frack113
b9a355e3f4
cleanup falsepositives
2021-08-20 17:18:32 +02:00
Florian Roth
b92346ba5f
Merge pull request #1882 from austinsonger/win_susp_bitstransfer.yml
...
win_susp_bitstransfer.yml
2021-08-20 16:53:52 +02:00
Florian Roth
ecd0bb4576
Merge pull request #1890 from frack113/update_conti_ref
...
update ref from conti_leak
2021-08-20 16:53:12 +02:00
Florian Roth
700b8e440f
Merge pull request #1868 from d4rk-d4nph3/master
...
Added rule for zero day CVE-2021-22123 in Fortinet WAFs
2021-08-20 16:52:49 +02:00
Rachel Rice
f037f5b0a9
Add filter3 back for vm export failure, without consolelogin
...
Signed-off-by: Rachel Rice <rachel.rice@lacework.net>
2021-08-20 15:42:49 +01:00
frack113
5cfadf5d64
Merge pull request #1891 from frack113/fix_sigma_similarity_backend_error
...
sigma_similarity fix when backend support error
2021-08-20 15:38:28 +02:00
Austin Songer
a25f6e196f
Update microsoft365_unusual_volume_of_file_deletion.yml
2021-08-20 08:17:25 -05:00
Austin Songer
360b936357
Update microsoft365_potential_ransomware_activity.yml
2021-08-20 08:17:09 -05:00
Austin Songer
ae36804935
Update microsoft365_user_restricted_from_sending_email.yml
2021-08-20 08:16:48 -05:00
Rachel Rice
f09b3ea4b1
Update AWS CloudTrail rules
...
aws_ec2_disable_encryption.yml
Remove `status: success` from selection criteria, not required
aws_ec2_vm_export_failure.yml
Remove filter3:
```
eventName: 'ConsoleLogin'
responseElements|contains: 'Failure'
```
Incompatible with selection criteria `eventName: 'CreateInstanceExportTask'`
aws_ec2_download_userdata.yml, aws_iam_backdoor_users_keys.yml, aws_rds_change_master_password.yml, aws_rds_public_db_restore.yml
Update reference
aws_sts_assumedrole_misuse.yml
Rename to aws_sts_assumerole_misuse.yml
Update references to "AssumedRole" to "AssumeRole"
Update selection criteria of `userIdentity.sessionContext: Role` to `userIdentity.sessionContext.sessionIssuer.type: Role`
2021-08-20 13:43:00 +01:00
frack113
7ebd411190
update ref from conti_leak
2021-08-20 14:22:17 +02:00
frack113
f6fe5e7d02
fix when backend support error
2021-08-20 13:58:57 +02:00
frack113
4e895da471
fix error "has no len()"
2021-08-20 09:20:56 +02:00
frack113
4e29dc9c45
fix title
2021-08-20 09:06:16 +02:00
frack113
9b106dcc7d
Merge pull request #1880 from austinsonger/azure_suppression_rule_created.yml
...
azure_suppression_rule_created.yml
2021-08-20 09:04:48 +02:00
frack113
d58b1e8e40
Merge pull request #1879 from austinsonger/azure_application_gateway_modified_or_deleted.yml
...
azure_application_gateway_modified_or_deleted.yml
2021-08-20 09:03:57 +02:00
frack113
4b08aac47f
Merge pull request #1878 from austinsonger/azure_application_security_group_modified_or_deleted.yml
...
azure_application_security_group_modified_or_deleted.yml
2021-08-20 09:01:39 +02:00
frack113
cf2b0dd1a6
Merge pull request #1886 from austinsonger/m365.yml
...
Add m365.yml
2021-08-20 09:01:16 +02:00
Austin Songer
853c2eb41d
Update microsoft365_potential_ransomware_activity.yml
2021-08-20 01:19:01 -05:00
Austin Songer
f745593e80
Update microsoft365_potential_ransomware_activity.yml
2021-08-20 00:33:42 -05:00
Austin Songer
e6457531dd
Create m365.yml
2021-08-20 00:29:29 -05:00
Austin Songer
ba418eb057
Merge branch 'SigmaHQ:master' into m365.yml
2021-08-20 00:23:31 -05:00
frack113
ec97e12e35
Merge pull request #1881 from austinsonger/@austinsonger
...
