Commit Graph

4063 Commits

Author SHA1 Message Date
Florian Roth
715bca0fd2
Merge pull request #1704 from frack113/redcanary_t1216
Redcanary t1216
2021-07-17 09:48:43 +02:00
Florian Roth
56ae1938af
Merge pull request #1706 from BlackB0lt/patch-12
Create sysmon_cve_2021_31979_cve_2021_33771_exploits.yml
2021-07-17 09:46:35 +02:00
Florian Roth
b1a00152bc
Merge pull request #1698 from SigmaHQ/rule-devel
several new rules and fixes
2021-07-17 09:39:47 +02:00
Florian Roth
b911175f28 Suspicious mshta patterns 2021-07-17 09:04:41 +02:00
Florian Roth
6c79115ce0 Regsvr32 Anomalies extended 2021-07-17 09:04:31 +02:00
Sittikorn S
d3a1fb8565
Update sysmon_cve_2021_31979_cve_2021_33771_exploits.yml 2021-07-17 06:49:37 +07:00
Sittikorn S
5e84a603d0
Update sysmon_cve_2021_31979_cve_2021_33771_exploits.yml 2021-07-17 01:04:07 +07:00
Sittikorn S
a3c4aa5dad
Update sysmon_cve_2021_31979_cve_2021_33771_exploits.yml 2021-07-17 01:02:14 +07:00
Sittikorn S
eea3675d4e
Rename sysmon_cve_2021_31979_cve-2021_33771_exploits.yml to sysmon_cve_2021_31979_cve_2021_33771_exploits.yml 2021-07-17 00:09:04 +07:00
Sittikorn S
90fc50e0a2
Update and rename sysmon_devilstongue_CVE_2021_31979_exploit.yml to sysmon_cve_2021_31979_cve-2021_33771_exploits.yml
rename sysmon_cve_2021_31979_cve-2021_33771_exploits.yml
2021-07-17 00:02:15 +07:00
Sittikorn S
9fb589201e
Update and rename sysmon_devilstongue_exploit_0day.yml to sysmon_devilstongue_CVE_2021_31979_exploit.yml
Change Title
2021-07-16 23:47:14 +07:00
Sittikorn S
f2187f05e6
Update and rename sysmon_devilstongue_CVE_2021_31979_CVE_2021_33771.yml to sysmon_devilstongue_exploit_0day.yml 2021-07-16 23:42:05 +07:00
Sittikorn S
91295cff21
Update sysmon_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 23:35:31 +07:00
Sittikorn S
dac72e2750
Update and rename sysmon_exploit_CVE_2021_31979_CVE_2021_33771.yml to sysmon_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 23:30:05 +07:00
Sittikorn S
10b7b6d640
Update sysmon_exploit_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 23:11:14 +07:00
Sittikorn S
94ba194b42
Update sysmon_exploit_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 23:09:51 +07:00
Sittikorn S
477ec060d2
Update and rename sysmon_susp_devilstongue_CVE_2021_31979_CVE_2021_33771.yml to sysmon_exploit_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 22:47:04 +07:00
Sittikorn S
99e5990416
Update sysmon_susp_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 22:30:06 +07:00
Sittikorn S
dc94c4e51e
Update sysmon_susp_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 22:21:34 +07:00
Sittikorn S
0954163e9d
Update sysmon_susp_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 22:19:07 +07:00
Sittikorn S
e094c76098
Update sysmon_susp_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 22:14:22 +07:00
Sittikorn S
0506e10697
Create sysmon_susp_devilstongue_CVE_2021_31979_CVE_2021_33771.yml 2021-07-16 22:09:07 +07:00
Tran Trung Hieu
8effde4e1d More suspicious flag fot bitsadmin execution 2021-07-16 16:40:00 +07:00
Tran Trung Hieu
1cb631017a Suspicious behaviours related to SOURGUM 2021-07-16 14:13:48 +07:00
Bhabesh Rai
be8fce8e82 Added rule for ADRecon execution 2021-07-16 12:58:47 +05:45
frack113
9a7f3036e4 update ref in win_manage-bde_lolbas.yml 2021-07-16 08:34:30 +02:00
frack113
d6dc217c6d Add process_creation_syncappvpublishingserver_vbs_execute_powershell.yml 2021-07-16 08:28:25 +02:00
Florian Roth
021f211c14 fix: FP with WCE and Windows Cluster Service 2021-07-15 12:09:28 +02:00
frack113
c6cb7f1247 fix missing references and duplicate UUID 2021-07-15 11:06:54 +02:00
Florian Roth
e40b859254
Merge pull request #1695 from frack113/fix_re
escape / in regex
2021-07-15 09:25:58 +02:00
Florian Roth
abb8df887a
Merge pull request #1690 from WuerthIT/patch_rule
update rule: powershell_accessing_win_api.yml
2021-07-15 08:36:38 +02:00
Florian Roth
f3d24e27c2
Merge pull request #1694 from leegengyu/patch-13
Update win_remote_powershell_session_process.yml
2021-07-15 08:36:12 +02:00
Florian Roth
2055da991f
Merge pull request #1691 from SigmaHQ/rule-devel
Rules: scripts from Temp folders, reg disable sec services
2021-07-15 08:35:54 +02:00
frack113
0ef3dc2082 escape / in regex 2021-07-15 08:13:49 +02:00
G Y
8bbea58786
Update win_remote_powershell_session_process.yml
Updated TTP and formatting.
