Florian Roth
|
7cc1b300d2
|
rule: maze ransomware patterns
|
2020-05-08 11:42:06 +02:00 |
|
Florian Roth
|
28953a2942
|
fix: MITRE tags in rule
|
2020-03-25 18:11:04 +01:00 |
|
Florian Roth
|
6584729a0d
|
rule: powershell downloadfile
|
2020-03-25 14:58:14 +01:00 |
|
Florian Roth
|
35e43db7a7
|
fix: converted CRLF line break to LF
|
2020-03-25 14:36:34 +01:00 |
|
Florian Roth
|
17297193c7
|
Merge branch 'master' into devel
|
2020-03-25 14:18:11 +01:00 |
|
Florian Roth
|
50b0d04ee8
|
rule: Exploited CVE-2020-10189 Zoho ManageEngine
|
2020-03-25 14:02:53 +01:00 |
|
Florian Roth
|
28d8b87a0f
|
rule: extended web shell spawn rule
|
2020-03-25 14:02:39 +01:00 |
|
Thomas Patzke
|
c10332b06c
|
Merge pull request #663 from neu5ron/updates_sigmac_and_rules
Updates sigmac and rules
|
2020-03-22 00:22:31 +01:00 |
|
Florian Roth
|
6040b1f1f8
|
Merge pull request #668 from Neo23x0/devel
Devel
|
2020-03-19 18:36:31 +01:00 |
|
Florian Roth
|
8454f60a8e
|
fix: reduced level due to false positives
|
2020-03-17 20:40:28 +01:00 |
|
neu5ron
|
4c94906d53
|
rule should be wildcard AND had a prepended ^ in one of the CommandLine conditions that would have caused to not trigger
|
2020-03-14 15:00:42 -04:00 |
|
neu5ron
|
4b572f3ccb
|
newline in description - typo
|
2020-03-14 14:58:58 -04:00 |
|
Florian Roth
|
cbf0f43934
|
Merge pull request #655 from msec1203/msec1203-patch-1
add rule for suspicious use of csharp console by scripting utility
|
2020-03-09 18:01:12 +01:00 |
|
Florian Roth
|
6845fa21b3
|
fix: fixed several issues
|
2020-03-09 17:43:16 +01:00 |
|
ecco
|
2489b8534c
|
sysmon registry events fix
|
2020-03-09 12:02:04 -04:00 |
|
Florian Roth
|
ddefb3bc58
|
Merge branch 'master' into devel
|
2020-03-07 11:06:25 +01:00 |
|
Florian Roth
|
07914c2783
|
Merge pull request #652 from 2XXE-SRA/patch-1
MMC Lateral Movement Rule 1
|
2020-03-07 11:02:16 +01:00 |
|
Florian Roth
|
2e184382f5
|
fix: eventid in process_creation rules
|
2020-03-07 10:43:47 +01:00 |
|
Florian Roth
|
7e8b59abe6
|
Merge pull request #643 from grumo35/patch-2
Update sysmon_cred_dump_tools_dropped_files.yml
|
2020-03-07 10:39:35 +01:00 |
|
Florian Roth
|
c609de4f27
|
Merge pull request #648 from NVISO-BE/patch-azure-ad-replication
Exclude Azure AD sync accounts from AD Replication rule
|
2020-03-07 10:39:04 +01:00 |
|
Florian Roth
|
b040c129be
|
fix: author field starting with an '@' symbol
|
2020-03-07 10:38:02 +01:00 |
|
2XXE (SRA)
|
ae56db97ff
|
mmc lateral movement detection 1
see https://github.com/Neo23x0/sigma/issues/576
|
2020-03-04 14:57:41 -05:00 |
|
ecco
|
b9e4734087
|
fix sysmon registry rules with HKLM/HKU format as used since 02/2017 in sysmon
|
2020-03-04 12:47:42 -05:00 |
|
Florian Roth
|
6bbb166f3d
|
rule: extended webshell rule with tomcat.exe
|
2020-03-04 14:25:57 +01:00 |
|
Florian Roth
|
53278c2a46
|
Merge pull request #649 from Neo23x0/devel
fix: avoiding FPs with Citrix software
|
2020-03-03 11:35:02 +01:00 |
|
Florian Roth
|
f98ad7a8df
|
fix: wrong identifier
|
2020-03-03 11:25:02 +01:00 |
|
Florian Roth
|
be4242aca8
|
fix avoiding FPs with MpCmdRun
ParentImage: C:\Windows\System32\services.exe