Update author.
2021-08-20 06:31:44 +02:00
Austin Songer
42fbc0cbfc
Update aws_eks_cluster_created_or_deleted.yml
2021-08-19 23:13:35 -05:00
Austin Songer
bcb43cf728
Update aws_eks_cluster_created_or_deleted.yml
2021-08-19 23:13:06 -05:00
Austin Songer
b89910a38a
Update aws_eks_cluster_created_or_deleted.yml
2021-08-19 23:09:38 -05:00
frack113
f882ebda35
fix status
2021-08-20 06:08:28 +02:00
Austin Songer
54bda90685
Create microsoft365_user_restricted_from_sending_email.yml
2021-08-19 23:08:25 -05:00
Austin Songer
9b19190ea7
Create microsoft365_potential_ransomware_activity.yml
2021-08-19 23:05:05 -05:00
Austin Songer
99fbd4ef44
Create microsoft365_unusual_volume_of_file_deletion.yml
2021-08-19 23:00:23 -05:00
Austin Songer
fe0e1353e0
Update win_susp_bitstransfer.yml
2021-08-19 22:24:23 -05:00
Austin Songer
810aae5ddd
Update aws_eks_cluster_created_or_deleted.yml
2021-08-19 21:58:36 -05:00
Austin Songer
8d57ae5ffd
Create win_susp_bitstransfer.yml
2021-08-19 21:57:37 -05:00
Austin Songer
0a3e57cc12
Update
2021-08-20 02:10:32 +00:00
Austin Songer
842ade16be
Forgot to add my username to some of the rules.
2021-08-20 02:09:31 +00:00
Austin Songer
9a83836070
Update aws_eks_cluster_created_or_deleted.yml
2021-08-19 21:00:36 -05:00
Austin Songer
6ae62488b3
Merge branch 'SigmaHQ:master' into azure_application_gateway_modified_or_deleted.yml
2021-08-19 20:32:35 -05:00
Austin Songer
d2f87feb7b
Merge branch 'SigmaHQ:master' into azure_application_security_group_modified_or_deleted.yml
2021-08-19 20:31:48 -05:00
frack113
0103b148f7
Merge pull request #1876 from rachelrice/update_cloudtrail_rules
...
Update AWS CloudTrail rules
2021-08-19 18:33:07 +02:00
frack113
23ad8cd14e
remove bad rules
2021-08-19 18:30:32 +02:00
frack113
3283664154
Update remove useless rules
2021-08-19 18:28:44 +02:00
frack113
f1a84536c3
update fix
2021-08-19 17:55:41 +02:00
frack113
39617c9807
Merge pull request #1865 from austinsonger/azure_keyvault_secrets_modified_or_deleted.yml
...
add azure_keyvault_secrets_modified_or_deleted.yml
2021-08-19 17:06:28 +02:00
frack113
600c6233c2
Merge pull request #1874 from gs3cl/patch-1
...
Update win_nltest_query.yml
2021-08-19 16:18:20 +02:00
frack113
78212546a7
Merge pull request #1869 from frack113/redcanary_T1546.013
...
powershell_trigger_profiles T1546.013
2021-08-19 16:17:53 +02:00
frack113
90c9c08743
fix title
2021-08-19 16:09:31 +02:00
Austin Songer
cc51e054e3
Update azure_keyvault_secrets_modified_or_deleted.yml
2021-08-19 09:04:22 -05:00
frack113
89b6e1108b
powershell_wmi_persistence fix errors
2021-08-19 15:42:19 +02:00
frack113
1266a66a8d
add powershell_wmi_persistence.yml
2021-08-19 15:37:28 +02:00
Rachel Rice
67020bb0ff
Update AWS CloudTrail rules
...
aws_elasticache_security_group_created.yml
aws_elasticache_security_group_modified_or_deleted.yml
Removed spaces from eventNames
aws_s3_data_management_tampering.yml
Fix typo in title, use s3 as eventSource
aws_snapshot_backup_exfiltration.yml
Use ec2 as eventSource
2021-08-19 14:24:43 +01:00