Thomas Patzke
|
f118839664
|
Further fixes and deduplications
From suggestions of @yugoslavskiy in issue #554.
|
2020-02-16 14:03:07 +01:00 |
|
Thomas Patzke
|
d7bd90cb24
|
Merge branch 'master' into oscd
|
2020-02-03 23:13:16 +01:00 |
|
Florian Roth
|
848e0c90e4
|
Merge branch 'master' into master
|
2020-01-31 14:45:29 +01:00 |
|
Florian Roth
|
e79e99c4aa
|
fix: fixed missing date fields in remaining files
|
2020-01-30 16:07:37 +01:00 |
|
Thomas Patzke
|
8d6a507ec4
|
OSCD QA wave 1
* Checked all rules against Mordor and EVTX samples datasets
* Added field names
* Some severity adjustments
* Fixes
|
2020-01-11 00:11:27 +01:00 |
|
yugoslavskiy
|
41a09cde34
|
updated filenames
|
2019-11-26 23:31:18 +01:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
yugoslavskiy
|
701e7f7cc6
|
oscd task #2 completed
- new rules:
+ rules/windows/builtin/win_susp_lsass_dump_generic.yml
+
rules/windows/builtin/win_transferring_files_with_credential_data_via_ne
twork_shares.yml
+
rules/windows/builtin/win_remote_registry_management_using_reg_utility.y
ml
+ rules/windows/sysmon/sysmon_unsigned_image_loaded_into_lsass.yml
+ rules/windows/sysmon/sysmon_lsass_memory_dump_file_creation.yml
+
rules/windows/sysmon/sysmon_raw_disk_access_using_illegitimate_tools.yml
+ rules/windows/sysmon/sysmon_cred_dump_tools_dropped_files.yml
+ rules/windows/sysmon/sysmon_cred_dump_tools_named_pipes.yml
+
rules/windows/process_creation/process_creation_shadow_copies_creation.y
ml
+
rules/windows/process_creation/process_creation_shadow_copies_deletion.y
ml
+
rules/windows/process_creation/process_creation_copying_sensitive_files_
with_credential_data.yml
+
rules/windows/process_creation/process_creation_shadow_copies_access_sym
link.yml
+
rules/windows/process_creation/process_creation_grabbing_sensitive_hives
_via_reg.yml
+
rules/windows/process_creation/process_creation_mimikatz_command_line.ym
l
+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_dcsync.yml
+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_netsync.yml
.yml
- updated rules:
+ rules/windows/builtin/win_susp_raccess_sensitive_fext.yml
+ rules/windows/builtin/win_mal_creddumper.yml
+ rules/windows/builtin/win_mal_service_installs.yml
+ rules/windows/process_creation/win_susp_process_creations.yml
+ rules/windows/sysmon/sysmon_powershell_exploit_scripts.yml
+ rules/windows/sysmon/sysmon_mimikatz_detection_lsass.yml
- deprecated rules:
+ rules/windows/process_creation/win_susp_vssadmin_ntds_activity.yml
|
2019-11-04 04:26:34 +03:00 |
|
ecco
|
bdf8f99fdb
|
fix typo
|
2019-09-04 11:31:00 -04:00 |
|
Florian Roth
|
f6fd1df6f4
|
Rule: separate Ryuk rule created for VBurovs strings
|
2019-08-06 10:33:46 +02:00 |
|
Vasiliy Burov
|
3813d277a6
|
Ryuk Ransomware commands from real case
|
2019-06-28 19:26:05 +03:00 |
|
Michael Wade
|
f70549ec54
|
First Pass
|
2019-06-13 23:15:38 -05:00 |
|
Alec Costello
|
886de39814
|
Small edits
Got trigger happy, first time doing this, please dont cruicify me.
|
2019-05-17 17:40:32 +03:00 |
|
Alec Costello
|
34d9b4b365
|
Update win_susp_process_creations.yml
Tested the type method redirecting to a file and dumping the hashes out with pwdump.
Used the wmic method to create the shadow copy.
|
2019-05-17 16:10:43 +03:00 |
|
Florian Roth
|
7b3d67ae66
|
fix: bugfix in new proc creation rule
|
2019-03-02 11:28:13 +01:00 |
|
Thomas Patzke
|
56a1ed1eac
|
Merge branch 'project-1'
|
2019-03-02 00:26:10 +01:00 |
|
Thomas Patzke
|
7602309138
|
Increased indentation to 4
* Converted (to generic sigma) rules
* Converter outputs by default with indentation 4
|
2019-03-02 00:14:20 +01:00 |
|
Thomas Patzke
|
c922f7d73f
|
Merge branch 'master' into project-1
|
2019-02-26 00:24:46 +01:00 |
|
Thomas Patzke
|
96eb460944
|
Converted Sysmon/1 and Security/4688 to generic process creation rules
|
2019-01-16 23:36:31 +01:00 |
|