Commit Graph

7512 Commits

Author SHA1 Message Date
mlp1515
7ad927f28e
Update win_wmiprvse_spawning_process.yml
French language settings
2021-08-26 12:42:47 +00:00
mlp1515
644397e65c
Update win_exploit_cve_2019_1388.yml
French language settings
2021-08-26 12:41:36 +00:00
frack113
f277ecbbeb
Merge pull request #1923 from frack113/fix_invalid_tags
Check invalid tags
2021-08-25 10:26:43 +02:00
frack113
a6767255c0
Merge pull request #1922 from frack113/missing
add gworkspace_user_granted_admin_privileges.yml
2021-08-25 09:16:44 +02:00
frack113
a4021842de Fix invalid tags 2021-08-25 09:15:57 +02:00
frack113
1d725e8519 add gworkspace_user_granted_admin_privileges.yml 2021-08-25 08:15:18 +02:00
frack113
061c093f3f
Merge pull request #1918 from d4rk-d4nph3/master
Added rule for Arcadyan Router Exploitations
2021-08-25 08:10:48 +02:00
Bhabesh Rai
df4180547e Merged rules 2021-08-25 11:18:51 +05:45
Bhabesh Rai
a4d0e3453d Fix for CVE tag 2021-08-25 10:24:15 +05:45
frack113
e849af9df0
Merge pull request #1915 from frack113/tags_cve
fix tags
2021-08-25 06:29:48 +02:00
frack113
7028aba3bd
Merge pull request #1919 from austinsonger/gworkspace-rules
Role-Based Rules
2021-08-24 21:46:15 +02:00
frack113
09a00232fb
update references 2021-08-24 21:14:59 +02:00
frack113
a5f858b63c
update references 2021-08-24 21:13:49 +02:00
frack113
962b6ac077
Merge pull request #1917 from austinsonger/spelling
Spelling fix
2021-08-24 21:06:34 +02:00
Austin Songer
ab8cc52dc6 Role-Based Rules 2021-08-24 10:53:59 -05:00
Bhabesh Rai
ce6141e318 Added rule for Arcadyan Router Exploitations 2021-08-24 21:11:46 +05:45
Austin Songer
62f2affd03 Spelling fix 2021-08-24 14:15:50 +00:00
Florian Roth
9f69cead8a
Merge pull request #1916 from SigmaHQ/rule-devel
refactor: changed level of rule, refactored RazerInstaller rule
2021-08-24 15:42:26 +02:00
Florian Roth
46e312ff0d
fix: error in modifier 2021-08-24 15:03:23 +02:00
Florian Roth
cc519552aa
refactor: RazorInstaller integrity level system 2021-08-24 14:54:07 +02:00
frack113
7753f8c22e fix tags 2021-08-24 12:36:31 +02:00
Florian Roth
6ca30619ac
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel 2021-08-24 12:30:42 +02:00
Florian Roth
3cdb88ad55
refactor: level of suspicious parent for powershell rule 2021-08-24 12:30:40 +02:00
frack113
5b869a3f42 Update cve tags 2021-08-24 10:50:01 +02:00
frack113
ace46c17be Update cve tags 2021-08-24 10:27:27 +02:00
frack113
c2302a15da fix cve tags 2021-08-24 10:10:45 +02:00
frack113
8f85ac0fde tags update 2021-08-24 09:35:04 +02:00
Florian Roth
0c69fd9c41
Merge pull request #1898 from SigmaHQ/rule-devel
rule: EfsPotato Named Pipe, splwow64, RazerInstaller
2021-08-24 09:20:54 +02:00
frack113
679651bdf9
Merge pull request #1913 from neu5ron/add_zeek_dce_rpc_printnightmare_print_driver_install
Zeek DCE_RPC PrintNightmare
2021-08-24 08:37:02 +02:00
frack113
e76c11da7f
Merge pull request #1908 from neu5ron/patch-7
improve rule logic zeek_default_cobalt_strike_certificate.yml
2021-08-24 08:36:33 +02:00
frack113
293f422243
Merge pull request #1906 from neu5ron/patch-5
improve zeek_dce_rpc_smb_spoolss_named_pipe
2021-08-24 08:36:18 +02:00
frack113
81ec546e42
Merge pull request #1905 from neu5ron/patch-4
improve rule
2021-08-24 08:36:04 +02:00
Florian Roth
272625a005
Update win_susp_splwow64.yml 2021-08-24 08:34:08 +02:00
frack113
15aa0cb70e
add modified 2021-08-24 08:02:24 +02:00
frack113
ade7295cab
Merge pull request #1911 from austinsonger/gworkspace_granted_domain_api_access.yml
gworkspace_granted_domain_api_access.yml
2021-08-24 08:01:34 +02:00
frack113
4ee4f12f30
add modified 2021-08-24 08:01:01 +02:00
frack113
8ab90d8012
add modified 2021-08-24 07:59:36 +02:00
frack113
be43ecd70d
Remove empty element in list
Otherwise get a `null` when convert to some backend (es-rule,...)
2021-08-24 07:57:16 +02:00
frack113
d8befe3a13
Update References 2021-08-24 07:34:33 +02:00
frack113
07dc04b1db
Merge pull request #1910 from austinsonger/gworkspace_user_assigned_admin_role.yml
gworkspace_user_assigned_admin_role.yml
2021-08-24 07:22:25 +02:00
frack113
831a473c0d
Merge pull request #1904 from austinsonger/365
Microsoft 365 Rules
2021-08-24 07:17:24 +02:00
neu5ron
9e588fdcf6 Zeek dce_rpc.log Detection of print driver installs over RPC (ie: possible PrintNightmare) using the three existing known RPC functions, as well as few others "discussed" but not directly related to PrintNightmare PoC or public post-compromise write-ups. 2021-08-24 00:58:36 -04:00
Austin Songer
facd58bd0a
Delete gworkspace_user_granted_admin_privileges.yml 2021-08-23 21:19:51 -05:00
Austin Songer
3cd43bfd9b
Create gworkspace_granted_domain_api_access.yml 2021-08-23 21:19:44 -05:00
Austin Songer
aa7a8a3e71
Update gworkspace_user_granted_admin_privileges.yml 2021-08-23 19:58:20 -05:00
Austin Songer
0fe2b3f569
Update and rename gworkspace_user_assigned_admin_role.yml to gworkspace_user_granted_admin_privileges.yml 2021-08-23 19:52:32 -05:00
Austin Songer
ede0332f22
Delete microsoft365_suspicious_inbox_manipulation_rules.yml 2021-08-23 19:40:20 -05:00
Austin Songer
3dd201d36f
Rename workspace_user_assigned_admin_role.yml to gworkspace_user_assigned_admin_role.yml 2021-08-23 19:38:58 -05:00
Austin Songer
6b1f0b83f4
Create workspace_user_assigned_admin_role.yml 2021-08-23 19:38:47 -05:00
Austin Songer
c767da91d1
Delete gworkspace_user_assigned_admin_role.yml 2021-08-23 19:38:01 -05:00