2_disable_encryption.yml
Remove `status: success` from selection criteria, not required

aws_ec2_vm_export_failure.yml
Remove filter3:
```
eventName: 'ConsoleLogin'
responseElements|contains: 'Failure'
```
Incompatible with selection criteria `eventName: 'CreateInstanceExportTask'`

aws_ec2_download_userdata.yml, aws_iam_backdoor_users_keys.yml, aws_rds_change_master_password.yml, aws_rds_public_db_restore.yml
Update reference

aws_sts_assumedrole_misuse.yml
Rename to aws_sts_assumerole_misuse.yml
Update references to "AssumedRole" to "AssumeRole"
Update selection criteria of `userIdentity.sessionContext: Role` to `userIdentity.sessionContext.sessionIssuer.type: Role`
2021-08-20 13:43:00 +01:00
frack113
7ebd411190 update ref from conti_leak 2021-08-20 14:22:17 +02:00
frack113
f6fe5e7d02 fix when backend support error 2021-08-20 13:58:57 +02:00
frack113
4e895da471 fix error "has no len()" 2021-08-20 09:20:56 +02:00
frack113
4e29dc9c45
fix title 2021-08-20 09:06:16 +02:00
frack113
9b106dcc7d
Merge pull request #1880 from austinsonger/azure_suppression_rule_created.yml
azure_suppression_rule_created.yml
2021-08-20 09:04:48 +02:00
frack113
d58b1e8e40
Merge pull request #1879 from austinsonger/azure_application_gateway_modified_or_deleted.yml
azure_application_gateway_modified_or_deleted.yml
2021-08-20 09:03:57 +02:00