Florian Roth
|
aab3dbee4f
|
Rule: Detect Empire PowerShell Default Cmdline Params
|
2019-04-20 09:38:41 +02:00 |
|
Florian Roth
|
03d8184990
|
Rule: Extended PowerShell Susp Cmdline Enc Commands
|
2019-04-20 09:38:41 +02:00 |
|
Florian Roth
|
d5fa51eab9
|
Merge pull request #305 from Karneades/patch-3
Remove too loose filter in notepad++ updater rule
|
2019-04-19 12:40:24 +02:00 |
|
Florian Roth
|
e32708154f
|
Merge pull request #304 from Karneades/patch-2
Remove too loose filter in mshta rule
|
2019-04-19 09:51:45 +02:00 |
|
Florian Roth
|
74dd008b10
|
FP note for HP software
|
2019-04-19 09:51:32 +02:00 |
|
Karneades
|
d75ea35295
|
Restrict whitelist filter in system exe anomaly rule
|
2019-04-18 22:06:12 +02:00 |
|
Florian Roth
|
f78413deab
|
Merge pull request #309 from jmlynch/master
added rules for renamed wscript, cscript and paexec. Added two direct…
|
2019-04-17 23:59:27 +02:00 |
|
Florian Roth
|
4808f49e0d
|
More exact path
|
2019-04-17 23:45:15 +02:00 |
|
Florian Roth
|
1a4a74b64b
|
fix: dot mustn't be escaped
|
2019-04-17 23:44:36 +02:00 |
|
Florian Roth
|
76780ccce2
|
Too many different trusted cscript imphashes
|
2019-04-17 23:33:56 +02:00 |
|
Florian Roth
|
7c5f985f6f
|
Modifications
|
2019-04-17 23:30:49 +02:00 |
|
Florian Roth
|
4298abffb7
|
Modifications
|
2019-04-17 23:29:29 +02:00 |
|
Florian Roth
|
615a802a8e
|
Modifications
|
2019-04-17 23:26:20 +02:00 |
|
Sam0x90
|
0e8a46aaf7
|
Update win_subp_svchost rule
Adding rpcnet.exe as ParentImage
|
2019-04-16 15:00:06 +02:00 |
|
Florian Roth
|
17470d1545
|
Rule: extended parent list for legitimate svchost starts
https://twitter.com/Sam0x90/status/1117768799816753153
|
2019-04-15 14:54:35 +02:00 |
|
Florian Roth
|
612a7642d2
|
Added Local directory
|
2019-04-15 08:47:53 +02:00 |
|
Florian Roth
|
1d3159bef0
|
Rule: Extended Office Shell rule
|
2019-04-15 08:13:35 +02:00 |
|
Karneades
|
d872c52a43
|
Add restricted filters to notepad++ gup.exe rule
|
2019-04-15 08:12:12 +02:00 |
|
Florian Roth
|
1e262f5055
|
Merge pull request #303 from Karneades/patch-1
Remove too loose filter in wmi spwns powershell rule
|
2019-04-14 23:11:57 +02:00 |
|
Karneades
|
75d36165fc
|
Remove non-generic falsepositives
There are tons of FPs for that... :)
|
2019-04-11 12:55:24 +02:00 |
|
Karneades
|
51e65be98b
|
Remove loose wildcard filter in powershell encoded cmd rule
|
2019-04-11 12:53:12 +02:00 |
|
Jason Lynch
|
89fb726875
|
added win_office_spawn_exe_from_users_directory.yml. Detects executable in users directory started via office program. Helpful for adversaries that tend to drop and execute renamed binaries in this location such as fin7
|
2019-04-09 09:45:07 -04:00 |
|
Jason Lynch
|
f0c8c428bb
|
added rules for renamed wscript, cscript and paexec. Added two directories to the existing sysmon_susp_prog_location_network_connection rule. These additions are all fin7 related.
