Jonhnathan
|
ce4e22750d
|
Update powershell_winlogon_helper_dll.yml
|
2020-10-15 17:15:23 -03:00 |
|
Jonhnathan
|
efe9c2d3d6
|
Update powershell_shellcode_b64.yml
|
2020-10-15 17:14:01 -03:00 |
|
Jonhnathan
|
013533fceb
|
Update powershell_prompt_credentials.yml
|
2020-10-15 17:13:16 -03:00 |
|
Jonhnathan
|
8cf2596068
|
Update powershell_malicious_keywords.yml
|
2020-10-15 17:12:08 -03:00 |
|
Jonhnathan
|
ec10d5a61f
|
Update powershell_malicious_commandlets.yml
|
2020-10-15 17:11:20 -03:00 |
|
Jonhnathan
|
4a3607d50b
|
Update powershell_exe_calling_ps.yml
|
2020-10-15 17:09:47 -03:00 |
|
aw350m3
|
eb6b9be5a2
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
|
aw350m3
|
c28fce6273
|
fix duplication of key "modified" in mapping
|
2020-08-25 00:53:09 +00:00 |
|
aw350m3
|
c22273d162
|
fix duplication of key modified in mapping
|
2020-08-25 00:50:38 +00:00 |
|
aw350m3
|
399f378269
|
att&ck tags review: windows/powershell, windows/process_access, windows/network_connection
|
2020-08-24 23:31:26 +00:00 |
|
aw350m3
|
ba2e891433
|
windows/powershell folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
|
2020-08-24 00:01:50 +00:00 |
|
Ryan Plas
|
de53a08746
|
Merge branch 'master' of github.com:Neo23x0/sigma
|
2020-07-15 10:27:33 -04:00 |
|
Florian Roth
|
58b68758b4
|
fix: wrong MITRE ATT&CK ids used in the beta version
|
2020-07-14 17:53:32 +02:00 |
|
Ryan Plas
|
04fd598bcf
|
Update additional rules to have correct logsource attributes
|
2020-07-13 17:02:17 -04:00 |
|
Ryan Plas
|
25d978d9bd
|
Update powershell_shellcode_b64.yml logsource to use the correct Sigma schema values
|
2020-07-11 22:17:06 -04:00 |
|
Thomas Patzke
|
7eb499ad85
|
Added rule id
|
2020-07-07 22:54:55 +02:00 |
|
Thomas Patzke
|
360b5714a8
|
Splitted and improved new rule
|
2020-07-07 22:47:14 +02:00 |
|
Thomas Patzke
|
0ce5f2cc75
|
Merge branch 'patch-2' of https://github.com/4A616D6573/sigma into pr-483
|
2020-07-07 22:37:11 +02:00 |
|
Harish SEGAR
|
649e4eaa63
|
Added new rule for pwsh_xor_cmd
|
2020-06-29 22:09:58 +02:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
zaphod
|
1a598282f4
|
Add 'Add-Content' to powershell_ntfs_ads_access
|
2020-05-13 11:57:10 +02:00 |
|
Remco Verhoef
|
40539a0c0e
|
fix incorrect use of action global
|
2020-05-06 22:53:02 +02:00 |
|
Florian Roth
|
4f469c0e39
|
Adjusted level
|
2020-04-14 13:37:10 +02:00 |
|
teddy-ROxPin
|
1501331f77
|
Create powershell_create_local_user.yml
Adds coverage for creating a local account via PowerShell from https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1136/T1136.md#atomic-test-4---create-a-new-user-in-powershell
|
2020-04-11 02:51:05 -06:00 |
|
Florian Roth
|
0ea2db8b9e
|
Merge pull request #484 from hieuttmmo/master
New sigma rules to detect new MITRE technique in last update (T1502)
|
2020-04-03 09:59:36 +02:00 |
|
Florian Roth
|
f4928e95bc
|
Update powershell_suspicious_profile_create.yml
|
2020-04-03 09:36:17 +02:00 |
|
Florian Roth
|
c0ab9c5745
|
Merge pull request #671 from HarishHary/powershell_downgrade_attack
Powershell downgrade attack (small improvements)
|
2020-04-03 09:31:33 +02:00 |
|
Florian Roth
|
6cf0edc076
|
Merge pull request #685 from teddy-ROxPin/patch-1
Typo fix for powershell_suspicious_invocation_generic.yml
|
2020-04-03 09:30:32 +02:00 |
|
Remco Hofman
|
b791d599ee
|
Disabled keywords that could cause FPs
|
2020-03-30 08:53:52 +02:00 |
|
teddy-ROxPin
|
1a3731f7ae
|
Typo fix for powershell_suspicious_invocation_generic.yml
' - windowstyle hidden ' changed to ' -windowstyle hidden '
|
2020-03-29 04:16:15 -06:00 |
|
Remco Hofman
|
f52ed4150d
|
WMImplant parameter detection
|
2020-03-27 15:08:35 +01:00 |
|
Florian Roth
|
35e43db7a7
|
fix: converted CRLF line break to LF
|
2020-03-25 14:36:34 +01:00 |
|
Harish SEGAR
|
67694e4ba7
|
Restructure new improvement to process_creation folder.
|
2020-03-20 23:29:32 +01:00 |
|
Harish SEGAR
|
b9a916ceb4
|
Removed useless condition.
|
2020-03-20 22:50:26 +01:00 |
|
Harish SEGAR
|
30fac9545a
|
Fixed author field.
|
2020-03-20 22:49:07 +01:00 |
|
Harish SEGAR
|
1f251cec07
|
Added missing action field
|
2020-03-20 22:46:19 +01:00 |
|
Harish SEGAR
|
293018a9e7
|
Added conditions...
|
2020-03-20 22:33:14 +01:00 |
|
Harish SEGAR
|
74b81120e4
|
Usage of value modifiers...
|
2020-03-20 22:03:48 +01:00 |
|
Harish SEGAR
|
b129f09fee
|
Improvement detection on downgrade of powershell
|
2020-03-20 21:48:19 +01:00 |
|
Florian Roth
|
dd1a0e764c
|
docs: more false positive conditions
|
2020-02-25 11:13:58 +01:00 |
|
Florian Roth
|
5d96f81a84
|
fix: lowered level due to false positives
|
2020-02-25 11:12:11 +01:00 |
|
Thomas Patzke
|
48d95f027c
|
Merge branch 'oscd'
|
2020-02-20 23:11:57 +01:00 |
|
Thomas Patzke
|
373424f145
|
Rule fixes
Made tests pass the new CI tests. Added further allowed lower case words
in rule test.
|
2020-02-20 23:00:16 +01:00 |
|
Florian Roth
|
a4c210ed16
|
rule: remove keywords in powershell rule prone to FPs
|
2020-02-11 16:26:17 +01:00 |
|
Thomas Patzke
|
d7bd90cb24
|
Merge branch 'master' into oscd
|
2020-02-03 23:13:16 +01:00 |
|
Thomas Patzke
|
815c562a17
|
Merge branch 'master' into oscd
|
2020-02-02 13:40:08 +01:00 |
|
Thomas Patzke
|
f59b36d891
|
Fixed rule
|
2020-02-02 12:54:56 +01:00 |
|
Thomas Patzke
|
593abb1cce
|
OSCD QA wave 3
|
2020-02-02 12:41:12 +01:00 |
|
Florian Roth
|
7a222920df
|
added 'date'
|
2020-01-31 15:27:30 +01:00 |
|
Florian Roth
|
913c839780
|
added 'id'
|
2020-01-31 15:26:43 +01:00 |
|