yt0ng
e44b4f450e
DNS TXT Answer with possible execution strings
...
https://twitter.com/stvemillertime/status/1024707932447854592
2018-08-08 15:51:56 +02:00
Florian Roth
9640806678
Rules: Telegram Bot API access
2018-06-05 16:25:43 +02:00
Florian Roth
1aaed07dd7
Rule: Suspicious base64 encoded part of DNS query
2018-05-10 14:08:52 +02:00
Florian Roth
62b490396d
Rule: Cobalt Strike DNS Beaconing
2018-05-10 14:08:52 +02:00
Thomas Patzke
986c9ff9b7
Added field names to first rules
2017-09-12 23:54:04 +02:00
Thomas Patzke
5c465129bd
Fixed rules
...
* Replaced unspecified logsource attribute 'type' with 'category'
* Usage of service 'auth' for linux logs
2017-09-11 00:35:52 +02:00
Thomas Patzke
27e5d0c2b4
Fixed further parse error
2017-08-02 23:32:00 +02:00
Florian Roth
37449e2c5d
Fix: Search to log source in network rule
2017-04-15 11:32:38 +02:00
Florian Roth
b1446f9b87
Removed 'last' keyword from 'timeframe' fields
2017-02-28 17:52:40 +01:00
Thomas Patzke
15c6f9411b
Rule review
...
* Typos
* Added false positive descriptions
2017-02-24 23:44:42 +01:00
Florian Roth
166f207dc0
Sysmon rules 'logsource' change
2017-02-19 09:19:06 +01:00
Florian Roth
cd6e24c5ff
Added "logsource" sections and new rule
2017-02-19 00:31:59 +01:00
Florian Roth
18fd63f6b7
Levels to low, medium, high, critical
2017-02-16 18:06:22 +01:00
Thomas Patzke
88270fcf2d
Rule review and cleanup
...
* removed unnecessary one element lists from definitions
* converted some lists of one element maps to maps because the resulting
OR linkage would cause wrong result.
2017-02-15 23:53:08 +01:00
Florian Roth
a2adb1ddb5
Renamed rule files, new rules
2017-02-10 19:17:02 +01:00
Thomas Patzke
97847a29de
Moved network rules into rules directory
2017-02-08 12:43:50 +01:00