ecco
|
7a1d48cccd
|
fix: PsExec false positives
|
2019-09-26 04:50:43 -04:00 |
|
ecco
|
0c96777f6a
|
sysmon rules cleanup and move to process_creation
|
2019-09-11 10:24:43 -04:00 |
|
Florian Roth
|
038900e2fe
|
fix: renamed powershell rule
|
2019-09-06 17:33:56 +02:00 |
|
Florian Roth
|
7f1b6eb311
|
fix: duplicate rule
|
2019-09-06 10:30:47 +02:00 |
|
Florian Roth
|
fcbae16cc8
|
rule: image debugger
|
2019-09-06 10:28:20 +02:00 |
|
ecco
|
01956f1312
|
powershell false positives
|
2019-09-06 03:54:19 -04:00 |
|
Denys Iuzvyk
|
774be4d008
|
Escaped '\*' to '\*' where required
|
2019-09-04 14:05:58 +03:00 |
|
Florian Roth
|
ca2019b57f
|
fix: typo in MITRE tag
|
2019-08-27 12:32:56 +02:00 |
|
Florian Roth
|
6b7cd94197
|
Changes
|
2019-08-27 12:23:42 +02:00 |
|
weev3
|
d42a51372d
|
Control Panel Item, MITRE_ID=T1196
|
2019-08-27 14:55:55 +06:30 |
|
Thomas Patzke
|
68fb56f503
|
Merge pull request #345 from ki11oFF/patch-1
Detection of usage mimikatz trough WinRM
|
2019-08-23 23:04:07 +02:00 |
|
Florian Roth
|
c291038ebe
|
rule: renamed powershell
|
2019-08-22 14:22:55 +02:00 |
|
Karneades
|
18bbec4bcd
|
improve(rule): add Empire links and userland match
Add default task name and powershell task command to match what the rule name says: detects default config.
|
2019-08-09 11:58:43 +02:00 |
|
Florian Roth
|
f3fb2b41b2
|
Rule: FP filters extended
|
2019-07-23 14:58:36 +02:00 |
|
Christophe Tafani-Dereeper
|
5bc10a4855
|
Include Github raw URLs in suspicious downloads detection rule
|
2019-07-05 09:01:35 +00:00 |
|
Thomas Patzke
|
dbbc1751ef
|
Converted rule to generic log source
|
2019-06-19 23:25:25 +02:00 |
|
Thomas Patzke
|
d14f5c3436
|
Merge pull request #371 from savvyspoon/issue285
CAR tagging
|
2019-06-19 23:21:43 +02:00 |
|
Thomas Patzke
|
d82df83ef1
|
Merge pull request #369 from TareqAlKhatib/refactors
Refactors
|
2019-06-19 23:16:19 +02:00 |
|
Michael Wade
|
f70549ec54
|
First Pass
|
2019-06-13 23:15:38 -05:00 |
|
Sherif Eldeeb
|
2d22a3fe02
|
Add detection for recent Mimikatz versions
GrantedAccess is 0x1010 not 0x1410 in recent versions of mimikatz.
