Commit Graph

5317 Commits

Author SHA1 Message Date
yugoslavskiy
c71e0ae0ea
Merge pull request #1209 from vburov/patch-15
[OSCD] Create win_susp_multiple_files_renamed_or_deleted.yml
2021-01-06 00:19:41 +03:00
yugoslavskiy
38661bbc10
Merge pull request #1208 from NikitaStormwind/RTT(17)
[OSCD] Atomic Red Team: Detected Windows Software Discovery (T1518)
2021-01-06 00:19:20 +03:00
yugoslavskiy
2cf1994763
Merge pull request #1206 from w0rk3r/oscd5
[OSCD] Windows - Suspicious Service DACL Modification
2021-01-06 00:18:53 +03:00
yugoslavskiy
aad2838f58
Merge pull request #1198 from tas-kmanager/mt-oscd-sigma547-50-rule2
[OSCD] Always Install Elevated - Slide 50 - Rule 2
2021-01-06 00:18:44 +03:00
yugoslavskiy
e0286abb62
Merge pull request #1197 from w0rk3r/oscd_rules_improvement2
[OSCD] Small improvements on others rules
2021-01-06 00:18:36 +03:00
yugoslavskiy
0b7babaa84
Merge pull request #1196 from tas-kmanager/mt-oscd-sigma547-50-rule1
[OSCD] Always Install Elevated - Slide 50 - Rule 1
2021-01-06 00:18:26 +03:00
yugoslavskiy
fc1fa23440
Merge pull request #1191 from vburov/patch-14
[OSCD] Create powershell_cmdline_special_characters.yml
2021-01-06 00:18:12 +03:00
yugoslavskiy
8e50eeb4a9
Merge pull request #1187 from nsaddler/lolbas108
[OSCD] LOLBAS Manage-bde.yml
2021-01-06 00:18:02 +03:00
yugoslavskiy
cfbd10ab8b
Merge pull request #1186 from nsaddler/lolbas107_2
[OSCD] LOLBAS CL_Mutexverifiers - powershell
2021-01-06 00:17:54 +03:00
yugoslavskiy
e91d48cc93
Merge pull request #1185 from nsaddler/lolbas107_1
[OSCD] LOLBAS CL_Mutexverifiers - process_creation
2021-01-06 00:17:46 +03:00
yugoslavskiy
9d1c695204
Merge pull request #1184 from nsaddler/lolbas106_1
[OSCD] LOLBAS CL_Invocation - powershell
2021-01-06 00:17:10 +03:00
yugoslavskiy
def4a7dbb9
Merge pull request #1183 from nsaddler/lolbas106
[OSCD] LOLBAS CL_Invocation - process_creation
2021-01-06 00:17:01 +03:00
yugoslavskiy
6f2e8c56b2
Merge pull request #1182 from nsaddler/lolbas80
[OSCD] LOLBAS wab.yml
2021-01-06 00:16:53 +03:00
yugoslavskiy
e1fd69f548
Merge pull request #1179 from SanWieb/OSCD_regedit_3
[OSCD] regedit.exe LOLbas 72 [3]
2021-01-06 00:16:45 +03:00
yugoslavskiy
8e6b77fc4f
Merge pull request #1177 from OpalSec/oscd
[OSCD] Tasks 24, 25 & 26: Detection for Invoke-Obfuscation CLIP+, STDIN+ & VAR+ Launchers
2021-01-06 00:16:34 +03:00
yugoslavskiy
95d8a9daf0
Merge pull request #1174 from uncleAntik/update
[OSCD] LOLBin vsjitdebugger.exe #136
2021-01-06 00:16:20 +03:00
yugoslavskiy
252345ca00
Merge pull request #1173 from uncleAntik/fix
[OSCD] LOLBin te.exe #133
2021-01-06 00:16:12 +03:00
yugoslavskiy
aeb448cd4d
Merge pull request #1171 from alejandroortuno/network-sniffing
[OSCD] MacOS Network Sniffing
2021-01-06 00:15:52 +03:00
yugoslavskiy
ebc6451b86
Merge pull request #1170 from alejandroortuno/startup-items
[OSCD] MacOS Startup Items
2021-01-06 00:15:45 +03:00
yugoslavskiy
ad739f7f29
Merge pull request #1169 from remotephone/oscd_t1113
[OSCD] - T1113 - macOS Screencapture via builtin screencapture utility
2021-01-06 00:15:37 +03:00
yugoslavskiy
d50c081f3f
Merge pull request #1168 from remotephone/oscd_t1056_002
[OSCD] macOS - T1056.002 - GUI Input capture
2021-01-06 00:15:30 +03:00
yugoslavskiy
1fd0afc58e
Merge pull request #1167 from tas-kmanager/mt-oscd-sigma547-43
[OSCD] Add Accesschk tool usage rule
2021-01-06 00:14:08 +03:00
yugoslavskiy
5ade9208d5
Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
2021-01-06 00:12:34 +03:00
yugoslavskiy
46eb01f3c5
Merge pull request #1164 from GlebSukhodolskiy/oscd_reg
[OSCD] Modified Rule "Autorun Keys Modification"
2021-01-06 00:11:58 +03:00
yugoslavskiy
4c8e0b201d
Merge pull request #1162 from uncleAntik/131
[OSCD] LOLBin sqltoolsps.exe #131
2021-01-06 00:11:33 +03:00
yugoslavskiy
b56a7181ce