2021-07-15 11:20:25 +08:00
Florian Roth
e516aecc74 fix: error in selector 2021-07-14 15:58:55 +02:00
Florian Roth
530e04faec rule: Script Execution from Temp Folder 2021-07-14 15:52:52 +02:00
Florian Roth
0d794357e8 rule: reg disable security services 2021-07-14 15:52:35 +02:00
k-vdv
12b172039f fixed some typos and adjusted capitalization to original 2021-07-14 15:47:17 +02:00
Florian Roth
3ff4e99d44
Merge pull request #1688 from SigmaHQ/rule-devel
refactor: improved Raccine uninstall rule
2021-07-14 09:57:08 +02:00
Florian Roth
04370c7e91 refactor: improved Raccine uninstall rule 2021-07-14 09:56:35 +02:00
Florian Roth
1ec9473472
Merge pull request #1687 from SigmaHQ/rule-devel
Rule adjustments and new Serv-U exploitation rules
2021-07-14 08:59:33 +02:00
Florian Roth
5e2e6c9b72 Merge branch 'config-adjustments' into rule-devel 2021-07-14 08:35:47 +02:00
Florian Roth
e0f166aba2 rule: Serv-U exploitation
https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/
2021-07-14 08:35:25 +02:00
Florian Roth
85d47aeabc
Merge pull request #1678 from frack113/redcanary_t1228
Some Redcanary T1228
2021-07-14 08:18:52 +02:00
Florian Roth
9fce0fb42d
Merge pull request #1680 from phantinuss/master
medium level Rule for Windows Defender Exclusions
2021-07-14 08:18:39 +02:00
frack113
8b14dc6c99 fix [colons] too many spaces after colon 2021-07-13 14:42:47 +02:00
frack113
c00dd0bf65 add win_susp_athremotefxvgpudisablementcommand.yml 2021-07-13 14:29:00 +02:00
frack113
6d1e8268ba update win_workflow_compiler.yml 2021-07-13 13:55:27 +02:00
phantinuss
bf9b82fc45
medium level rule for Windows Defender Exclusions 2021-07-13 13:16:25 +02:00
frack113
6b9466ec20 Add process_creation_protocolhandler_suspicious_file.yml 2021-07-13 12:19:07 +02:00
frack113
33832acf5b fix Error: [colons] too many spaces before colon 2021-07-13 10:09:52 +02:00
frack113
c2d9b05191 Add process_creation_infdefaultinstall.yml 2021-07-13 09:56:34 +02:00
frack113
fd377fe163 update process_creation_syncappvpublishingserver_execute_arbitrary_powershell 2021-07-13 09:45:46 +02:00
frack113
82f666c5da add process_creation_syncappvpublishingserver_execute_arbitrary_powershell.yml 2021-07-12 16:17:40 +02:00
frack113
d6a86a3fa0 add T1218 sysmon_creation_mavinject_dll.yml 2021-07-12 16:08:18 +02:00
Florian Roth
382d5b2adb
Merge pull request #1674 from frack113/fix_small_errors
Fix some typo error
2021-07-12 15:23:55 +02:00
Florian Roth
682e0458a3
Merge pull request #1675 from frack113/redcanary_attack.t1562.001
Atomic Red team T1562.001
2021-07-12 15:23:35 +02:00
Florian Roth
677c53a262
Merge pull request #1676 from d4rk-d4nph3/master
Added latest McAfee zloader's reference for Office Security Settings …
2021-07-12 14:02:49 +02:00
Bhabesh Rai
1fc5ec981d Added latest McAfee zloader's reference for Office Security Settings Changed 2021-07-12 16:56:21 +05:45
frack113
a96678d725 test 21 to 24 from https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md 2021-07-12 10:54:44 +02:00
Florian Roth
7f071d7851
Merge pull request #1554 from mlp1515/master
Update win_multiple_suspicious_cli.yml
2021-07-12 10:43:26 +02:00
Thomas Patzke
0b83c12dd1 Merge branch 'devel-tp' 2021-07-12 10:21:19 +02:00
frack113
af140ebf84 fix some typo error 2021-07-12 09:40:18 +02:00
Thomas Patzke
176514bd7a New rule: suspicious spoolsv child process 2021-07-12 08:48:59 +02:00
Thomas Patzke
0b590aba5d Adjusted Spool Service DLL load rule 2021-07-11 09:29:43 +02:00
Florian Roth
58a634b0b6
Merge branch 'master' into master 2021-07-11 00:32:55 +02:00
frack113
