Florian Roth
|
a9879670c8
|
Merge pull request #1410 from phantinuss/fp-tuning
FP Tunings, fixes and value modifier refactoring
|
2021-04-01 17:44:23 +02:00 |
|
phantinuss
|
4934f80601
|
fix: FP tuning for IIS Express and making use of value modifiers
|
2021-04-01 14:37:20 +02:00 |
|
phantinuss
|
8b4234de3b
|
refactor: make use of value modifiers
|
2021-04-01 14:37:17 +02:00 |
|
phantinuss
|
794865c79d
|
fix: adding filter to condition and reintroducing the users folder constraint
|
2021-04-01 14:37:17 +02:00 |
|
phantinuss
|
43be8c8cba
|
refactor: make use of value modifiers
|
2021-04-01 14:37:16 +02:00 |
|
phantinuss
|
bd5ba2ae01
|
fix: adding only as a known false positive as it cannot be filtered out in a generic and public way
|
2021-04-01 14:37:15 +02:00 |
|
phantinuss
|
65bc62d401
|
fix: adding filter out for CamMute.exe
|
2021-04-01 14:37:14 +02:00 |
|
phantinuss
|
2cab121c71
|
refactor: merging rule process_creation/win_susp_exec_folder.yml and process_creation/win_susp_prog_location_process_starts.yml because of significant overlap
|
2021-04-01 14:37:13 +02:00 |
|
phantinuss
|
109b7890db
|
fix: taking windows security 4688 events into account for filter out
|
2021-04-01 14:36:57 +02:00 |
|
Florian Roth
|
2560f40e06
|
Merge pull request #1406 from roysjosh/winlogbeat-mapping
Map CommandLine appropriately
|
2021-04-01 09:16:28 +02:00 |
|
Joshua Roys
|
30ab2aad75
|
Map CommandLine appropriately
Args is an array of the exploded command line and causes many rules to misfire.
|
2021-03-30 10:15:10 -04:00 |
|
Thomas Patzke
|
eb98f0ba28
|
Merge pull request #1402 from refractionPOINT/lc-support-live-wel
Add option to support different LimaCharlie targets.
|
2021-03-29 23:13:01 +02:00 |
|
Florian Roth
|
ac1f82f7ca
|
Merge pull request #1380 from iosonogio/bugfix/netwitness-null
[bugfix] netwitness and netwitness-epl backends have incoherent null expressions
|
2021-03-29 11:23:18 +02:00 |
|
Florian Roth
|
428db0c74a
|
Merge pull request #1382 from d4rk-d4nph3/master
Added rule for CVE-2021-21978 in VMware View Planner
|
2021-03-29 11:22:56 +02:00 |
|
Florian Roth
|
b296c643de
|
Merge pull request #1346 from blueteam0ps/patch-3
Added win_ad_find_discovery.yml
|
2021-03-29 11:20:49 +02:00 |
|
Florian Roth
|
8262b01e1a
|
Merge pull request #1404 from blueteam0ps/patch-5
Added detection for Dumpert
|
2021-03-29 11:19:57 +02:00 |
|
BlueTeamOps
|
6ef5f0a0a2
|
Added detection for Dumpert
-Dumpert based LSASS dump using DLL
-Dumpert.exe detection
|
2021-03-27 07:34:05 +11:00 |
|
Florian Roth
|
14a872faac
|
Merge pull request #1403 from blueteam0ps/patch-4
Added additional CS signatures
|
2021-03-25 17:18:22 +01:00 |
|
BlueTeamOps
|
8916459bab
|
Added additional CS signatures
|
2021-03-25 22:44:24 +11:00 |
|
Maxime Lamothe-Brassard
|
e0666036a4
|
Add option to support different LimaCharlie targets.
