yugoslavskiy
|
ebc6451b86
|
Merge pull request #1170 from alejandroortuno/startup-items
[OSCD] MacOS Startup Items
|
2021-01-06 00:15:45 +03:00 |
|
yugoslavskiy
|
ad739f7f29
|
Merge pull request #1169 from remotephone/oscd_t1113
[OSCD] - T1113 - macOS Screencapture via builtin screencapture utility
|
2021-01-06 00:15:37 +03:00 |
|
yugoslavskiy
|
d50c081f3f
|
Merge pull request #1168 from remotephone/oscd_t1056_002
[OSCD] macOS - T1056.002 - GUI Input capture
|
2021-01-06 00:15:30 +03:00 |
|
yugoslavskiy
|
1fd0afc58e
|
Merge pull request #1167 from tas-kmanager/mt-oscd-sigma547-43
[OSCD] Add Accesschk tool usage rule
|
2021-01-06 00:14:08 +03:00 |
|
yugoslavskiy
|
5ade9208d5
|
Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
|
2021-01-06 00:12:34 +03:00 |
|
yugoslavskiy
|
46eb01f3c5
|
Merge pull request #1164 from GlebSukhodolskiy/oscd_reg
[OSCD] Modified Rule "Autorun Keys Modification"
|
2021-01-06 00:11:58 +03:00 |
|
yugoslavskiy
|
4c8e0b201d
|
Merge pull request #1162 from uncleAntik/131
[OSCD] LOLBin sqltoolsps.exe #131
|
2021-01-06 00:11:33 +03:00 |
|
yugoslavskiy
|
b56a7181ce
|
Merge pull request #1157 from invrep-de/oscd
[OSCD] Bad Opsec Powershell Artifacts
|
2021-01-06 00:11:24 +03:00 |
|
yugoslavskiy
|
319ebd158c
|
Merge pull request #1155 from sn0w0tter/oscd2
[OSCD] LOLBAS atbroker suspicious creation of ATs
|
2021-01-06 00:11:13 +03:00 |
|
yugoslavskiy
|
d2087c276c
|
Merge pull request #1151 from zinint/1009-27-2
[OSCD] Detects Obfuscated Powershell via VAR++ Launcher #27 (Services)
|
2021-01-06 00:10:55 +03:00 |
|
yugoslavskiy
|
1f0d081c01
|
Merge pull request #1144 from NikitaStormwind/regular28(3)
[OSCD] Detects Obfuscated Powershell via Stdin in Scripts #28 (Services)
|
2021-01-05 23:23:00 +03:00 |
|
yugoslavskiy
|
1cfc0d17ef
|
Merge pull request #1141 from omkar72/oscd-6
[OSCD] suspicious clr logs creation
|
2021-01-05 23:22:36 +03:00 |
|
yugoslavskiy
|
82e5d031b0
|
Merge pull request #1139 from omkar72/oscd-4
[OSCD] script applications loading .net dll
|
2021-01-05 23:17:25 +03:00 |
|
yugoslavskiy
|
635ac44949
|
Merge pull request #1132 from remotephone/oscd_t1070_002
[OSCD] Adding t1070_002 - Clear mac system logs
|
2021-01-05 23:16:57 +03:00 |
|
yugoslavskiy
|
793d271d37
|
Merge pull request #1131 from oscd-initiative/oscd_sigma_art_macos_task_63
[OSCD] macOS hidden user creation
|
2021-01-05 23:16:36 +03:00 |
|
yugoslavskiy
|
a82c559816
|
Merge pull request #1130 from vburov/patch-13
[OSCD] Create powershell_cmdline_specific_encoded_methods.yml
|
2021-01-05 23:16:24 +03:00 |
|
yugoslavskiy
|
dd7a95ac74
|
Merge pull request #1081 from cy1337/patch-1
[OSCD] Added nltest LOLBIN
|
2021-01-05 23:16:14 +03:00 |
|
yugoslavskiy
|
a4101a6808
|
Merge pull request #1128 from alejandroortuno/local-group
[OSCD] Local System Groups Discovery
|
2021-01-05 23:14:47 +03:00 |
|
yugoslavskiy
|
db66f8365e
|
Merge pull request #1127 from alejandroortuno/account-creation
[OSCD] MacOS local account creation
|
2021-01-05 23:14:28 +03:00 |
|
yugoslavskiy
|
f2c6011c6b
|
Merge pull request #1126 from skirankumar/master
[OSCD]Sysmon_silenttrinity_stager_msbuild_activity.yml
|
2021-01-05 23:14:20 +03:00 |
|
yugoslavskiy
|
1c1c38e091
|
Merge pull request #1119 from uncleAntik/oscd
[OSCD] sqlps.exe LOLbin
|
2021-01-05 23:14:02 +03:00 |
|
yugoslavskiy
|
07ac09f9aa
|
Merge pull request #1114 from NikitaStormwind/regular29(3)
[OSCD] Detects Obfuscated Powershell via use Clip.exe in Scripts #29 (Services)
|
2021-01-05 23:13:48 +03:00 |
|
yugoslavskiy
|
220a4873c7
|
Merge pull request #1109 from NikitaStormwind/regular31(3)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (Services)
|
2021-01-05 23:13:38 +03:00 |
|
yugoslavskiy
|
9803dc8baa
|
Merge pull request #1108 from NikitaStormwind/regular30(3)
[OSCD] Detects Obfuscated Powershell via use Rundll32 in Scripts #30 (Services)
|
2021-01-05 23:13:27 +03:00 |
|
yugoslavskiy
|
39991a8ab6
|
Merge pull request #1106 from stvetro/2020