17edaa0950 combines 2 rules 2021-07-09 16:41:03 +02:00
Florian Roth
aa0231e1f8
Merge pull request #1664 from frack113/parentofparent
Move to rules-unsupported as use special enrichment field
2021-07-09 10:55:22 +02:00
frack113
a53e21eb77 2 more rule with custom field 2021-07-09 10:07:41 +02:00
frack113
14322393f7 fix more invalid windows field name 2021-07-09 10:02:05 +02:00
frack113
06a05cfad9 Move to rules-unsupported as use special enrichment field 2021-07-09 07:40:57 +02:00
Florian Roth
db8cc0ee2d
Merge pull request #1656 from SigmaHQ/rule-devel
rule: suspicious vss ps load / PrinternightMare updates
2021-07-08 15:03:28 +02:00
Florian Roth
c91eda7660
Merge pull request #1610 from cianmcgovern/powershell-network-connection
Move ipv6 check to selection fields as filter is negated
2021-07-08 14:53:36 +02:00
Florian Roth
0518439de7
Merge pull request #1648 from frack113/fix_windows_fields
Fix more windows fields name
2021-07-08 14:53:14 +02:00
Florian Roth
f78b353352 PrinterNightmare rule updates 2021-07-08 14:35:51 +02:00
Florian Roth
2055f78780 refactor: make the rule more usable 2021-07-08 09:05:57 +02:00
Florian Roth
79338b2dbd
fix: title 2021-07-08 08:33:46 +02:00
Thomas Patzke
103a8f8052 Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
Florian Roth
96ea35fd92 rule: suspicious vss ps load 2021-07-07 18:21:57 +02:00
Florian Roth
25dec8a17b
Merge pull request #1649 from leegengyu/patch-9
Update win_apt_apt29_thinktanks.yml - Links
2021-07-07 18:10:27 +02:00
Florian Roth
c3c152d457
Merge pull request #1652 from SigmaHQ/rule-devel
refactor: changed cmdkey rule
2021-07-07 18:09:44 +02:00
frack113
8a96aa7855 Add 2 defense-evasion T1562.001 rules 2021-07-07 15:43:55 +02:00
Florian Roth
0c7661e8bc refactor: changed cmdkey rule 2021-07-07 14:45:03 +02:00
G Y
1adac5b036
Update win_apt_apt29_thinktanks.yml - Links
Reference links updated with grammar corrections.
2021-07-07 20:21:41 +08:00
frack113
4e3b275056 Fix more windows fields name 2021-07-07 12:28:00 +02:00
Florian Roth
792f234872
Merge pull request #1636 from leegengyu/patch-6
powershell_data_compressed.yml - Update selection
2021-07-07 10:12:52 +02:00
Florian Roth
2e15742a37
Merge pull request #1637 from frack113/fix_win_rdp_reverse_tunnel.yml
win_rdp_reverse_tunnel.yml  fix invalid field name
2021-07-07 10:12:16 +02:00
Florian Roth
6e00745288
Merge pull request #1638 from frack113/fix_win_external_device.yml
win_external_device.yml  fix invalid field name
2021-07-07 10:12:04 +02:00
Florian Roth
bd0628240c
Merge pull request #1639 from frack113/fix_win_possible_dc_shadow.yml
fix invalid field EventID 5136
2021-07-07 10:11:51 +02:00
Florian Roth
ad36a03622
Merge pull request #1640 from frack113/fix_win_susp_local_anon_logon_created.yml
win_susp_local_anon_logon_created.yml fix invalid case SamAccountName
2021-07-07 10:11:36 +02:00
Florian Roth
dc2377be13
Merge pull request #1644 from leegengyu/patch-7
Update win_admin_rdp_login.yml - Fix Field Name & Value
2021-07-07 10:04:02 +02:00
Florian Roth
0573097696
Merge pull request #1645 from leegengyu/patch-8
Update win_mal_service_installs.yml - Corrected logsource
2021-07-07 10:03:48 +02:00
frack113
bb970de5b7 fix invalid fields name 2021-07-07 09:05:00 +02:00
mlp1515
aec9fac276
Update win_user_added_to_local_administrators.yml 2021-07-07 06:30:33 +00:00
mlp1515
29a6a2d5fb
Merge branch 'SigmaHQ:master' into master 2021-07-07 08:25:04 +02:00
G Y
6b63a309da
Update win_mal_service_installs.yml - Corrected logsource
Fix mistake (incorrect logsource for event ID 4697) in #1629.
