frack113
f6fe5e7d02
fix when backend support error
2021-08-20 13:58:57 +02:00
frack113
9b106dcc7d
Merge pull request #1880 from austinsonger/azure_suppression_rule_created.yml
...
azure_suppression_rule_created.yml
2021-08-20 09:04:48 +02:00
frack113
d58b1e8e40
Merge pull request #1879 from austinsonger/azure_application_gateway_modified_or_deleted.yml
...
azure_application_gateway_modified_or_deleted.yml
2021-08-20 09:03:57 +02:00
frack113
4b08aac47f
Merge pull request #1878 from austinsonger/azure_application_security_group_modified_or_deleted.yml
...
azure_application_security_group_modified_or_deleted.yml
2021-08-20 09:01:39 +02:00
frack113
cf2b0dd1a6
Merge pull request #1886 from austinsonger/m365.yml
...
Add m365.yml
2021-08-20 09:01:16 +02:00
Austin Songer
e6457531dd
Create m365.yml
2021-08-20 00:29:29 -05:00
Austin Songer
ba418eb057
Merge branch 'SigmaHQ:master' into m365.yml
2021-08-20 00:23:31 -05:00
frack113
ec97e12e35
Merge pull request #1881 from austinsonger/@austinsonger
...
Update author.
2021-08-20 06:31:44 +02:00
frack113
f882ebda35
fix status
2021-08-20 06:08:28 +02:00
Austin Songer
0a3e57cc12
Update
2021-08-20 02:10:32 +00:00
Austin Songer
842ade16be
Forgot to add my username to some of the rules.
2021-08-20 02:09:31 +00:00
Austin Songer
9a83836070
Update aws_eks_cluster_created_or_deleted.yml
2021-08-19 21:00:36 -05:00
Austin Songer
6ae62488b3
Merge branch 'SigmaHQ:master' into azure_application_gateway_modified_or_deleted.yml
2021-08-19 20:32:35 -05:00
Austin Songer
d2f87feb7b
Merge branch 'SigmaHQ:master' into azure_application_security_group_modified_or_deleted.yml
2021-08-19 20:31:48 -05:00
frack113
0103b148f7
Merge pull request #1876 from rachelrice/update_cloudtrail_rules
...
Update AWS CloudTrail rules
2021-08-19 18:33:07 +02:00
frack113
39617c9807
Merge pull request #1865 from austinsonger/azure_keyvault_secrets_modified_or_deleted.yml
...
add azure_keyvault_secrets_modified_or_deleted.yml
2021-08-19 17:06:28 +02:00
frack113
600c6233c2
Merge pull request #1874 from gs3cl/patch-1
...
Update win_nltest_query.yml
2021-08-19 16:18:20 +02:00
frack113
78212546a7
Merge pull request #1869 from frack113/redcanary_T1546.013
...
powershell_trigger_profiles T1546.013
2021-08-19 16:17:53 +02:00
Austin Songer
cc51e054e3
Update azure_keyvault_secrets_modified_or_deleted.yml
2021-08-19 09:04:22 -05:00
Rachel Rice
67020bb0ff
Update AWS CloudTrail rules
...
aws_elasticache_security_group_created.yml
aws_elasticache_security_group_modified_or_deleted.yml
Removed spaces from eventNames
aws_s3_data_management_tampering.yml
Fix typo in title, use s3 as eventSource
aws_snapshot_backup_exfiltration.yml
Use ec2 as eventSource
2021-08-19 14:24:43 +01:00
frack113
08af3a9429
Cleanup errors
2021-08-19 15:20:04 +02:00
frack113
60931d09b9
fix title error
2021-08-19 14:24:54 +02:00
frack113
08324a5a56
Merge pull request #1875 from frack113/fix_sigma_similarity
...
sigma_similarity fix start errors
2021-08-19 14:16:52 +02:00
gs3cl
bf9ac21ebc
Update win_nltest_recon.yml
...
change "startswith" to "contains"
2021-08-19 14:12:00 +02:00
frack113
2cdab46ee4
fix start errors
2021-08-19 09:37:00 +02:00
gs3cl
df829f0d45
Update and rename win_nltest_query.yml to win_nltest_recon.yml
...
changes based on feedback added
Update and rename win_nltest_query.yml to win_nltest_recon.yml
2021-08-19 08:26:33 +02:00
Florian Roth
459a0bdca1
Merge pull request #1870 from frack113/fix_fp_Renamed_Powershell
...
