Commit Graph

343 Commits

Author SHA1 Message Date
yugoslavskiy
d9a0f6c41a
Merge pull request #1090 from alejandroortuno/sigma-cron-rule
[OSCD] Scheduled Task/Job: Cron
2021-01-05 23:09:59 +03:00
yugoslavskiy
c8da05fa5d
Merge pull request #1086 from remotephone/oscd
[OSCD] T1016 - linux/macOS firewall enumeration
2021-01-05 23:09:15 +03:00
yugoslavskiy
caf01c57bf
Merge pull request #1083 from omergunal/patch-8
[OSCD] T1082: System Information Discovery - Linux
2021-01-05 23:08:19 +03:00
yugoslavskiy
e002ffa404
Merge pull request #1079 from omergunal/patch-6
[OSCD] T1070.004: File Deletion - Linux
2021-01-05 23:06:12 +03:00
yugoslavskiy
1939b815d6
Merge pull request #1078 from omergunal/patch-5
[OSCD] T1070.002: Clear Linux or Mac System Logs - Linux
2021-01-05 23:06:02 +03:00
yugoslavskiy
75feffb016
Merge pull request #1082 from omergunal/patch-7
[OSCD] T1201: Password Policy Discovery - Linux
2021-01-05 23:02:06 +03:00
yugoslavskiy
3ef76437e4
Merge pull request #1055 from omergunal/patch-2
[OSCD] Scheduled Task/Job: At
2021-01-05 22:59:09 +03:00
yugoslavskiy
f65e7100ec
Merge pull request #1057 from omergunal/patch-4
[OSCD] T1057: Process Discovery
2021-01-05 22:58:35 +03:00
yugoslavskiy
57947fbd39
Merge pull request #1044 from omergunal/patch-1
[OSCD] Linux - Install Root Certificate
2021-01-05 22:56:18 +03:00
yugoslavskiy
733277d490
Merge pull request #1248 from oscd-initiative/oscd_art_macos_task_28_T1083
[OSCD] ART sync, test T1083: File and Directory Discovery (macOS)
2021-01-05 22:55:40 +03:00
yugoslavskiy
f825003690
Merge pull request #1239 from alx1m1k/oscd-4
[OSCD] T1529: System Shutdown/Reboot - Lin/macOS
2021-01-05 22:55:14 +03:00
Thomas Patzke
9b4c1662b0
Merge pull request #1240 from alx1m1k/oscd-5
[OSCD] T1070.006: File Time Attribute Change - Lin/macOS
2020-12-30 23:00:54 +01:00
Thomas Patzke
1dcc56a0b0
Merge pull request #1241 from alx1m1k/oscd-6
[OSCD] T1552.001: Credentials In Files - Lin/macOS
2020-12-30 22:59:49 +01:00
Thomas Patzke
e0f7dc125c
Merge pull request #1244 from oscd-initiative/oscd_art_macos_task_3_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (macOS)
2020-12-30 22:58:26 +01:00
Thomas Patzke
810485993a
Merge pull request #1245 from oscd-initiative/oscd_art_linux_task_4_T1027
[OSCD] ART sync, test T1027: Obfuscated Files or Information (Linux)
2020-12-30 22:57:59 +01:00
Thomas Patzke
aa5396cb9f
Merge pull request #1246 from oscd-initiative/oscd_art_macos_task_14_T1049
[OSCD] ART sync, test T1049: System Network Connections Discovery (macOS)
2020-12-30 22:57:29 +01:00
Thomas Patzke
fb9698345b
Merge pull request #1247 from oscd-initiative/oscd_art_linux_task_8__T1049
[OSCD] ART sync, test T1049: System Network Connections Discovery (Linux)
2020-12-30 22:57:11 +01:00
Thomas Patzke
6a7991ee96
Merge pull request #1250 from oscd-initiative/oscd_art_macos_task_41_T1518.001
[OSCD] ART sync, test T1518.001: Security Software Discovery (macOS)
2020-12-30 22:41:18 +01:00
Thomas Patzke
a88c853237
Merge pull request #1251 from oscd-initiative/oscd_art_linux_task_26_T1518.001
[OSCD] ART sync, test T1518.001: Security Software Discovery (Linux)
2020-12-30 22:40:32 +01:00
Thomas Patzke
436fd37655
Merge pull request #1252 from oscd-initiative/oscd_art_macos_task_55_T1553.001
[OSCD] ART sync, test T1553.001: Gatekeeper Bypass (macOS)
2020-12-30 22:39:36 +01:00
Thomas Patzke
5de952d488
Merge pull request #1253 from oscd-initiative/oscd_art_macos_task_60_T1562.001