This modification should address both
|
2019-06-12 12:13:31 +03:00 |
|
Thomas Patzke
|
5715413da9
|
Usage of Channel field name in ELK Windows config
|
2019-06-11 13:15:43 +02:00 |
|
Tareq AlKhatib
|
fce2a45dac
|
Corrected Typo
|
2019-06-10 09:51:34 +03:00 |
|
Florian Roth
|
7b63c92fc0
|
Rule: applying recommendation
https://twitter.com/SwiftOnSecurity/status/1131464234901094400
|
2019-05-23 09:44:25 +02:00 |
|
Olaf Hartong
|
b60cfbe244
|
Added password flag
|
2019-05-22 13:20:26 +02:00 |
|
Florian Roth
|
346022cfe8
|
Transformed to process creation rule
|
2019-05-22 12:50:49 +02:00 |
|
Olaf Hartong
|
4a775650a2
|
Rule Windows 10 scheduled task SandboxEscaper 0-day
|
2019-05-22 12:36:03 +02:00 |
|
Olaf Hartong
|
e675cdf9c4
|
Rule Windows 10 scheduled task SandboxEscaper 0-day
|
2019-05-22 12:32:07 +02:00 |
|
Olaf Hartong
|
544dfe3704
|
Rule Windows 10 scheduled task SandboxEscaper 0-day
|
2019-05-22 12:28:42 +02:00 |
|
Florian Roth
|
c937fe3c1b
|
Rule: Terminal Service Process Spawn
|
2019-05-22 10:38:27 +02:00 |
|
Florian Roth
|
74ca0eeb88
|
Rule: Renamed PsExec
|
2019-05-21 09:49:40 +02:00 |
|
Patryk
|
c163dcbe05
|
Update sysmon_mimikatz_trough_winrm.yml
Deleted tab character (\t)
|
2019-05-20 13:22:36 +02:00 |
|
Patryk
|
a9faa3dc33
|
Create sysmon_mimikatz_trough_winrm.yml
Detects usage of mimikatz through WinRM protocol
|
2019-05-20 12:25:58 +02:00 |
|
Florian Roth
|
694fa567b6
|
Reformatted
|
2019-05-15 20:22:53 +02:00 |
|
Florian Roth
|
1c36bfde79
|
Bugfix - Swisscom in Newline
|
2019-05-15 15:03:55 +02:00 |
|
Florian Roth
|
d5f49c5777
|
Fixed syntax
|
2019-05-15 14:50:57 +02:00 |
|
Florian Roth
|
508d1cdae0
|
Removed double back slashes
|
2019-05-15 14:46:45 +02:00 |
|
Unknown
|
13522b97a7
|
Adjusting Newline
|
2019-05-15 12:15:41 +02:00 |
|
Unknown
|
275896dbe6
|
Suspicious Outbound RDP Rule likely identifying CVE-2019-0708
|
2019-05-15 11:47:12 +02:00 |
|
Florian Roth
|
f78413deab
|
Merge pull request #309 from jmlynch/master
added rules for renamed wscript, cscript and paexec. Added two direct…
|
2019-04-17 23:59:27 +02:00 |
|
Florian Roth
|
daaee558a1
|
Rule: added date to Tom's WMI rule
|
2019-04-15 09:06:53 +02:00 |
|
Florian Roth
|
65b81dad32
|
Rule: Suspicious scripting in a WMI consumer
|
2019-04-15 08:13:35 +02:00 |
|
Jason Lynch
|
f0c8c428bb
|
added rules for renamed wscript, cscript and paexec. Added two directories to the existing sysmon_susp_prog_location_network_connection rule. These additions are all fin7 related.
|
2019-04-08 08:07:30 -04:00 |
|
Florian Roth
|
81693d81b6
|
Merge pull request #295 from sbousseaden/master
Create win_atsvc_task.yml
|
2019-04-04 18:32:13 +02:00 |
|
Karneades
|
865d971704
|
Remove backslashes in CommandLine for sticky key rule
Example command line is exactly "cmd.exe sethc.exe 211".
=> the detection with *\cmd.exe... would not match.
|
2019-04-03 16:16:18 +02:00 |
|
sbousseaden
|
3d69727332
|
Create sysmon_rdp_settings_hijack.yml
|
2019-04-03 14:16:25 +02:00 |
|
sbousseaden
|
016261cacf
|
Update sysmon_lsass_memdump.yml
|
2019-04-03 14:06:49 +02:00 |
|
sbousseaden
|
a85c668f6f
|
Update sysmon_lsass_memdump.yml
|
2019-04-03 14:00:51 +02:00 |
|
sbousseaden
|
32c6b34746
|
Create sysmon_lsass_memdump.yml
|
2019-04-03 13:51:59 +02:00 |
|
sbousseaden
|
ddb2d92a98
|
Create sysmon_tsclient_filewrite_startup.yml
|
2019-04-03 13:19:59 +02:00 |
|
Tareq AlKhatib
|
783d8c4268
|
Reverting back to regular Sysmon 1 to fix CI test
|
2019-03-09 21:31:56 +03:00 |
|