2021-07-07 10:33:26 +08:00
G Y
eece2850a7
Update win_admin_rdp_login.yml - Fix Field Name
1. Field name changed to `TargetUserName`.
Source: https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624

2. Value changed from `Admin-` to `Admin`.
2021-07-07 09:43:55 +08:00
frack113
9cf1d3d5f3 fix invalid case SamAccountName 2021-07-06 15:43:07 +02:00
frack113
bbf908835e fix invalid field EventID 5136 2021-07-06 15:25:32 +02:00
leegengyu
3594b10d74 Insert modified date 2021-07-06 20:56:31 +08:00
G Y
c5d2a55f6d
powershell_data_compressed.yml - Update selection
Changed to ScriptBlockText (due to PowerShell logging-specific context).
2021-07-06 20:36:38 +08:00
Florian Roth
bcf2bf2e4d
Merge pull request #1635 from frack113/fix_win_susp_failed_logons_single_source_kerberos
Fix invalid field name
2021-07-06 14:35:06 +02:00
frack113
b0c9bc1d2d fix invalid field name EventID 6416 2021-07-06 14:27:29 +02:00
frack113
fca3c72087 fix invalid field name 2021-07-06 14:16:01 +02:00
Florian Roth
ff0f1a0222
Merge pull request #1633 from leegengyu/art_convert_yaml_to_md
Convert ART reference links from .yaml to .md
2021-07-06 13:39:37 +02:00
frack113
12fb71b83b fix invalid field name 2021-07-06 12:53:38 +02:00
leegengyu
1f19f79da9 Convert ART reference links from .yaml to .md 2021-07-06 17:56:38 +08:00
Florian Roth
705415c2bd
Merge pull request #1632 from frack113/process_creation_OriginalFileName
change OriginalFilename case
2021-07-06 11:45:21 +02:00
leegengyu
69d5d9734d Updated ART reference links from .yaml 2021-07-06 17:39:25 +08:00
leegengyu
5eb9547d5b Updated ART reference links from .yaml to .md and sub-technique links. 2021-07-06 17:30:57 +08:00
leegengyu
7557732ca2 Updated ART reference links from .yaml to .md and sub-technique links. 2021-07-06 17:21:22 +08:00
Florian Roth
8beb70e970
Merge pull request #1631 from leegengyu/patch-5
Update mordordatasets links
2021-07-06 10:45:15 +02:00
Florian Roth
223ae079ea
Merge pull request #1627 from SigmaHQ/rule-devel
rule: PrinterNightmare Mimikatz update
2021-07-06 10:44:48 +02:00
Florian Roth
e31f0c8f7f
Merge pull request #1628 from d4rk-d4nph3/master
Added and updated Defender's tamper related rules
2021-07-06 10:44:33 +02:00
Florian Roth
17f7bbc063
Merge pull request #1630 from frack113/fix_childimage
childimage do not exist in sysmon schema
2021-07-06 10:44:00 +02:00
leegengyu
5d10cc68da Update mordordatasets references 2021-07-06 16:35:20 +08:00
G Y
7f15b0a075
Update win_smb_file_creation_admin_shares.yml - Dead link
Updated dead link.
2021-07-06 16:24:02 +08:00
frack113
cfccdea28e change OriginalFilename case 2021-07-06 10:09:47 +02:00
G Y
aab65361da
Update rules/windows/builtin/win_mal_service_installs.yml
Add modified date.

Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
2021-07-06 00:50:23 -07:00
frack113
9c94cf42fe childimage do not exist in sysmon schema 2021-07-06 09:26:43 +02:00
G Y
a0407cf477
Update win_mal_service_installs.yml - Add new Event ID
Added event ID 4697, which is equivalent to existing event ID 7045.