[OSCD] ART sync, test T1562.001: Disable or Modify Tools (macOS)
2020-12-30 22:39:15 +01:00
Thomas Patzke
e223d34a6e
Merge pull request #1257 from alejandroortuno/service-scanning
[OSCD] Network Service Scanning
2020-12-30 22:35:47 +01:00
Thomas Patzke
5c03c4d4ec
Merge pull request #1258 from alejandroortuno/applescript
[OSCD] MacOS Applescript
2020-12-30 22:31:30 +01:00
Thomas Patzke
06c168d9b2
Merge pull request #1259 from alejandroortuno/firewall
[OSCD] Firewall Disable (Linux)
2020-12-30 22:30:41 +01:00
Florian Roth
7954684fbf
Merge pull request #1260 from alejandroortuno/remote-system-discovery
[OSCD] Remote System Discovery
2020-12-21 18:32:08 +01:00
Florian Roth
64197d0dec
Merge pull request #1261 from alejandroortuno/emond
[OSCD] MacOS Emond Launch Daemon
2020-12-21 18:30:56 +01:00
yugoslavskiy
378f663502
Update lnx_clear_logs.yml 2020-12-02 01:28:29 +01:00
yugoslavskiy
6ce08935bb
Update lnx_file_deletion.yml 2020-12-02 01:27:35 +01:00
yugoslavskiy
1c4c5af99f
Update lnx_clear_logs.yml 2020-12-02 01:24:59 +01:00
Ömer Günal
4ab522815b
Update lnx_clear_logs.yml 2020-12-01 21:28:12 +03:00
Ömer Günal
d0bb6e9e81
Update lnx_file_deletion.yml 2020-12-01 21:24:57 +03:00
Florian Roth
c17c034cb5
Changed selections and condition
see manpage for security tool on macOS
https://gist.github.com/Capybara/6228955
2020-11-27 19:23:31 +01:00
Tim I
78d201ad15 Fix value modifier and add a slash 2020-11-24 23:06:21 +03:00
Alejandro Ortuno
000c038ede Retrigger tests 2020-11-20 09:30:43 +01:00
Alejandro Ortuno
cfcda8d25f Trigger new test execution 2020-11-20 09:29:09 +01:00
Ömer Günal
1582c5230a
Update lnx_process_discovery.yml 2020-11-18 23:25:15 +03:00
Thomas Patzke
199a897f75 Fix rule indent 2020-11-17 10:12:55 +01:00
yugoslavskiy
2939b33ab5
Update lnx_network_service_scanning.yml 2020-11-16 01:00:09 +01:00
Ömer Günal
edc416a1d8
Update lnx_system_info_discovery.yml 2020-11-14 19:24:23 +03:00
Ömer Günal
821bdf8ab4
Update lnx_install_root_certificate.yml 2020-11-14 19:19:28 +03:00
Ömer Günal
19cad11a4a
Update lnx_system_info_discovery.yml 2020-11-10 20:11:49 +03:00
Ömer Günal
ab959394ab
Update lnx_install_root_certificate.yml 2020-11-10 20:09:46 +03:00
Ömer Günal
f41accab33
Update lnx_install_root_certificate.yml 2020-11-10 20:09:03 +03:00
Alejandro Ortuno
ad031d97ee Filter out listening mode on nc 2020-11-09 10:32:56 +01:00
Ömer Günal
577165b7f7
Update lnx_system_info_discovery.yml 2020-11-08 11:09:27 +03:00
Ömer Günal
0e4a5baf1a
Update lnx_install_root_certificate.yml 2020-11-08 11:08:30 +03:00
Ömer Günal
499a8f85b0
Update lnx_install_root_certificate.yml 2020-11-08 11:06:11 +03:00
Ömer Günal
5dc3472af0
Update lnx_system_info_discovery.yml 2020-11-07 11:51:53 +03:00
Ömer Günal
89a24d4bfa
Update lnx_install_root_certificate.yml 2020-11-07 11:50:30 +03:00
yugoslavskiy
c17e8574d0
change the syntax a bit and removed .service suffix as it is
[redundant](https://www.freedesktop.org/software/systemd/man/systemctl.html]:

```
Unit commands listed above take either a single unit name (designated as UNIT), or multiple unit specifications (designated as PATTERN…). In the first case, the unit name with or without a suffix must be given. If the suffix is not specified (unit name is "abbreviated"), systemctl will append a suitable suffix, ".service" by default, and a type-specific suffix in case of commands which operate only on specific unit types. For example,

# systemctl start sshd
and
# systemctl start sshd.service

are equivalent
```
2020-11-06 20:56:08 +01:00