|
2021-03-24 17:58:50 -07:00 |
|
Florian Roth
|
48265ad71a
|
Merge pull request #1398 from SigmaHQ/rule-devel
MSExchange Management log mapping, some fixes
|
2021-03-20 17:21:31 +01:00 |
|
Florian Roth
|
7d7dd4cb67
|
fix: missing index field in FE helix config
|
2021-03-20 09:09:45 +01:00 |
|
Florian Roth
|
8b145e20e4
|
Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel
|
2021-03-20 09:04:40 +01:00 |
|
Florian Roth
|
58a1ab9817
|
fix: wrong indentation in fireeye helix mapping
|
2021-03-20 09:04:38 +01:00 |
|
Florian Roth
|
525f4b6a6b
|
Merge pull request #1388 from Cyb3rPandaH/master
CVE-2021-27065 - Set OabVirtualDirectory ExternalUrl Property
|
2021-03-20 08:53:04 +01:00 |
|
Florian Roth
|
e47ee24889
|
Merge branch 'master' into rule-devel
|
2021-03-20 08:52:55 +01:00 |
|
Florian Roth
|
9e287a1b89
|
feat: MSExchange Management log mapping
|
2021-03-20 08:49:59 +01:00 |
|
Florian Roth
|
1fc408bfaa
|
fix: duplicate field values in YAML configs
|
2021-03-20 08:49:43 +01:00 |
|
Florian Roth
|
334dd9a058
|
Update win_set_oabvirtualdirectory_externalurl.yml
|
2021-03-20 08:34:02 +01:00 |
|
Florian Roth
|
33af006479
|
Merge pull request #1389 from ZikyHD/patch_win_susp_wuauclt
Fix ProcessCommandLine field
|
2021-03-20 08:29:23 +01:00 |
|
Florian Roth
|
01fcfd4f76
|
Merge pull request #1390 from ZikyHD/patch_win_proc_wrong_parent
Add "Microsoft Security Client" directory for MsMpEng.exe (Win<8)
|
2021-03-20 08:29:09 +01:00 |
|
Florian Roth
|
2472926c48
|
Merge pull request #1391 from ZikyHD/patch_win_etw_trace_evasion
Fix win_etw_trace_evasion rule
|
2021-03-20 08:28:51 +01:00 |
|
Florian Roth
|
6ac6b9295b
|
Merge pull request #1392 from hustlibraco/patch-1
Update winlogbeat.yml
|
2021-03-20 08:28:35 +01:00 |
|
Florian Roth
|
a6cd34dbc4
|
Merge pull request #1396 from albchen/patch-1
Updated for use with Image Load events
|
2021-03-20 08:28:19 +01:00 |
|
albchen
|
42e82c95df
|
Updated for use with Image Load events
Added compatibility to add DeviceImageLoadEvents if "image_load" category is found. Also, field ImageLoaded added to the mapping.
|
2021-03-18 15:49:25 -07:00 |
|
Florian Roth
|
dd4a1ac393
|
fix: prone to FPs - use is unclear
https://regex101.com/r/tss5TZ/1
|
2021-03-18 16:44:49 +01:00 |
|
Florian Roth
|
6b2bcd3d87
|
Merge pull request #1395 from SigmaHQ/rule-devel
Rule devel
|
2021-03-18 10:52:02 +01:00 |
|
Florian Roth
|
d30e87d543
|
fix: lsass access - FPs with AV / EDR software
|
2021-03-18 09:04:03 +01:00 |
|
Florian Roth
|
92510e2507
|
extended Exchange post-exploitation rule
|
2021-03-17 18:01:45 +01:00 |
|
Florian Roth
|
6645e2b2dd
|
Merge pull request #1394 from Codehardt/master
fix: syntax error in THOR's config file
|
2021-03-17 16:54:08 +01:00 |
|
Codehardt
|
6d626456f2
|
fix: syntax error in THOR's config file
|
2021-03-17 11:49:50 +01:00 |
|
Florian Roth
|
943f8513e2
|
Merge pull request #1393 from SigmaHQ/rule-devel
Rule devel
|
2021-03-16 16:35:55 +01:00 |
|
Florian Roth
|
bfc99996b5
|
fix: Bug in rule condition
|
2021-03-16 16:35:21 +01:00 |
|
Florian Roth
|
32adf0c3ce
|
fix: prone to FPs
|
2021-03-16 15:52:35 +01:00 |
|
libraco
|
3c5624ca88
|
Update winlogbeat.yml
add `SAMAccountName: winlog.event_data.SamAccountName` mapping for rules/windows/builtin/win_vul_cve_2020_1472.yml
|
2021-03-15 23:54:28 +08:00 |
|
libraco
|
2971a08734
|
Update winlogbeat.yml
add AccessList mapping of winlogbeat for rules/windows/builtin/win_susp_lsass_dump_generic.yml.
|
2021-03-15 23:01:07 +08:00 |
|
zikyhd
|
e91822e070
|
Fix win_etw_trace_evasion rule
|
2021-03-15 15:02:18 +01:00 |
|
Cedric HIEN
|
864973888e
|
Add "Microsoft Security Client" directory for MsMpEng.exe (Win<8)
|
2021-03-15 12:07:05 +01:00 |
|
Cedric HIEN
|
e4f24f4e1f
|
Fix ProcessCommandLine field
|
2021-03-15 11:56:19 +01:00 |
|
Florian Roth
|
310888bae7
|
Merge pull request #1386 from SigmaHQ/rule-devel
Rule devel
|
2021-03-15 10:52:57 +01:00 |
|