Fix some false positives in renamed powershell
2021-08-19 08:23:51 +02:00
frack113
7bca85e406
Merge pull request #1873 from austinsonger/spelling
...
Spelling Fixes
2021-08-19 06:15:45 +02:00
gs3cl
92b72ffdc1
Update win_nltest_query.yml
...
modification based on new reports
1.https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)
-> for (selection_recon1 and seletion_recon2")
2.https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters -> nltest example
3.MITRE reference just for reference to MITRE to gain more insights
4.https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/
-> new Report about Trickbot with reference and usage of "nltest" therefore I included the option in this rule
2021-08-18 20:45:18 +00:00
Austin Songer
5553534d7c
Update README.md
2021-08-18 14:29:02 -05:00
Austin Songer
e039f91272
Spelling
2021-08-18 19:00:57 +00:00
Austin Songer
c9128687ee
Spelling Errors on Rules
2021-08-18 18:58:20 +00:00
Austin Songer
36406d5781
Fixed Spelling
2021-08-18 18:53:28 +00:00
Austin Songer
112a08a54a
Merge branch 'SigmaHQ:master' into master
2021-08-18 13:42:45 -05:00
Florian Roth
39ef3e0df9
Merge pull request #1872 from SigmaHQ/rule-devel
...
fix: FPs with WMIADAP.exe
2021-08-18 19:26:17 +02:00
frack113
c7d697e720
Merge pull request #1864 from austinsonger/azure_key_vault_modified_or_deleted.yml
...
azure_keyvault_modified_or_deleted.yml
2021-08-18 18:30:20 +02:00
frack113
e7132a8498
Merge pull request #1863 from austinsonger/azure_vault_key_modified_or_deleted.yml
...
azure_keyvault_key_modified_or_deleted.yml
2021-08-18 18:28:46 +02:00
frack113
768855e6d6
update modified after FP fix
2021-08-18 18:17:53 +02:00
Florian Roth
44013e25c8
fix: FPs with WMIADAP.exe
2021-08-18 17:26:57 +02:00
frack113
2d05eda1be
fix ContextInfo FP
2021-08-18 15:18:29 +02:00
frack113
48d0846b53
add powershell_trigger_profiles
2021-08-18 14:29:50 +02:00
frack113
6a282ad24a
fix many FP
2021-08-18 13:56:14 +02:00
Florian Roth
efcf1d9019
Merge pull request #1867 from SigmaHQ/rule-devel
...
fix: FPs with [reflection.assembly]::Load
2021-08-18 11:42:47 +02:00
Florian Roth
a2e45353aa
Merge pull request #1825 from frack113/iis_ProxyLogon
...
rule: ProxyLogon web_cve_2021_26858_iis_rce.yml
2021-08-18 09:54:15 +02:00
Florian Roth
66c674e8e8
Merge pull request #1837 from phantinuss/master
...
generalise amsi bypass rule to CobaltStrike BOF injection pattern
2021-08-18 09:53:21 +02:00
Florian Roth
5fa5a412d5
fix: FPs with [reflection.assembly]::Load
2021-08-18 09:49:34 +02:00
frack113
136c53190a
Merge pull request #1860 from frack113/duplicate_uuid
...
Update test_missing_id message
2021-08-17 17:13:00 +02:00
Austin Songer
309e71491b
Update azure_keyvault_key_modified_or_deleted.yml
2021-08-17 08:44:39 -05:00
Austin Songer
23d0477120
Update azure_keyvault_secrets_modified_or_deleted.yml
2021-08-17 08:42:41 -05:00
Austin Songer
16e0def41d
Update and rename azure_vault_key_modified_or_deleted.yml to azure_keyvault_key_modified_or_deleted.yml
2021-08-17 08:31:22 -05:00