Hendrik
|
7e742cc049
|
kibana-ndjson for all configs which already have kibana
|
2020-11-09 08:46:17 +01:00 |
|
Pushkarev Dmitry
|
1da229e3a9
|
Added AppLocker log source
|
2020-07-13 20:20:28 +00:00 |
|
Thomas Patzke
|
43e5ae5d24
|
Added Windows NTLM log source + fixes
|
2020-07-02 23:20:36 +02:00 |
|
j91321
|
ae842a65cb
|
Windows Defender rules and logsource
|
2020-06-28 10:55:32 +02:00 |
|
Thomas Patzke
|
24b08bbf30
|
Merge branch 'master' of https://github.com/socprime/sigma into socprime-master
|
2020-05-24 17:06:32 +02:00 |
|
vh
|
e8b956f575
|
Updated config
|
2020-05-20 12:35:00 +03:00 |
|
neu5ron
|
177f0a783b
|
winlogbeat forward (at a snails pace) ECS field names
|
2020-05-19 04:58:51 -04:00 |
|
Remco Hofman
|
c5be83eb01
|
Added ee-outliers backend
|
2020-05-08 10:18:35 +02:00 |
|
Thomas Patzke
|
5b42135935
|
Added es-rule backend to all ES configurations
|
2020-02-24 23:20:48 +01:00 |
|
Thomas Patzke
|
8d6a507ec4
|
OSCD QA wave 1
* Checked all rules against Mordor and EVTX samples datasets
* Added field names
* Some severity adjustments
* Fixes
|
2020-01-11 00:11:27 +01:00 |
|
Thomas Patzke
|
991108e64d
|
Further proxy field name fixes (config + rules)
|
2019-12-07 00:23:30 +01:00 |
|
ecco
|
4c5eab88b6
|
add GroupSid to other configs
|
2019-09-11 04:53:30 -04:00 |
|
Thomas Patzke
|
b9ff280209
|
Cleanup of configuration names
|
2019-07-14 00:50:15 +02:00 |
|