Anton Kutepov
|
3f45269296
|
Merge branch 'oscd'
B
B
B
B
A
|
2021-03-02 22:58:41 +03:00 |
|
yugoslavskiy
|
6494103839
|
Update win_susp_powershell_enc_cmd.yml
|
2020-12-01 01:54:51 +01:00 |
|
yugoslavskiy
|
d1b625d080
|
Update win_susp_powershell_enc_cmd.yml
|
2020-12-01 01:51:47 +01:00 |
|
yugoslavskiy
|
3cbc2f0aec
|
Update win_susp_powershell_enc_cmd.yml
|
2020-12-01 01:47:23 +01:00 |
|
Yugoslavskiy Daniil
|
50623544a2
|
remove possible duplicate filter
|
2020-11-29 22:03:19 +01:00 |
|
yugoslavskiy
|
c01c05b826
|
Update win_susp_powershell_enc_cmd.yml
|
2020-11-28 17:29:15 +01:00 |
|
Jonhnathan
|
c9461506f2
|
Update win_susp_powershell_enc_cmd.yml
|
2020-11-28 13:06:10 -03:00 |
|
Jonhnathan
|
2364e9870d
|
Update win_susp_powershell_enc_cmd.yml
|
2020-11-28 13:05:47 -03:00 |
|
Jonhnathan
|
f4f8174199
|
Update win_susp_powershell_enc_cmd.yml
|
2020-11-28 13:04:36 -03:00 |
|
Florian Roth
|
75637324e0
|
feat: cover newest emotet campaigns
|
2020-10-23 23:44:48 +02:00 |
|
Florian Roth
|
198b292c26
|
rule: emotet encoded commands
|
2020-10-20 12:51:58 +02:00 |
|
Jonhnathan
|
7df7d7f48b
|
Update win_susp_powershell_enc_cmd.yml
|
2020-10-15 19:39:11 -03:00 |
|
Jonhnathan
|
610ae5ddd7
|
Update win_susp_powershell_enc_cmd.yml
|
2020-10-15 19:38:47 -03:00 |
|
grikos
|
293662810e
|
att&ck tags review: windows/process_creation part 8
|
2020-08-28 17:14:26 +03:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
Florian Roth
|
ab038d1ac7
|
style: minor changes
|
2019-12-20 14:59:26 +01:00 |
|
Florian Roth
|
bbaa9df217
|
rule: better JAB rule
|
2019-12-16 19:08:51 +01:00 |
|
Florian Roth
|
f83eb2268e
|
rule: improved JAB expression
|
2019-12-16 19:04:05 +01:00 |
|
Florian Roth
|
bd7c996588
|
rule: suspicious PS rule modified to cover newest malware campaigns
|
2019-12-16 19:02:57 +01:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Florian Roth
|
7bef822da7
|
rule: minor improvement to susp ps enc cmd
|
2019-09-04 16:31:49 +02:00 |
|
Florian Roth
|
0657f29c99
|
Rule: reworked win_susp_powershell_enc_cmd
|
2019-07-30 14:36:30 +02:00 |
|
Florian Roth
|
03d8184990
|
Rule: Extended PowerShell Susp Cmdline Enc Commands
|
2019-04-20 09:38:41 +02:00 |
|
Karneades
|
75d36165fc
|
Remove non-generic falsepositives
There are tons of FPs for that... :)
|
2019-04-11 12:55:24 +02:00 |
|
Karneades
|
51e65be98b
|
Remove loose wildcard filter in powershell encoded cmd rule
|
2019-04-11 12:53:12 +02:00 |
|
mikhail
|
40241c1fdf
|
Fix 4 rules
|
2019-03-06 01:56:05 +03:00 |
|
Thomas Patzke
|
7602309138
|
Increased indentation to 4
* Converted (to generic sigma) rules
* Converter outputs by default with indentation 4
|
2019-03-02 00:14:20 +01:00 |
|
Thomas Patzke
|
c922f7d73f
|
Merge branch 'master' into project-1
|
2019-02-26 00:24:46 +01:00 |
|
Thomas Patzke
|
96eb460944
|
Converted Sysmon/1 and Security/4688 to generic process creation rules
|
2019-01-16 23:36:31 +01:00 |
|