Merge pull request #1157 from invrep-de/oscd
[OSCD] Bad Opsec Powershell Artifacts
2021-01-06 00:11:24 +03:00
yugoslavskiy
319ebd158c
Merge pull request #1155 from sn0w0tter/oscd2
[OSCD] LOLBAS atbroker suspicious creation of ATs
2021-01-06 00:11:13 +03:00
yugoslavskiy
d2087c276c
Merge pull request #1151 from zinint/1009-27-2
[OSCD] Detects Obfuscated Powershell via VAR++ Launcher #27 (Services)
2021-01-06 00:10:55 +03:00
yugoslavskiy
1f0d081c01
Merge pull request #1144 from NikitaStormwind/regular28(3)
[OSCD] Detects Obfuscated Powershell via Stdin in Scripts #28 (Services)
2021-01-05 23:23:00 +03:00
yugoslavskiy
1cfc0d17ef
Merge pull request #1141 from omkar72/oscd-6
[OSCD] suspicious clr logs creation
2021-01-05 23:22:36 +03:00
yugoslavskiy
82e5d031b0
Merge pull request #1139 from omkar72/oscd-4
[OSCD] script applications loading .net dll
2021-01-05 23:17:25 +03:00
yugoslavskiy
635ac44949
Merge pull request #1132 from remotephone/oscd_t1070_002
[OSCD] Adding t1070_002 - Clear mac system logs
2021-01-05 23:16:57 +03:00
yugoslavskiy
793d271d37
Merge pull request #1131 from oscd-initiative/oscd_sigma_art_macos_task_63
[OSCD] macOS hidden user creation
2021-01-05 23:16:36 +03:00
yugoslavskiy
a82c559816
Merge pull request #1130 from vburov/patch-13
[OSCD] Create powershell_cmdline_specific_encoded_methods.yml
2021-01-05 23:16:24 +03:00
yugoslavskiy
dd7a95ac74
Merge pull request #1081 from cy1337/patch-1
[OSCD] Added nltest LOLBIN
2021-01-05 23:16:14 +03:00
yugoslavskiy
a4101a6808
Merge pull request #1128 from alejandroortuno/local-group
[OSCD] Local System Groups Discovery
2021-01-05 23:14:47 +03:00
yugoslavskiy
db66f8365e
Merge pull request #1127 from alejandroortuno/account-creation
[OSCD]  MacOS local account creation
2021-01-05 23:14:28 +03:00
yugoslavskiy
f2c6011c6b
Merge pull request #1126 from skirankumar/master
[OSCD]Sysmon_silenttrinity_stager_msbuild_activity.yml
2021-01-05 23:14:20 +03:00
yugoslavskiy
1c1c38e091
Merge pull request #1119 from uncleAntik/oscd
[OSCD] sqlps.exe LOLbin
2021-01-05 23:14:02 +03:00
yugoslavskiy
07ac09f9aa
Merge pull request #1114 from NikitaStormwind/regular29(3)
[OSCD] Detects Obfuscated Powershell via use Clip.exe in Scripts #29 (Services)
2021-01-05 23:13:48 +03:00
yugoslavskiy
220a4873c7
Merge pull request #1109 from NikitaStormwind/regular31(3)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (Services)
2021-01-05 23:13:38 +03:00
yugoslavskiy
9803dc8baa
Merge pull request #1108 from NikitaStormwind/regular30(3)
[OSCD] Detects Obfuscated Powershell via use Rundll32 in Scripts #30 (Services)
2021-01-05 23:13:27 +03:00
yugoslavskiy
39991a8ab6
Merge pull request #1106 from stvetro/2020
[OSCD] Suspicious ftp.exe usage (LOLBin)
2021-01-05 23:13:03 +03:00
yugoslavskiy
804db42b7a
Merge pull request #1105 from Vasilisa-L/OSCD_rasautou
[OSCD] Rasautou.exe LOLbin
2021-01-05 23:12:48 +03:00
yugoslavskiy
794cd7aaeb
Merge pull request #1104 from Vasilisa-L/OSCD_rpcping
[OSCD] rpcping lolbin
2021-01-05 23:12:35 +03:00
yugoslavskiy
05b03afddb
Merge pull request #1103 from concorde18/oscd_win_susp_diskshadow
[OSCD] win_susp_diskshadow
2021-01-05 23:10:55 +03:00
yugoslavskiy
d48bac226f
Merge pull request #1099 from NikitaStormwind/regular31(2)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (process_creation)
2021-01-05 23:10:46 +03:00
yugoslavskiy
32aea9ad2b
Merge pull request #1098 from NikitaStormwind/regular31
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (4104, 4103)
2021-01-05 23:10:28 +03:00
yugoslavskiy
ae3c0d0801
Merge pull request #1095 from esebese/task136
[OSCD]win_pe_exec_vsjitdebugger.yml added
2021-01-05 23:10:18 +03:00
yugoslavskiy
e492263a31
Merge pull request #1091 from alejandroortuno/sigma-local-account-rule
[OSCD] Local System Accounts Discovery
2021-01-05 23:10:09 +03:00