j91321
|
bc442d3021
|
Add path with lowercase system32
|
2020-03-24 19:48:24 +01:00 |
|
Thomas Patzke
|
815c562a17
|
Merge branch 'master' into oscd
|
2020-02-02 13:40:08 +01:00 |
|
Thomas Patzke
|
9bb50f3d60
|
OSCD QA wave 2
* Improved rules
* Added filtering
* Adjusted severity
|
2020-01-17 15:46:28 +01:00 |
|
GelosSnake
|
f574c20432
|
Update win_system_exe_anomaly.yml
fixing to much original fork.
|
2019-12-29 18:02:49 +02:00 |
|
GelosSnake
|
7e7f6d1182
|
Update win_system_exe_anomaly.yml
Following sigma event I've noticed my twitter account was referenced:
https://twitter.com/GelosSnake/status/934900723426439170
Rule:
https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_system_exe_anomaly.yml
Seems like - '\SystemRoot\System32\\*' is missing and hence triggering an FP.
|
2019-12-29 18:01:19 +02:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Denys Iuzvyk
|
774be4d008
|
Escaped '\*' to '\*' where required
|
2019-09-04 14:05:58 +03:00 |
|
Thomas Patzke
|
25c0330dca
|
Added filter
|
2019-05-10 00:20:56 +02:00 |
|
Karneades
|
b47900fbee
|
Add default path to filter for explorer in exe anomaly rule
|
2019-04-21 17:42:47 +02:00 |
|
Thomas Patzke
|
49beb5d1a8
|
Integrated PR from @P4T12ICK in existing rule
PR #321
|
2019-04-21 00:28:40 +02:00 |
|
Karneades
|
d75ea35295
|
Restrict whitelist filter in system exe anomaly rule
|
2019-04-18 22:06:12 +02:00 |
|
Yugoslavskiy Daniil
|
8bec627ff1
|
fixed multiple tags issue
|
2019-03-06 06:09:37 +01:00 |
|
mrblacyk
|
99595a7f89
|
Added missing tags and some minor improvements
|
2019-03-05 23:25:49 +01:00 |
|
Thomas Patzke
|
7602309138
|
Increased indentation to 4
* Converted (to generic sigma) rules
* Converter outputs by default with indentation 4
|
2019-03-02 00:14:20 +01:00 |
|
Thomas Patzke
|
c922f7d73f
|
Merge branch 'master' into project-1
|
2019-02-26 00:24:46 +01:00 |
|
Thomas Patzke
|
96eb460944
|
Converted Sysmon/1 and Security/4688 to generic process creation rules
|
2019-01-16 23:36:31 +01:00 |
|