2021-07-06 12:11:32 +08:00
G Y
c01ec60e7d
Update win_mal_service_installs.yml - Add new service
Add new malicious service (javamtsup) by APT29 and add reference links.
2021-07-06 11:03:08 +08:00
Bhabesh Rai
3bc6532049 Added and updated Defender's tamper related rules 2021-07-05 20:30:07 +05:45
Florian Roth
e5849a08f1 rule: PrinterNightmare Mimikatz update
51dc7c0363 (diff-cf4373b6c7195386ac1973681e5561bd96e1bb9e099cfd3febd1111e986bd17cL1450-R1451)
2021-07-05 15:29:52 +02:00
Florian Roth
4b487f49fc
Merge pull request #1624 from frack113/fix_pr_869
Fix PR 869
2021-07-05 15:26:50 +02:00
Florian Roth
0da297dbef
Merge pull request #1626 from frack113/description_is_null
fix missing description
2021-07-05 15:26:31 +02:00
Florian Roth
8069b53e5e
Merge pull request #1625 from SigmaHQ/rule-devel
Kaseya patterns, PrinterNightmare Mimikatz update
2021-07-05 13:29:23 +02:00
frack113
0245d58065 fix missing description 2021-07-05 12:56:05 +02:00
Florian Roth
6c4f36c473 fix: minor typo - no \ at the end of the expression 2021-07-05 12:05:57 +02:00
Florian Roth
7e9d6600eb rule: PrinterNightmare - new mimikatz printer name 2021-07-05 12:03:56 +02:00
Florian Roth
7fab22ddc2 rule: more Kaseya patterns 2021-07-05 12:03:35 +02:00
frack113
d05f3efd1b fix pr 869 2021-07-04 19:44:50 +02:00
Florian Roth
d101c9893a
Merge pull request #1623 from SigmaHQ/rule-devel
rule: mimikatz printernightmare
2021-07-04 14:28:44 +02:00
Florian Roth
1e152bf594
Merge pull request #1615 from leegengyu/patch-1
Update powershell_data_compressed.yml - Outdated link
2021-07-04 14:19:55 +02:00
Florian Roth
062198550d
Merge pull request #1620 from leegengyu/patch-2
Update win_susp_sdelete.yml - Outdated Link and Typo
2021-07-04 14:19:31 +02:00
Florian Roth
fd5b7506d1 refactor: changed rule contents, removed eventIDs 2021-07-04 14:03:28 +02:00
Florian Roth
62b25cadf1 rule: mimikatz printernightmare 2021-07-04 13:47:56 +02:00
G Y
a60a2feb17
Update sysmon_susp_pfx_file_creation.yml
Fixed typo.
2021-07-04 10:38:53 +08:00
G Y
268c97f23a
Update win_susp_sdelete.yml
Update old links and typo.
2021-07-04 09:53:23 +08:00
G Y
c63439e74d
Update powershell_data_compressed.yml
Changed reference link from `.yaml` to `.md`.
2021-07-04 08:15:29 +08:00
Florian Roth
a02b7a2390
Merge pull request #1617 from SigmaHQ/rule-devel
rule: REvil Kaseya patterns
2021-07-03 17:32:18 +02:00
Florian Roth
d188932748
Merge pull request #1616 from frack113/update_win_renamed_powershell.yml
Tune detection in win_renamed_powershell.yml
2021-07-03 17:04:52 +02:00
Florian Roth
48621d68ff
Merge pull request #1613 from leegengyu/powershell_powerview_malicious_commandlets_additions
Update powershell_powerview_malicious_commandlets.yml - Addition and Miscellaneous
2021-07-03 17:04:29 +02:00
Florian Roth
1d82ac50e4 refactor: additional pattern, extended description 2021-07-03 17:03:40 +02:00
Florian Roth
57b816f49d rule: REvil Kaseya patterns 2021-07-03 16:34:02 +02:00
frack113
02100f1a3c Tune detection in win_renamed_powershell.yml 2021-07-03 15:18:01 +02:00
G Y
d247766a2e
Update powershell_data_compressed.yml
Corrected old link and formatting.
2021-07-03 20:48:03 +08:00
Florian Roth
e7144b34ee
fix: bug in syntax 2021-07-03 13:19:56 +02:00
Florian Roth
2d0cdc16fc
added modified date 2021-07-03 13:19:14 +02:00