Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
Thomas Patzke
|
01d6c3b58d
|
Fixes
|
2020-02-16 23:24:00 +01:00 |
|
Thomas Patzke
|
f118839664
|
Further fixes and deduplications
From suggestions of @yugoslavskiy in issue #554.
|
2020-02-16 14:03:07 +01:00 |
|
Thomas Patzke
|
d7bd90cb24
|
Merge branch 'master' into oscd
|
2020-02-03 23:13:16 +01:00 |
|
Florian Roth
|
e79e99c4aa
|
fix: fixed missing date fields in remaining files
|
2020-01-30 16:07:37 +01:00 |
|
yugoslavskiy
|
efc404fbae
|
resolve conflicts with rule IDs; restored and deprecated sysmon_mimikatz_detection_lsass.yml
|
2019-11-19 02:11:19 +01:00 |
|
yugoslavskiy
|
334626168c
|
Update win_mal_service_installs.yml
|
2019-11-14 00:43:03 +03:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
yugoslavskiy
|
701e7f7cc6
|
oscd task #2 completed
- new rules:
+ rules/windows/builtin/win_susp_lsass_dump_generic.yml
+
rules/windows/builtin/win_transferring_files_with_credential_data_via_ne
twork_shares.yml
+
rules/windows/builtin/win_remote_registry_management_using_reg_utility.y
ml
+ rules/windows/sysmon/sysmon_unsigned_image_loaded_into_lsass.yml
+ rules/windows/sysmon/sysmon_lsass_memory_dump_file_creation.yml
+
rules/windows/sysmon/sysmon_raw_disk_access_using_illegitimate_tools.yml
+ rules/windows/sysmon/sysmon_cred_dump_tools_dropped_files.yml
+ rules/windows/sysmon/sysmon_cred_dump_tools_named_pipes.yml
+
rules/windows/process_creation/process_creation_shadow_copies_creation.y
ml
+
rules/windows/process_creation/process_creation_shadow_copies_deletion.y
ml
+
rules/windows/process_creation/process_creation_copying_sensitive_files_
with_credential_data.yml
+
rules/windows/process_creation/process_creation_shadow_copies_access_sym
link.yml
+
rules/windows/process_creation/process_creation_grabbing_sensitive_hives
_via_reg.yml
+
rules/windows/process_creation/process_creation_mimikatz_command_line.ym
l
+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_dcsync.yml
+
rules/windows/unsupported_logic/builtin/dumping_ntds.dit_via_netsync.yml
.yml
- updated rules:
+ rules/windows/builtin/win_susp_raccess_sensitive_fext.yml
+ rules/windows/builtin/win_mal_creddumper.yml
+ rules/windows/builtin/win_mal_service_installs.yml
+ rules/windows/process_creation/win_susp_process_creations.yml
+ rules/windows/sysmon/sysmon_powershell_exploit_scripts.yml
+ rules/windows/sysmon/sysmon_mimikatz_detection_lsass.yml
- deprecated rules:
+ rules/windows/process_creation/win_susp_vssadmin_ntds_activity.yml
|
2019-11-04 04:26:34 +03:00 |
|
Michael Wade
|
f70549ec54
|
First Pass
|
2019-06-13 23:15:38 -05:00 |
|
David Spautz
|
e275d44462
|
Add tags to windows builtin rules
|
2018-07-24 07:50:32 +02:00 |
|
Thomas Patzke
|
84645f4e59
|
Simplified rule conditions with new condition constructs
|
2018-03-06 23:14:43 +01:00 |
|
Florian Roth
|
aca70e57ec
|
Massive Title Cleanup
|
2018-01-27 10:57:30 +01:00 |
|
Florian Roth
|
e06cf6c43f
|
Service install - net user persistence
|
2017-08-16 15:16:57 +02:00 |
|
Florian Roth
|
01e1d3a3d7
|
WannaCry Service Install
|
2017-05-15 16:06:16 +02:00 |
|
Florian Roth
|
707e5a948f
|
Rules: Password dumper activity and lateral movement
|
2017-03-27 15:20:50 +02:00 |
|