Commit Graph

1084 Commits

Author SHA1 Message Date
yugoslavskiy
cc7aebe9b6
Update win_service_execution.yml 2019-11-05 04:42:53 +03:00
yugoslavskiy
ac95d840b4
Update powershell_winlogon_helper_dll.yml 2019-11-05 04:33:07 +03:00
yugoslavskiy
479aafe466
Update win_service_execution.yml 2019-11-05 04:26:19 +03:00
yugoslavskiy
37674b944f
Update win_query_registry.yml 2019-11-05 03:04:46 +03:00
yugoslavskiy
9d9de64387
Update win_query_registry.yml 2019-11-05 03:00:33 +03:00
yugoslavskiy
27e63abcc4
Update and rename win_custom_service_execution.yml to win_service_execution.yml 2019-11-05 02:57:15 +03:00
yugoslavskiy
3d5f5e2fe7
Update win_custom_service_execution.yml 2019-11-05 02:56:50 +03:00
yugoslavskiy
66bfbd0af9
Update and rename win_service_execution.yml to win_custom_service_execution.yml 2019-11-05 02:55:41 +03:00
yugoslavskiy
c147863eb3
Update powershell_data_compressed.yml 2019-11-05 02:38:36 +03:00
yugoslavskiy
b755d4fb68
Update and rename win_system_owner_user_discovery.yml to win_local_system_owner_account_discovery.yml 2019-11-05 02:31:20 +03:00
yugoslavskiy
9831897b6b
Update win_xsl_script_processing.yml 2019-11-05 01:32:29 +03:00
yugoslavskiy
ce55f80fb6
Update win_xsl_script_processing.yml 2019-11-05 01:31:55 +03:00
zinint
cd1cd48619
Delete win_app_windows_discovery.yml 2019-11-05 01:18:26 +03:00
zinint
a3ec56da07
Update win_xsl_script_processing.yml 2019-11-05 00:02:19 +03:00
zinint
fd6875485b
Add files via upload 2019-11-05 00:00:14 +03:00
zinint
cd43354c04
Delete sysmon_xsl_script_processing.yml 2019-11-04 23:47:23 +03:00
zinint
2679baddcd
Delete powershell_network_sniffing.yml 2019-11-04 23:46:43 +03:00
yugoslavskiy
e81f4f0ea6
Update sysmon_xsl_script_processing.yml 2019-11-04 23:42:47 +03:00
yugoslavskiy
b565398bc5
Update win_network_sniffing.yml 2019-11-04 23:02:03 +03:00
yugoslavskiy
e38116fce2
Update and rename win_data_compressed.yml to win_data_compressed_with_rar.yml 2019-11-04 22:55:32 +03:00
yugoslavskiy
cb167e73b1 fix filenames 2019-11-04 22:49:28 +03:00
yugoslavskiy
f880fa82b5
Rename process_creation_change_default_file_association.yml to win_change_default_file_association.yml 2019-11-04 22:48:13 +03:00
yugoslavskiy
cbf01aa51e
Update and rename win_change_default_file_association.yml to process_creation_change_default_file_association.yml 2019-11-04 22:46:55 +03:00
yugoslavskiy
ce849a1184 Merge branch 'master' into oscd 2019-11-04 20:48:19 +03:00
yugoslavskiy
1f1fd68331
Merge pull request #472 from feedb/oscd
add 11 new rules:

- rules/linux/auditd/lnx_auditd_web_rce.yml
- rules/windows/process_creation/process_creation_susp_bginfo.yml
- rules/windows/process_creation/process_creation_susp_cdb.yml
- rules/windows/process_creation/process_creation_susp_devtoolslauncher.yml
- rules/windows/process_creation/process_creation_susp_dnx.yml
- rules/windows/process_creation/process_creation_susp_dxcap.yml
- rules/windows/process_creation/process_creation_susp_msoffice.yml
- rules/windows/process_creation/process_creation_susp_odbcconf.yml
- rules/windows/process_creation/process_creation_susp_openwith.yml
- rules/windows/process_creation/process_creation_susp_psr_capture_screenshots.yml
- rules/windows/sysmon/sysmon_webshell_creation_detect.yml
2019-11-04 20:40:58 +03:00
yugoslavskiy
3f1c94837b
Rename process_creation_susp_openwith_execution.yml to process_creation_susp_openwith.yml 2019-11-04 20:38:44 +03:00
yugoslavskiy
54e9be9cd0
Rename process_creation_susp_devtoolslauncher_execution.yml to process_creation_susp_devtoolslauncher.yml 2019-11-04 20:38:24 +03:00
yugoslavskiy
999126446b
Rename win_susp_psr_capture_screenshots.yml to process_creation_susp_psr_capture_screenshots.yml 2019-11-04 20:37:16 +03:00