[OSCD] Suspicious ftp.exe usage (LOLBin)
|
2021-01-05 23:13:03 +03:00 |
|
yugoslavskiy
|
804db42b7a
|
Merge pull request #1105 from Vasilisa-L/OSCD_rasautou
[OSCD] Rasautou.exe LOLbin
|
2021-01-05 23:12:48 +03:00 |
|
yugoslavskiy
|
794cd7aaeb
|
Merge pull request #1104 from Vasilisa-L/OSCD_rpcping
[OSCD] rpcping lolbin
|
2021-01-05 23:12:35 +03:00 |
|
yugoslavskiy
|
05b03afddb
|
Merge pull request #1103 from concorde18/oscd_win_susp_diskshadow
[OSCD] win_susp_diskshadow
|
2021-01-05 23:10:55 +03:00 |
|
yugoslavskiy
|
d48bac226f
|
Merge pull request #1099 from NikitaStormwind/regular31(2)
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (process_creation)
|
2021-01-05 23:10:46 +03:00 |
|
yugoslavskiy
|
32aea9ad2b
|
Merge pull request #1098 from NikitaStormwind/regular31
[OSCD] Detects Obfuscated Powershell via use MSHTA in Scripts #31 (4104, 4103)
|
2021-01-05 23:10:28 +03:00 |
|
yugoslavskiy
|
ae3c0d0801
|
Merge pull request #1095 from esebese/task136
[OSCD]win_pe_exec_vsjitdebugger.yml added
|
2021-01-05 23:10:18 +03:00 |
|
yugoslavskiy
|
e492263a31
|
Merge pull request #1091 from alejandroortuno/sigma-local-account-rule
[OSCD] Local System Accounts Discovery
|
2021-01-05 23:10:09 +03:00 |
|
yugoslavskiy
|
d9a0f6c41a
|
Merge pull request #1090 from alejandroortuno/sigma-cron-rule
[OSCD] Scheduled Task/Job: Cron
|
2021-01-05 23:09:59 +03:00 |
|
yugoslavskiy
|
aa9182593a
|
Merge pull request #1087 from Vasilisa-L/OSCD_pester.bat
[OSCD] 109: Pester.bat
|
2021-01-05 23:09:47 +03:00 |
|
yugoslavskiy
|
c8da05fa5d
|
Merge pull request #1086 from remotephone/oscd
[OSCD] T1016 - linux/macOS firewall enumeration
|
2021-01-05 23:09:15 +03:00 |
|
yugoslavskiy
|
caf01c57bf
|
Merge pull request #1083 from omergunal/patch-8
[OSCD] T1082: System Information Discovery - Linux
|
2021-01-05 23:08:19 +03:00 |
|
yugoslavskiy
|
1992b1ac9f
|
Merge pull request #1074 from semanurguneysu/oscd
[OSCD] Create sysmon_abusing_debug_privilege.yml
|
2021-01-05 23:06:57 +03:00 |
|
yugoslavskiy
|
b5c78212ad
|
Merge pull request #1076 from nsaddler/oscd5
[OSCD] Powershell without powershell.exe Rule Added
|
2021-01-05 23:06:37 +03:00 |
|
yugoslavskiy
|
c7e9522f29
|
Merge pull request #1077 from uchakin/oscd
[OSCD] UAC bypass added
|
2021-01-05 23:06:24 +03:00 |
|
yugoslavskiy
|
e002ffa404
|
Merge pull request #1079 from omergunal/patch-6
[OSCD] T1070.004: File Deletion - Linux
|
2021-01-05 23:06:12 +03:00 |
|
yugoslavskiy
|
1939b815d6
|
Merge pull request #1078 from omergunal/patch-5
[OSCD] T1070.002: Clear Linux or Mac System Logs - Linux
|
2021-01-05 23:06:02 +03:00 |
|
yugoslavskiy
|
ff373b0f33
|
Update win_nltest_query.yml
|
2021-01-05 23:03:41 +03:00 |
|
yugoslavskiy
|
75feffb016
|
Merge pull request #1082 from omergunal/patch-7
[OSCD] T1201: Password Policy Discovery - Linux
|
2021-01-05 23:02:06 +03:00 |
|
yugoslavskiy
|
bceb3c8af0
|
Merge pull request #1047 from grikos/sigma/oscd
[OSCD] Registry modify via VBoxDrvInst
|
2021-01-05 23:00:20 +03:00 |
|
yugoslavskiy
|
3ef76437e4
|
Merge pull request #1055 from omergunal/patch-2
[OSCD] Scheduled Task/Job: At
|
2021-01-05 22:59:09 +03:00 |
|
yugoslavskiy
|
f65e7100ec
|
Merge pull request #1057 from omergunal/patch-4
[OSCD] T1057: Process Discovery
|
2021-01-05 22:58:35 +03:00 |
|
yugoslavskiy
|
87e5e5a7fc
|
Merge pull request #1069 from nsaddler/oscd3
[OSCD] Powershell Script Installed as a Service Rule added
|
2021-01-05 22:58:21 +03:00 |
|
yugoslavskiy
|
738bb4af90
|
Merge pull request #1041 from ryanplasma/rplas-SIGMA-547-page-13
[OSCD] Add Stored Credentials in Fake Files rule
|
2021-01-05 22:57:36 +03:00 |
|
yugoslavskiy
|
57947fbd39
|
Merge pull request #1044 from omergunal/patch-1
[OSCD] Linux - Install Root Certificate
|
2021-01-05 22:56:18 +03:00 |
|
yugoslavskiy
|
733277d490
|
Merge pull request #1248 from oscd-initiative/oscd_art_macos_task_28_T1083
[OSCD] ART sync, test T1083: File and Directory Discovery (macOS)
|
2021-01-05 22:55:40 +03:00 |
|