CommandLine: C:\Program Files\Microsoft Security Client\\MpCmdRun.exe
|
2020-03-03 11:16:59 +01:00 |
|
Florian Roth
|
7139bfb0cb
|
fix: avoiding FPs with Citrix software
writing C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\__PSScriptPolicyTest_r23phtye.jsp.ps1
|
2020-03-03 11:01:42 +01:00 |
|
Remco Hofman
|
d4b5dd5749
|
Exclude Azure AD sync accounts from AD Replication rule
|
2020-03-02 16:43:20 +01:00 |
|
Thomas Patzke
|
b63889af75
|
Fixed rules that likely will cause false negatives by fix
|
2020-03-01 23:14:53 +01:00 |
|
Thomas Patzke
|
0a62b8747e
|
Merge pull request #634 from EccoTheFlintstone/fp_fix3
Rule: restore initial behaviour matching single word with spaces on each side
|
2020-03-01 22:40:24 +01:00 |
|
Florian Roth
|
19d383989c
|
fix: keyword expression in rule
|
2020-02-29 16:03:31 +01:00 |
|
Florian Roth
|
fa6458b70f
|
rule: two rules to detect CVE-2020-0688 exploitation
|
2020-02-29 15:45:45 +01:00 |
|
Florian Roth
|
fdcba84fc8
|
fix: escaped backslash
|
2020-02-29 10:12:59 +01:00 |
|
grumo35
|
0d932810b5
|
Update sysmon_cred_dump_tools_dropped_files.yml
Adding sysinternal's procdump utility more about this on : https://en.hackndo.com/remote-lsass-dump-passwords/
|
2020-02-28 15:16:18 +01:00 |
|
Florian Roth
|
f88225dd2a
|
Merge pull request #640 from Neo23x0/devel
fix: broader exclusion for rule - OneDrive false positives
|
2020-02-26 18:41:52 +01:00 |
|
Florian Roth
|
6bbd80a8ee
|
fix: broader exclusion for rule - OneDrive false positives
|
2020-02-26 18:31:58 +01:00 |
|
Florian Roth
|
ada0edb822
|
Merge pull request #621 from wagga40/new_koadic_rule
New Koadic detection rule
|
2020-02-26 13:25:03 +01:00 |
|
Florian Roth
|
0ba6874645
|
Merge pull request #638 from Neo23x0/devel
Several false positives with new rules
|
2020-02-26 09:46:02 +01:00 |
|
Florian Roth
|
1c90d6badd
|
level increased
|
2020-02-26 09:42:31 +01:00 |
|
Florian Roth
|
c8afd4a16b
|
Merge pull request #637 from tjgeorgen/patch-1
fix missing status & description in status field
|
2020-02-26 09:40:55 +01:00 |
|
Florian Roth
|
031e6d3ee6
|
Merge pull request #635 from EccoTheFlintstone/fix_fp4
wmiprvse subprocess: add fallback check on username instead of only l…
|
2020-02-26 09:40:34 +01:00 |
|
Florian Roth
|
4f3e3166d3
|
fixing false positives
|
2020-02-26 09:33:55 +01:00 |
|
Florian Roth
|
82d2b1e6f0
|
Merge branch 'master' into devel
# Conflicts:
# rules/windows/process_creation/win_susp_squirrel_lolbin.yml
|
2020-02-26 09:27:48 +01:00 |
|
Florian Roth
|
e7aff17e72
|
FP: OneDrive setup
|
2020-02-26 09:26:19 +01:00 |
|
Tom Georgen
|
74f3fe70cc
|
fix missing status & description in status field
|
2020-02-25 16:30:41 -05:00 |
|
Florian Roth
|
a152853ac3
|
Merge pull request #624 from Antonlovesdnb/master
New rules for Macro Detections
|
2020-02-25 15:44:31 +01:00 |
|
Antonlovesdnb
|
e8b861bff4
|
Update sysmon_susp_winword_vbadll_load.yml
|
2020-02-25 09:24:29 -05:00 |
|
Antonlovesdnb
|
4c5d489428
|
Update sysmon_susp_office_kerberos_dll_load.yml
|
2020-02-25 09:23:52 -05:00 |
|
Antonlovesdnb
|
f92e2f2b18
|
Update sysmon_susp_office_dotnet_assembly_dll_load.yml
|
2020-02-25 09:23:22 -05:00 |
|