yugoslavskiy
85cd989b6f
Rename win_susp_openwith_execution.yml to process_creation_susp_openwith_execution.yml 2019-11-04 20:36:58 +03:00
yugoslavskiy
8d0923de2d
Rename win_susp_odbcconf.yml to process_creation_susp_odbcconf.yml 2019-11-04 20:36:46 +03:00
yugoslavskiy
de098ff5b7
Rename win_susp_msoffice.yml to process_creation_susp_msoffice.yml 2019-11-04 20:36:21 +03:00
yugoslavskiy
9c19d1b58c
Rename win_susp_dxcap.yml to process_creation_susp_dxcap.yml 2019-11-04 20:36:07 +03:00
yugoslavskiy
66eba43a8d
Rename win_susp_dnx.yml to process_creation_susp_dnx.yml 2019-11-04 20:35:53 +03:00
yugoslavskiy
d18314b6b2
Rename win_susp_devtoolslauncher_execution.yml to process_creation_susp_devtoolslauncher_execution.yml 2019-11-04 20:35:43 +03:00
yugoslavskiy
49bc6ada25
Rename win_susp_cdb.yml to process_creation_susp_cdb.yml 2019-11-04 20:35:28 +03:00
yugoslavskiy
95412e5f30
Rename win_susp_bginfo.yml to process_creation_susp_bginfo.yml 2019-11-04 20:35:11 +03:00
yugoslavskiy
19396fd274
Update sysmon_webshell_creation_detect.yml 2019-11-04 19:23:52 +03:00
yugoslavskiy
9371e533c3
Update win_susp_openwith_execution.yml 2019-11-04 19:05:23 +03:00
yugoslavskiy
e6a39f1061
Update win_susp_odbcconf.yml 2019-11-04 19:01:30 +03:00
yugoslavskiy
c18fa0940d
Update win_susp_msoffice.yml 2019-11-04 18:44:07 +03:00
yugoslavskiy
bd0ebf0604
Update win_susp_dxcap.yml 2019-11-04 18:43:42 +03:00
yugoslavskiy
df07291e53
Update win_susp_cdb.yml 2019-11-04 18:43:03 +03:00
yugoslavskiy
a66539c771
Update win_susp_msoffice.yml 2019-11-04 18:42:26 +03:00
yugoslavskiy
56b7402e62
Update win_susp_dxcap.yml 2019-11-04 18:38:37 +03:00
yugoslavskiy
a9fdfee5c2
Update win_susp_dnx.yml 2019-11-04 18:34:25 +03:00
yugoslavskiy
dc23e566a0
Update win_susp_devtoolslauncher_execution.yml 2019-11-04 18:30:04 +03:00
yugoslavskiy
989d75033a
Update win_susp_cdb.yml 2019-11-04 18:25:30 +03:00
yugoslavskiy
43c20d203d
Update and rename win_susp_capture_screenshots.yml to win_susp_psr_capture_screenshots.yml 2019-11-04 18:16:39 +03:00
yugoslavskiy
a800093aaf
Update win_susp_bginfo.yml 2019-11-04 18:14:44 +03:00
Florian Roth
5786688f97 rule: Firewall disabled via Netsh 2019-11-04 16:10:10 +01:00
Thomas Patzke
a5579fa8cd
Merge pull request #513 from Karneades/fix-sysmon-rule
fix: bound sysmon logon script rule to field
2019-11-02 23:04:35 +01:00
Karneades
0117dac1db fix: bound sysmon logon script rule to field
Fixed rule:
- rules/windows/sysmon/sysmon_logon_scripts_userinitmprlogonscript.yml
2019-11-02 11:47:20 +01:00
Karneades
68fd20cb66 fix: bound windows event log rules to message field
Fixed rules
- rules/windows/builtin/win_susp_msmpeng_crash.yml
- rules/windows/builtin/win_alert_active_directory_user_control.yml
- rules/windows/builtin/win_av_relevant_match.yml
- rules/windows/builtin/win_mal_creddumper.yml
- rules/windows/builtin/win_susp_sam_dump.yml
- rules/windows/builtin/win_alert_mimikatz_keywords.yml
- rules/windows/builtin/win_alert_enable_weak_encryption.yml
2019-11-02 11:25:29 +01:00
Florian Roth
3107c0c268 rule: Formbook rule improved 2019-10-31 09:32:18 +01:00
zinint
60bf34e220
T1042 2019-10-30 23:30:56 +03:00
zinint
12ef86fcbe
t1040 2019-10-30 23:18:37 +03:00
zinint
b3b203e5b1
t1040 2019-10-30 23:15:19 +03:00
Florian Roth
4741b6a4d6 rule: Mustang Panda dropper 2019-10-30 18:22:40 +01:00
Florian Roth
d661771608 rule: another DTRACK reference 2019-10-30 18:22:25 +01:00
Florian Roth
3ac28f3eed rule: DTRACK process creation 2019-10-30 15:16:33 +01:00
Thomas Patzke
219f00e3fb Added command line parameter
Implements #418
2019-10-29 23:04:28 +01:00
Thomas Patzke
