Commit Graph

4044 Commits

Author SHA1 Message Date
toffeebr33k
a786ebd04b
Update aws_enum_listing.yml 2020-11-21 23:28:57 +08:00
toffeebr33k
1ca903b168
Update aws_enum_listing.yml 2020-11-21 23:22:07 +08:00
toffeebr33k
7f61591865
Add files via upload 2020-11-21 23:12:50 +08:00
Thomas Patzke
0ed54a6cae
Merge pull request #1290 from arollyson/helix_backend
Backend: FireEye Helix
2020-11-21 00:06:19 +01:00
Alek Rollyson
83b8af6cd2 Add FirEye Helix backend 2020-11-19 11:18:28 -05:00
Florian Roth
7566f19635
Merge pull request #1267 from w0rk3r/ecs-1
Suricata ECS
2020-11-17 15:05:47 +01:00
Florian Roth
9944c0e563 Merge branch 'master' into pr/1267 2020-11-17 14:33:55 +01:00
Florian Roth
1540241106 Merge branch 'master' of https://github.com/Neo23x0/sigma 2020-11-17 14:29:42 +01:00
Florian Roth
88e3de816d docs: uberAgent ESA target in README 2020-11-17 14:29:36 +01:00
Florian Roth
c5c6557ca2
Merge pull request #1256 from vastlimits/master
Backend: uberAgent ESA converter backend
2020-11-17 14:29:01 +01:00
Florian Roth
94540ea0b6
Merge pull request #1284 from heyibrahimkhan/master
added role name field to ecs-cloudtrail.
2020-11-17 14:24:40 +01:00
heyibrahimkhan@gmail.com
eed4fe04d5 added role name field to ecs-cloudtrail. 2020-11-13 05:59:55 +05:00
Sven Scharmentke
446b0b7f9d Merge branch 'master_origin' 2020-11-11 12:32:53 +01:00
Sven Scharmentke
a58d04e4df Rules: Support image_load 2020-11-11 12:31:55 +01:00
Thomas Patzke
43b9b17767
Merge pull request #1281 from andurin/kibana-ndjson-configs
kibana-ndjson for all configs which already have kibana
2020-11-11 07:34:37 +01:00
Florian Roth
af4d546408
Merge pull request #1282 from Neo23x0/rule-devel
fix: FPs with notepad++ GUP rule
2020-11-10 13:39:28 +01:00
Florian Roth
2e9d7951a6
Merge pull request #1272 from bczyz1/patch-2
Fix typo in win_apt_lazarus_session_hijack.yml
2020-11-10 13:35:08 +01:00
Florian Roth
230562bdf6
Merge pull request #1278 from K-Yo/update-navigator-v4
Update navigator v4
2020-11-10 13:34:46 +01:00
Florian Roth
c087e39698
Merge pull request #1277 from K-Yo/fix-unicode-error
Fix unicode error in sigma2attack
2020-11-10 13:34:05 +01:00
Florian Roth
f6c0fb2d33 fix: FPs with notepad++ GUP rule 2020-11-09 16:34:12 +01:00
Hendrik
7e742cc049 kibana-ndjson for all configs which already have kibana 2020-11-09 08:46:17 +01:00
Thomas Patzke
485457ee55
Merge pull request #1280 from andurin/kibana-ndjson
Elasticsearch Kibana ndjson backend
2020-11-06 13:44:00 +01:00
Hendrik
96e90fbff2 Fix recursion of rules 2020-11-06 12:43:52 +01:00
Olivier Caillault
34f24a60a1 Updating attack navigator version to v4.0 2020-11-05 23:37:01 +01:00
Hendrik
bf5d40eec3 New Backend - Kibana NDJSON
Tested against 7.9.3
2020-11-05 23:34:25 +01:00
K-Yo
c17c1fa96b
Merge pull request #1 from K-Yo/fix-unicode-error
Fix unicode error in sigma2attack
2020-11-05 22:39:54 +01:00
Olivier Caillault
31639366cd Fix unicode error in sigma2attack 2020-11-05 22:30:12 +01:00
Florian Roth
6dfeb6a63b
Merge pull request #1276 from Neo23x0/rule-devel
rule: FPs with WmiPrvSE rule
2020-11-05 17:04:25 +01:00
Florian Roth
c3785d6dc7 rule: FPs with WmiPrvSE rule 2020-11-05 16:44:33 +01:00
Florian Roth
784150b66c
Merge pull request #1273 from Neo23x0/rule-devel
rule: added second expression
2020-11-04 17:09:47 +01:00
Florian Roth
908023fa66 rule: added second expression 2020-11-04 16:43:35 +01:00
bczyz1
4a5b2d642e
Fix typo in win_apt_lazarus_session_hijack.yml 2020-11-03 14:46:29 +01:00
Florian Roth
413abf13cd
Merge pull request #1270 from Neo23x0/rule-devel
rule: reworked weblogic CVE-2020-14882 rule
2020-11-03 10:40:39 +01:00
Florian Roth
f848bb912c rule: reworked weblogic CVE-2020-14882 rule 2020-11-03 10:39:40 +01:00
Florian Roth
b218264d47
Merge pull request #1268 from Neo23x0/rule-devel
rule: WebLogic exploit CVE-2020-14882
2020-11-03 10:35:05 +01:00
Thomas Patzke
c202feaf87
Merge pull request #1269 from Neo23x0/ci
Removed ES query tests
2020-11-02 23:11:05 +01:00
Thomas Patzke
31241d9bbd
Removed ES query tests 2020-11-02 22:57:01 +01:00
Florian Roth
dd0d1d053c rule: WebLogic exploit CVE-2020-14882 2020-11-02 11:11:37 +01:00
Jonhnathan
9173fb2cb9
Update Makefile 2020-11-01 21:28:26 -03:00
Jonhnathan
83f2646667 Merge branch 'ecs-1' of https://github.com/w0rk3r/sigma into ecs-1 2020-11-01 21:22:48 -03:00
Jonhnathan
21161c82cc Revert "Create win_susp_replace_lolbin.yml"
This reverts commit e6a6549676.
2020-11-01 21:21:47 -03:00
Jonhnathan
90e211bad8
Create ecs-suricata.yml 2020-11-01 21:21:04 -03:00
Jonhnathan
c84641d332 Revert "Changed the rule to download only and not the copy"
This reverts commit 1324bc1ad1.
2020-11-01 20:36:02 -03:00
Jonhnathan
972a04fb60 Revert "Update win_susp_replace_lolbin.yml"
This reverts commit 6b2c235ab3.
2020-11-01 20:35:59 -03:00
Florian Roth
6f9aeb5ea9
Merge pull request #1263 from Neo23x0/rule-devel
feat: cover newest emotet campaigns
2020-10-24 00:02:39 +02:00
Florian Roth
75637324e0
feat: cover newest emotet campaigns 2020-10-23 23:44:48 +02:00
Thomas Patzke
16d63cc5d2 Decreased coverage requirement 2020-10-23 20:17:58 +02:00
Thomas Patzke
f0e89b0c8c Fixed: typecheck in sumologig-cse 2020-10-23 19:49:55 +02:00
Thomas Patzke
e30237c5c5 Fixed test configuration 2020-10-23 19:30:59 +02:00
Thomas Patzke
2fb7dd5e99 Fixes
* Removed Splunk regex query
* Added test for sumologic-cse backend
2020-10-23 15:31:00 +02:00