Thomas Patzke
|
f0e89b0c8c
|
Fixed: typecheck in sumologig-cse
|
2020-10-23 19:49:55 +02:00 |
|
Thomas Patzke
|
e30237c5c5
|
Fixed test configuration
|
2020-10-23 19:30:59 +02:00 |
|
Thomas Patzke
|
2fb7dd5e99
|
Fixes
* Removed Splunk regex query
* Added test for sumologic-cse backend
|
2020-10-23 15:31:00 +02:00 |
|
Thomas Patzke
|
9dc806448c
|
Merge branch 'master' of https://github.com/socprime/sigma into pr-1049
|
2020-10-23 14:57:25 +02:00 |
|
vh
|
383823f49a
|
Fix: added default value of current_table
|
2020-10-21 10:12:17 +03:00 |
|
vh
|
f45e45d736
|
Fix: Import SigmaRegularExpressionModifier in the splunk backend.
|
2020-10-20 18:13:53 +03:00 |
|
Florian Roth
|
e7462be5b9
|
Merge pull request #1254 from Neo23x0/rule-devel
Rule devel
|
2020-10-20 13:53:30 +02:00 |
|
Florian Roth
|
ee789a309c
|
fix: FP with expression
|
2020-10-20 13:11:10 +02:00 |
|
Florian Roth
|
198b292c26
|
rule: emotet encoded commands
|
2020-10-20 12:51:58 +02:00 |
|
Florian Roth
|
75f177210e
|
Merge pull request #1205 from Neo23x0/rule-devel
fix: ping hex ip rule
|
2020-10-16 12:33:03 +02:00 |
|
Florian Roth
|
986b711de6
|
Merge branch 'master' into rule-devel
|
2020-10-16 12:01:29 +02:00 |
|
Florian Roth
|
48f1be04d4
|
fix: ping hex ip rule
|
2020-10-16 10:06:24 +02:00 |
|
Thomas Patzke
|
f064102399
|
Merge pull request #996 from fryguy04/master
removed leading slash and allow for mult spaces
|
2020-10-12 23:32:17 +02:00 |
|
Thomas Patzke
|
976fc92b22
|
Merge pull request #971 from alan8trend/parse_nested_parentheses
Add support nested parentheses for Sigma condition
|
2020-10-12 23:30:36 +02:00 |
|
Thomas Patzke
|
e8cdd4777a
|
Merge pull request #1026 from ryanplasma/fix-pymisp-error
Fix error with pymisp in sigma2misp
|
2020-10-12 23:14:13 +02:00 |
|
Florian Roth
|
d30502cdab
|
Merge pull request #1134 from Neo23x0/rule-devel
Rule devel
|
2020-10-12 10:25:13 +02:00 |
|
Florian Roth
|
3affdd12e0
|
fix: rule title casing
|
2020-10-12 09:51:35 +02:00 |
|
Florian Roth
|
0d0cda0f86
|
docs: improved false positive notes
|
2020-10-12 09:18:42 +02:00 |
|
Florian Roth
|
e7c6794ecd
|
rule: suspicious wmic process call create + rundll32
|
2020-10-12 09:18:30 +02:00 |
|
Florian Roth
|
2e732eb01f
|
Merge branch 'master' into rule-devel
|
2020-10-12 09:13:24 +02:00 |
|
vh
|
51df5ad876
|
Added:
Sumo Logic CSE Rule Backend
Updated:
Mapping depence on logsource
Azure Sentinel Query Backend
MDATP: query with few logsources
CROWDSTRIKE: fix generateMapItemTypedNode
|
2020-10-06 15:07:52 +03:00 |
|
Florian Roth
|
c56cd2dfff
|
Merge pull request #1024 from omkar72/master
Com hijack shell folder
|
2020-10-02 09:24:16 +02:00 |
|
omkargudhate22
|
4487d9cc7e
|
added event type & changed technique
|
2020-10-02 09:22:14 +05:30 |
|
Florian Roth
|
d3ee1aba66
|
docs: MITRE ATT&CK(R) trademark references removed or adjusted
https://github.com/Neo23x0/sigma/issues/1028
|
2020-09-30 08:53:52 +02:00 |
|
Ryan Plas
|
cdbee4b531
|
Fix error with pymisp in sigma2misp
|
2020-09-29 12:01:33 -04:00 |
|
Florian Roth
|
c17ca6d5fe
|
Merge pull request #1018 from savvyspoon/wcry-dns
WannaCry Killswitch domain DNS query
|
2020-09-29 09:27:21 +02:00 |
|
omkargudhate22
|
68a992d903
|
updated name
|
2020-09-27 21:57:19 +05:30 |
|
omkargudhate22
|
e7c8197e34
|
Updated fields & renamed
|
2020-09-27 21:52:59 +05:30 |
|
omkargudhate22
|
ebe3dce1d7
|
Update sysmon_comhijack_uac_bypass.yml
|
2020-09-27 21:44:41 +05:30 |
|
omkar72
|
3f148e6c7c
|
COM hijack of shell folder to execute arbitrary application & UAC bypass using sdclt.