f4e9690d6b
Merge pull request #508 from Karneades/fixRule3
fix: bound keywords to field in multiple PS rules
2019-10-29 22:34:08 +01:00
Thomas Patzke
78d8ca2b41
Merge pull request #507 from Karneades/fixRule2
fix: bound keywords to field in PS cred prompt rule
2019-10-29 22:31:01 +01:00
Thomas Patzke
40df0d4534
Merge pull request #506 from Karneades/fixRule1
fix: bound keywords to field in WMI persistence rule
2019-10-29 22:30:27 +01:00
Thomas Patzke
6eb49fc1ce
Merge pull request #509 from Karneades/fixRule4
fix: change keyword and bound it to a field in PS rule
2019-10-29 22:27:54 +01:00
Thomas Patzke
b6403793c1 Fixed escaping in rule 2019-10-29 22:06:23 +01:00
Karneades
ab5556ae8c fix: change keyword and bound it to a field 2019-10-29 19:59:43 +01:00
Karneades
aafab2e936 fix: bound keywords to field in multiple PS rules
Rules changed:
- rules/windows/powershell/powershell_malicious_commandlets.yml
- rules/windows/powershell/powershell_malicious_keywords.yml
- rules/windows/powershell/powershell_suspicious_download.yml
- rules/windows/powershell/powershell_suspicious_invocation_specific.yml
2019-10-29 19:53:18 +01:00
Karneades
f31750e567 fix: bound keywords to field in PS cred prompt rule 2019-10-29 19:43:04 +01:00
Karneades
cd20e4a3fc fix: bound keywords to field in WMI persistence rule
See #501.
2019-10-29 19:22:41 +01:00
zinint
c243c4e210
T1035 2019-10-29 20:58:52 +03:00
Florian Roth
8ff85499c8 rule: svchost dll search order hijack 2019-10-28 12:03:03 +01:00
Florian Roth
1a3444d0ef docs: comment on rule expression 2019-10-28 12:02:46 +01:00
zinint
87c8326133
T1033 2019-10-27 23:49:07 +03:00
zinint
55eaae1cea
Rename win_app_windows_descovery.yml to win_app_windows_discovery.yml 2019-10-27 23:15:10 +03:00
zinint
93b867024c
T1012 2019-10-27 23:13:03 +03:00
root
717e40e8ed modified win_susp_dxcap.yml 2019-10-26 20:27:32 +02:00
root
9bf0150100 modified win_susp_dnx.yml 2019-10-26 20:20:21 +02:00
root
3b70f2edd6 modified win_susp_dnx.yml 2019-10-26 20:16:40 +02:00
root
3528afeef7 modified win_susp_dnx.yml 2019-10-26 20:13:53 +02:00
root
1dca0456ee modified win_susp_dxcap.yml 2019-10-26 20:09:25 +02:00
root
cbe0d73ce8 add win_susp_dxcap.yml 2019-10-26 20:06:02 +02:00
root
aaf63d2238 add win_susp_dxcap.yml 2019-10-26 20:02:25 +02:00
root
0616c2c39d add win_susp_dnx.yml 2019-10-26 19:58:45 +02:00
root
ee21888e67 add win_susp_cdb.yml 2019-10-26 19:49:45 +02:00
Florian Roth
42808b7eb8 rule: webshell detection improved 2019-10-26 09:14:54 +02:00
root
844d55c781 add win_susp_bginfo.yml 2019-10-26 08:18:37 +02:00
root
5bb5938e86 add win_susp_bginfo.yml 2019-10-26 08:16:08 +02:00
root
01c4c7cdbd modifed win_susp_msoffice.yml 2019-10-26 08:11:09 +02:00
root
bea2daac45 modifed win_susp_msoffice.yml 2019-10-26 07:55:44 +02:00
root
fc7f8ecea3 add win_susp_msoffice.yml 2019-10-26 07:48:38 +02:00
root
611c193826 modifed win_susp_odbcconf.yml 2019-10-26 07:45:53 +02:00
root
aa9a22e662 add win_susp_odbcconf.yml 2019-10-25 19:02:17 +02:00
alexpetrov12
8c2b7e9f85 fix 2019-10-25 18:30:40 +03:00
alexpetrov12
7aa804fe90 added new rules
Packet capture Windows command prompt, ODBCCONF execution dll, Windows Registry Persistence - COM key linking
2019-10-25 18:01:36 +03:00
zinint
6e94e798be
t1010 2019-10-25 16:12:51 +03:00
zinint
aef5fa3c2b
Rename powershell_winlogon_helper_dll.yaml to powershell_winlogon_helper_dll.yml 2019-10-24 16:37:38 +03:00
Florian Roth
a5ec6722a1 rule: the actual changes to hwp rule 2019-10-24 15:35:13 +02:00
zinint
5a98fdbbbd
ART t1004 2019-10-24 16:33:29 +03:00
zinint
317e9d3df9
PS Data Compressed attack.t1002
PS Data Compressed attack.t1002
2019-10-24 15:43:46 +03:00