Thomas Patzke
373424f145
Rule fixes
...
Made tests pass the new CI tests. Added further allowed lower case words
in rule test.
2020-02-20 23:00:16 +01:00
Thomas Patzke
d7bd90cb24
Merge branch 'master' into oscd
2020-02-03 23:13:16 +01:00
Thomas Patzke
815c562a17
Merge branch 'master' into oscd
2020-02-02 13:40:08 +01:00
Thomas Patzke
593abb1cce
OSCD QA wave 3
2020-02-02 12:41:12 +01:00
Florian Roth
03ecb3b8dc
refactor: moved rues from 'apt' folder in respective folders
2020-02-01 17:59:26 +01:00
Florian Roth
d42e87edd7
fix: fixed casing and long rule titles
2020-01-30 17:26:09 +01:00
Florian Roth
e79e99c4aa
fix: fixed missing date fields in remaining files
2020-01-30 16:07:37 +01:00
Florian Roth
efd3af0812
fix: fixed missing date fields in other files
2020-01-30 15:32:39 +01:00
Florian Roth
eac484092c
fix: changed hashes field to sha1 for better consistency
2020-01-29 19:52:24 +01:00
Tim Burrell (MSTIC)
9bd0402681
fixup - unique rule id; use process_creation instead of sysmon EventID:1
2020-01-02 20:05:28 +00:00
Tim Burrell (MSTIC)
5051334e85
Sigma queries for
...
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-02 14:47:55 +00:00
Florian Roth
5f061c15d0
fix: fixed missing condition
2019-12-20 15:18:05 +01:00
Florian Roth
bb466407ee
rule: operation Wocao activity
2019-12-20 15:00:07 +01:00
Florian Roth
ab038d1ac7
style: minor changes
2019-12-20 14:59:26 +01:00
Thomas Patzke
924e1feb54
UUIDs + moved unsupported logic
...
* Added UUIDs to all contributed rules
* Moved unsupported logic directory out of rules/ because this breaks CI
testing.
2019-12-19 23:56:36 +01:00
Thomas Patzke
694d666539
Merge branch 'master' into oscd
2019-12-19 23:15:15 +01:00
Thomas Patzke
ef63a65efe
Converted to Unix line end
2019-12-15 23:30:42 +01:00
Yugoslavskiy Daniil
9a511e5e62
fix issue with doubled detection section in apt_silence_downloader_v3.yml
2019-12-15 00:06:28 +01:00
Florian Roth
ab2dd094a5
fix: fixed broken link in elise rule
2019-12-05 09:56:20 +01:00
Yugoslavskiy Daniil
71e588cae1
add apt silence rules by Group-IB
2019-11-28 21:15:55 +01:00
Florian Roth
2c54d1afe4
rule: removed Zebrocy rule because it doesn't work that way
...
reason: command line gets split up at the '&' character, which results in two command lines
2019-11-18 11:42:38 +01:00
Thomas Patzke
0592cbb67a
Added UUIDs to rules
2019-11-12 23:12:27 +01:00
Thomas Patzke
5f6a4225ec
Unified line terminators of rules to Unix
2019-11-12 23:05:36 +01:00
Thomas Patzke
60ef593a6f
Fixed wrong backslash escaping of *
...
Fixes issue #466
2019-10-07 22:14:44 +02:00
Florian Roth
03d45d57de
rule: emissary panda activity
2019-09-03 15:35:33 +02:00
Thomas Patzke
d14f5c3436
Merge pull request #371 from savvyspoon/issue285
...
CAR tagging
2019-06-19 23:21:43 +02:00
Michael Wade
f70549ec54
First Pass
2019-06-13 23:15:38 -05:00
Tareq AlKhatib
3bcfc53905
Corrected Typo
2019-06-10 09:54:37 +03:00
megan201296
74fce5f511
Create apt_oceanlotus_registry.yml
...
Rule based on https://www.welivesecurity.com/2019/03/20/fake-or-fake-keeping-up-with-oceanlotus-decoys/ . Based on OSINT, these keys are unique to the oceanlotus activity and not at all legitimate.
2019-04-14 12:01:52 -05:00
Unknown
9ada22b8e0
adjusted link
2019-04-03 16:40:18 +02:00
Unknown
d2e605fc5c
Auto stash before rebase of "Neo23x0/master"
2019-04-03 16:25:18 +02:00
Liam Sennitt
bb026e4692
fixed tag typo on rules
2019-03-13 10:25:41 +00:00
Liam Sennitt
0aaac1a48e
add tags to crime fireball rule
2019-03-13 10:10:12 +00:00
Liam Sennitt
1e29c9c1ce
add tags to apt zxshell rule
2019-03-13 10:09:05 +00:00
Liam Sennitt
1f47dc1cdc
add tags to apt turla commands rule
2019-03-13 10:06:34 +00:00
Liam Sennitt
96492834c5
add tags to apt sofacy rule
2019-03-13 09:53:02 +00:00
Liam Sennitt
aca36c88cc
add tags to apt slingshot rule
2019-03-13 09:50:39 +00:00
Liam Sennitt
aac632bb41
add tags on apt equationgroup dll_u load rule
2019-03-13 09:48:27 +00:00
Liam Sennitt
5ffc027f22
fix tags in apt carbonpaper turla rule
2019-03-13 09:43:18 +00:00
Liam Sennitt
25b680bfec
fix and add tags to apt bear activity gtr19 rule
2019-03-13 09:40:28 +00:00
Liam Sennitt
3b193fb691
add tags to apt babyshark rule
2019-03-13 09:32:10 +00:00
Liam Sennitt
aee0d1dd67
fix tags on apt29 tor rule
2019-03-13 09:25:28 +00:00
Liam Sennitt
5dc229b590
add tags to apt29 thinktanks rule
2019-03-13 09:22:41 +00:00
Florian Roth
bd38cff042
Merge pull request #272 from LiamSennitt/master
...
fix tagging in turla png dropper service rule
2019-03-11 23:48:18 +01:00
Tareq AlKhatib
075df83118
Converted to use the new process_creation data source
2019-03-09 20:57:59 +03:00
Tareq AlKhatib
879017818f
More conversions to the new process_creation logsource
2019-03-05 09:46:53 +03:00
Tareq AlKhatib
b2952b9f78
Fixing failed CI build - take 2
2019-03-04 16:51:39 +03:00
Tareq AlKhatib
c8be6e649b
Fixing failed CI build
2019-03-04 16:44:30 +03:00
Tareq AlKhatib
45458121c6
Updated to use the new process_creation logsource
2019-03-04 16:13:27 +03:00
Tareq AlKhatib
58c61430a2
updated to use process_creation
2019-03-02 21:05:15 +03:00