Commit Graph

7595 Commits

Author SHA1 Message Date
frack113
af599e4877
Merge pull request #1958 from phantinuss/master
Bulk of new rules, mainly UAC Bypasses
2021-09-01 10:53:02 +02:00
phantinuss
9ffdced740
fix: implement suggestions from PR discussion 2021-09-01 10:21:37 +02:00
frack113
3ed7d6e330
Merge pull request #1959 from frack113/update_ps
Update PowerShell rules
2021-09-01 08:06:31 +02:00
frack113
b8a1f4c63b
Merge pull request #1961 from SigmaHQ/rule-devel
SideWalk User-Agent used by Sparkling Goblin
2021-09-01 08:06:15 +02:00
frack113
9671d6c0db
Merge pull request #1960 from austinsonger/sysmon_dns_over_https_enabled.yml
sysmon_dns_over_https_enabled.yml
2021-08-31 18:37:29 +02:00
Florian Roth
9b20060275
SideWalk UA 2021-08-31 17:14:19 +02:00
frack113
cff572b752
Update sysmon_dns_over_https_enabled.yml 2021-08-31 17:11:04 +02:00
phantinuss
add1ad40f8
additional UAC bypass rule 2021-08-31 16:23:32 +02:00
phantinuss
59d8e0b866
add System IntegrityLevel to uac bypass rules, the level is not used most of the time, but might 2021-08-31 16:18:05 +02:00
Austin Songer
9dc8d38565
Create sysmon_dns_over_https_enabled.yml 2021-08-31 09:14:14 -05:00
phantinuss
6eb7245673
fix: remove user sid, match any sid instead 2021-08-31 15:58:57 +02:00
frack113
eb434732a7 move rule not only powershell 2021-08-31 13:48:07 +02:00
frack113
18cdc36d73 Fix EventID 4103 detection 2021-08-31 13:44:54 +02:00
phantinuss
3a9e10d081
bulk of new rules to match working UACMe UAC bypasses 2021-08-31 12:51:21 +02:00
phantinuss
ea77d9161e
add another possible sdclt uac bypass registry path 2021-08-31 12:51:21 +02:00
phantinuss
50b8ca5110
add more COM interfaces and sharpen rule logic 2021-08-31 12:51:21 +02:00
phantinuss
3155f7172d
detection for proxyshell MSF module 2021-08-31 12:51:16 +02:00
phantinuss
abf40ecfbc
fix: typo in URL 2021-08-31 12:50:11 +02:00
frack113
b25fbbea54
Merge pull request #1957 from d4rk-d4nph3/master
Added new malwarebytes reference for Cab File Expansion rule
2021-08-31 09:54:47 +02:00
Bhabesh Rai
911c45201a Added -F option support 2021-08-31 13:02:53 +05:45
frack113
89e21c69ef fix detection 2021-08-31 09:07:54 +02:00
Bhabesh Rai
e2bfaea10f Added new malwarebytes reference for Cab File Expansion rule 2021-08-31 11:35:54 +05:45
frack113
acf59f9795 Fix some errors 2021-08-30 19:49:44 +02:00
Florian Roth
a5c6bbe04d
Merge pull request #1946 from SigmaHQ/rule-devel
rule: ProxyToken CVE-2021-33766 Exchange
2021-08-30 17:39:37 +02:00
Florian Roth
af9392ba0f
refactor: add 500 status code in selection2
to avoid FPs with exploitation attempts
2021-08-30 16:12:42 +02:00
Florian Roth
36a227796a
Merge pull request #1945 from SigmaHQ/rule-devel
rules: cobalt strike rules refactored
2021-08-30 15:48:01 +02:00
Florian Roth
4a4966af77
rule: ProxyToken CVE-2021-33766 Exchange 2021-08-30 15:47:53 +02:00
Florian Roth
98de92ceaf
refactor: global rule match on system and security 2021-08-30 15:17:53 +02:00
Florian Roth
1ded4eb913
rules: cobalt strike rules refactored 2021-08-30 15:10:30 +02:00
frack113
26bf8e1690
Merge pull request #1943 from frack113/update_test
Update test
2021-08-30 12:22:51 +02:00
frack113
6daaab7bc3
Merge pull request #1942 from frack113/update_help
Update help message
2021-08-30 12:22:19 +02:00
frack113
8ad2c722d6 add uberagent COVERAGE 2021-08-29 12:19:49 +02:00
frack113
2e79998cc7 add devo COVERAGE 2021-08-29 11:47:47 +02:00
frack113
83e2f3640c add lacework backend 2021-08-29 09:24:43 +02:00
frack113
772fe06e10 fix Backend does not support map values of type <class 'bool'> (57) 2021-08-29 09:10:30 +02:00
frack113
5ad29cf0c2 fix Base backend doesn't support multiple conditions (29) 2021-08-29 09:03:50 +02:00
frack113
718b44c38a fix List values must be strings or numbers (46) 2021-08-29 08:57:25 +02:00
frack113
4c414b2e8b fix Base backend doesn't support multiple conditions (33) 2021-08-29 08:52:54 +02:00
frack113
970dfa2f92
Merge pull request #1938 from EvanYu0816/upstream-fixes
Fix Pass the Hash and NotPetya Ransomware rule
2021-08-28 21:02:04 +02:00
frack113
a7456d4d6c
Merge pull request #1940 from frack113/fix_ps_fp
Powershell correction
2021-08-28 20:48:07 +02:00
frack113
3e355c64db
Merge pull request #1939 from SigmaHQ/rule-devel
rule: UAC bypass by mocking dirs
2021-08-28 20:47:27 +02:00
frack113
5f1143247b Update "sigmac -l" message 2021-08-28 08:51:58 +02:00
frack113
6aae623f45 Remove duplicate file 2021-08-28 08:42:02 +02:00
frack113
68237dffc4 fix HostApplication 2021-08-28 08:18:47 +02:00
frack113
ef6e0c5a4c Fix error and FP 2021-08-28 08:02:16 +02:00
Florian Roth
f78225c394
rule: UAC bypass by mocking dirs 2021-08-27 18:12:21 +02:00
Evan Yu
178d82e9cd Fix NotPetya Ransomware rule 2021-08-27 11:53:50 -04:00
Evan Yu
8bdd3e3987 Simplify Pass the Pash rule 2021-08-27 11:53:28 -04:00
frack113
ff37a49dc0
Merge pull request #1930 from SigmaHQ/rule-devel
fix: FPs with whoami rule and 4688 event IDs without parent info
2021-08-27 06:27:30 +02:00
frack113
0de795b0a2
Merge pull request #1936 from austinsonger/gworkspace_application_remove.yml
add gworkspace_application_remove.yml
2021-08-27 06:25:15 +02:00