|
2020-09-27 21:19:04 +05:30 |
|
omkargudhate22
|
15c8721e7b
|
Merge pull request #1 from Neo23x0/master
Updating my fork
|
2020-09-27 19:12:36 +05:30 |
|
Florian Roth
|
d7d9c0e772
|
Merge pull request #1021 from hieuttmmo/master
Sigma rule to detect AdFind.exe execution
|
2020-09-27 09:50:41 +02:00 |
|
Florian Roth
|
8020fe3c40
|
false positive condition
|
2020-09-26 17:03:29 +02:00 |
|
Florian Roth
|
60795f7050
|
Update win_susp_adfind.yml
Fear that a simple adfind.exe causes too many false positives
|
2020-09-26 17:02:39 +02:00 |
|
Florian Roth
|
dbdd758365
|
Duplicate Rule
we already have a rule for that
|
2020-09-26 17:01:32 +02:00 |
|
Tran Trung Hieu
|
d4dd0600ad
|
Fix logsource service to process_creation
|
2020-09-26 21:45:23 +07:00 |
|
Tran Trung Hieu
|
c756fc8576
|
Detect Suspicious AdFind Execution
|
2020-09-26 21:34:06 +07:00 |
|
Mike Wade
|
f76f80db80
|
Killswitch domain
|
2020-09-16 20:32:31 -06:00 |
|
Mike Wade
|
7b1ef9ea64
|
fixing test runner issues
|
2020-09-15 15:45:33 -06:00 |
|
Mike Wade
|
6ed36b0e41
|
fixed issues with tabs and duplicate tags
|
2020-09-15 08:52:00 -06:00 |
|
Florian Roth
|
2cd9b794e6
|
Merge pull request #1007 from d4rk-d4nph3/master
Windows Defender AMSI Trigger Detected
|
2020-09-15 15:45:00 +02:00 |
|
Florian Roth
|
19ccfb80da
|
Merge pull request #1016 from NVISO-BE/win_vul_cve_2020_1472
Added win_vul_cve_2020_1472 rule
|
2020-09-15 15:43:53 +02:00 |
|
Remco Hofman
|
6cadfa5b2b
|
Added win_vul_cve_2020_1472 rule
|
2020-09-15 15:13:53 +02:00 |
|
Mike Wade
|
1ddba05eb2
|
Second round
|
2020-09-15 07:02:30 -06:00 |
|
Mike Wade
|
da9b32bdd6
|
we
|
2020-09-15 06:24:44 -06:00 |
|
Mike Wade
|
8ce73bd8df
|
Fixed issues with tags and missing files
|
2020-09-15 06:10:57 -06:00 |
|
Thomas Patzke
|
b0ccf44243
|
Added test
|
2020-09-15 12:42:37 +02:00 |
|
Thomas Patzke
|
378d9c94cf
|
Merge branch 'master' of https://github.com/socprime/sigma into pr-981
|
2020-09-15 12:14:49 +02:00 |
|
Thomas Patzke
|
64961c6d42
|
Added test
|
2020-09-15 09:06:02 +02:00 |
|
Thomas Patzke
|
28426f9b7f
|
Merge branch 'Netwitness-EPL' of https://github.com/snake-jump/sigma into pr-1001
|
2020-09-15 08:29:03 +02:00 |
|