frack113
ad376a8328
Fix falsepositives list
2021-05-21 12:28:12 +02:00
frack113
2197514fc5
Fix falsepositives list
2021-05-21 12:26:37 +02:00
frack113
48a7e80192
Fix falsepositives list
2021-05-21 12:24:25 +02:00
frack113
6630ec7c41
Fix falsepositives list
2021-05-21 12:23:09 +02:00
frack113
a9e85ca58e
Fix falsepositives list
2021-05-21 12:22:36 +02:00
frack113
f4be70aa9e
Fix falsepositives list
2021-05-21 12:19:17 +02:00
frack113
f312663820
Fix falsepositives list
2021-05-21 11:29:17 +02:00
frack113
6878bfade9
Fix falsepositives list
2021-05-21 11:17:36 +02:00
frack113
cabaccceb8
Fix falsepositives list
2021-05-21 11:15:10 +02:00
frack113
45190c3874
Fix falsepositives list
2021-05-21 11:13:27 +02:00
frack113
dfe7e4e38c
Fix falsepositives list
2021-05-21 11:12:04 +02:00
Florian Roth
a0efd7a4dc
Merge pull request #1494 from Karneades/patch-1
...
Add keyword WinRM to remote powershell rules
2021-05-21 10:35:18 +02:00
Andreas Hunkeler
e58c59dcfd
Update modified field in WinRM rule
2021-05-21 09:29:11 +02:00
Andreas Hunkeler
d8ec5fa6af
Add modified field in WinRM rule
2021-05-21 09:28:45 +02:00
frack113
42dad6cd9f
Merge branch 'SigmaHQ:master' into es_rule_uuid
2021-05-21 09:28:11 +02:00
Florian Roth
a30391f3b4
Merge pull request #1495 from SigmaHQ/rule-devel
...
rule refactoring: Cobalt Strike service start
2021-05-20 17:43:29 +02:00
Florian Roth
a34949c7fb
Merge pull request #1493 from Karneades/WinRM
...
rule: add rule to detect shell spawn from WinRM host process
2021-05-20 17:35:06 +02:00
Andreas Hunkeler
93241e7fc6
Add keyword WinRM to remote powershell process rule
2021-05-20 17:03:32 +02:00
Andreas Hunkeler
b46f65965d
Add keyword WinRM to remote powershell network rule
2021-05-20 17:02:17 +02:00
Andreas Hunkeler
3763e54b99
Add keyword WinRM to remote powershell process rule
2021-05-20 17:00:25 +02:00
Andreas Hunkeler
226a666827
rule: add rule to detect shell spawn from WinRM host process
2021-05-20 16:05:13 +02:00
frack113
b92b765f9a
Fix import to kibana error 400 severity is invalid.
2021-05-20 13:14:43 +02:00
frack113
cbb81cdf86
Fix import to kibana error 400 rish_score is null.
...
rish_score is a integer.
If level is invalid set to medium
2021-05-20 12:32:19 +02:00
frack113
f0974e9cf3
Fix : **false_positives** must be a array.
...
If null add "Unknown".
If it is a string convert to a simple array row
2021-05-20 11:20:38 +02:00
Florian Roth
ebac8a098f
rule refactoring: Cobalt Strike service start
2021-05-20 10:05:12 +02:00
frack113
76523c5dbf
fix [ #1486 ]( https://github.com/SigmaHQ/sigma/issues/1486 ).
...
rule_id is always an uuid now.
For the rule-collection with only one uuid :
- first detection get the uuid
- other detection get a new uuid
it is a palliative, because the secondary uuid are not kept between 2 launches.
best practice is to use one uuid per detection and not files.
2021-05-20 08:42:58 +02:00
Jonhnathan
1cf7bb5735
Add Hex equivalent of WriteData
2021-05-19 10:27:20 -03:00
Florian Roth
18bbb2a342
Merge pull request #1490 from frack113/ElasticSearchRuleBackend
...
FIx ElasticSearchRuleBackend to use uuid instead of title for the rule id
2021-05-18 20:01:25 +02:00
Sven Scharmentke
a36bc55b06
Updated uberAgent backend to support version 6.1.
2021-05-18 12:07:09 +02:00
frack113
3b23c18f70
If not null use uuid instead of title for the rule id
2021-05-17 22:12:17 +02:00
Darin Smith
e921181f4b
Add AWS snapshot exfiltration rule
2021-05-17 13:00:01 -07:00
V1D1AN
56e3a6aaf3
Update ecs-zeek-elastic-beats-implementation.yml
2021-05-16 22:53:25 +02:00
SomeOne
e46ae5a28c
Add filter on sdiagnhost.exe in Suspicious In-Memory Module Execution rule
2021-05-16 16:03:33 +02:00
SomeOne
a93acbbe03
Exclude dism.exe
2021-05-16 15:23:31 +02:00
SomeOne
53b21d1afe
Add Sysmon EventID 11, 17 and 18 to win_tool_psexec rule
2021-05-16 15:03:58 +02:00
SomeOne
a788cd43ee
Add Windows Defender on WL
2021-05-16 14:10:33 +02:00
Florian Roth
5a3af872d8
Merge pull request #1479 from SigmaHQ/rule-devel
...
Rule devel, Trademark test
2021-05-15 13:42:34 +02:00
Florian Roth
9b32e72d0b
fix: syntax issue
2021-05-15 13:19:12 +02:00
Florian Roth
02bf32ce6c
fixed more legal issues
2021-05-15 13:09:08 +02:00
Florian Roth
526ab4f707
feat: trademark test case
2021-05-15 13:02:49 +02:00
Florian Roth
48757423ef
rule darkside patterns
2021-05-14 18:06:53 +02:00
Florian Roth
a655c5c1a0
update ngrok rule
2021-05-14 17:44:53 +02:00
Florian Roth
e4a1ce4498
rule: ngrok rdp port exposure
2021-05-14 17:34:52 +02:00
Florian Roth
3cf1be9e8d
rule: exchange vulnerability CVE-2021-28480
2021-05-14 10:08:41 +02:00
Florian Roth
691283616f
Merge pull request #1477 from wagga40/master
...
Resolves #1450 - Bug in es-rule backend when using "-r" argument
2021-05-14 09:00:30 +02:00
Florian Roth
bd81adc998
Merge pull request #1476 from wagga40/master
...
Change to have raw log in rule results with SQL/SQlite Backends
2021-05-14 08:59:57 +02:00
Florian Roth
30bee7204c
Merge pull request #1475 from wagga40/master
...
Modified some field values for case sensitive backends (SQL)
2021-05-14 08:59:39 +02:00
Florian Roth
83068416fa
Merge pull request #1458 from P4rtyH4RD/P4rtyH4RD-patch-1-mitre-code
...
Update powershell_suspicious_getprocess_lsass.yml
2021-05-14 08:59:14 +02:00
Florian Roth
09e32ae02e
Merge pull request #1474 from frack113/Check_category
...
Check category
2021-05-14 08:58:46 +02:00
wagga40
534898a3ce
Resolves #1450 - Bug in es-rule backend when using "-r" argument
2021-05-13 21:47:22 +02:00