|
2019-04-08 08:07:30 -04:00 |
|
Karneades
|
97376c00de
|
Fix condition
|
2019-04-04 22:33:32 +02:00 |
|
Karneades
|
766b8b8d18
|
Fix condition
|
2019-04-04 22:32:47 +02:00 |
|
Karneades
|
788e75ef1b
|
Fix condition
|
2019-04-04 22:32:21 +02:00 |
|
Karneades
|
840eb2f519
|
Remove too loose filter in notepad updater rule
|
2019-04-04 22:25:05 +02:00 |
|
Karneades
|
eb690d8902
|
Remove too loose filter in mshta rule
|
2019-04-04 22:16:24 +02:00 |
|
Karneades
|
1915561351
|
Remove to loose wildcard from wmi spwns powershell rule
|
2019-04-04 22:12:28 +02:00 |
|
yt0ng
|
e0459cec1c
|
renamed file
|
2019-04-03 17:39:17 +02:00 |
|
t0x1c-1
|
7e058e611c
|
WMI spawning PowerShell seen in various attacks
|
2019-04-03 16:56:45 +02:00 |
|
Unknown
|
9ada22b8e0
|
adjusted link
|
2019-04-03 16:40:18 +02:00 |
|
Unknown
|
d2e605fc5c
|
Auto stash before rebase of "Neo23x0/master"
|
2019-04-03 16:25:18 +02:00 |
|
Florian Roth
|
e473efb7c3
|
Trying to fix ATT&CK framework tag
|
2019-04-01 10:36:35 +02:00 |
|
Florian Roth
|
3f2ce4b71f
|
Lowered level to medium
|
2019-04-01 09:47:14 +02:00 |
|
t0x1c-1
|
51c42a15a7
|
Allow Incoming Connections by Port or Application on Windows Firewall
|
2019-04-01 08:16:56 +02:00 |
|
Florian Roth
|
ffac77fb37
|
Rule: extended LockerGoga description
|
2019-03-22 11:03:48 +01:00 |
|
Florian Roth
|
1adb040e0b
|
Rule: LockerGoga
|
2019-03-22 10:59:31 +01:00 |
|
Florian Roth
|
2ad2ba9589
|
fix: rule field fix in proc_creation rule
|
2019-03-22 10:59:18 +01:00 |
|
Thomas Patzke
|
be25aa2c37
|
Added CAR tags
|
2019-03-16 00:37:09 +01:00 |
|
Thomas Patzke
|
8512417de0
|
Incorporated MITRE CAR mapping from #55
|
2019-03-16 00:03:27 +01:00 |
|
Yugoslavskiy Daniil
|
5d54e9c8a1
|
nbstat.exe -> nbtstat.exe
|
2019-03-11 19:28:29 +01:00 |
|
Thomas Patzke
|
3c1948f089
|
Merge pull request #277 from megan201296/patch-18
Remove invalid link
|
2019-03-07 23:49:13 +01:00 |
|
Yugoslavskiy Daniil
|
475113b1c1
|
fixed incorrect date format
|
2019-03-07 22:52:11 +01:00 |
|
megan201296
|
c2a16591af
|
Remove invalid link
Cybereason link was broken. Couldn't find anything with a super similar file path. The below link might be a valid replacement but went better safe than sorry and just removed it completely. https://www.cybereason.com/hubfs/Cybereason%20Labs%20Analysis%20Operation%20Cobalt%20Kitty-Part1.pdf
|
2019-03-07 14:22:29 -06:00 |
|
Yugoslavskiy Daniil
|
cb7243de5d
|
fixed wrong tags
|
2019-03-06 06:18:38 +01:00 |
|
Yugoslavskiy Daniil
|
8bec627ff1
|
fixed multiple tags issue
|
2019-03-06 06:09:37 +01:00 |
|
Yugoslavskiy Daniil
|
5154460726
|
changed service to product
|
2019-03-06 05:57:01 +01:00 |
|
Yugoslavskiy Daniil
|
05cc7e455d
|
atc review
|
2019-03-06 05:25:12 +01:00 |
|
yugoslavskiy
|
725ab99e90
|
Merge pull request #1 from AverageS/master
Fix rules
|
2019-03-06 04:31:01 +01:00 |
|