Florian Roth
|
f88225dd2a
|
Merge pull request #640 from Neo23x0/devel
fix: broader exclusion for rule - OneDrive false positives
|
2020-02-26 18:41:52 +01:00 |
|
Florian Roth
|
6bbd80a8ee
|
fix: broader exclusion for rule - OneDrive false positives
|
2020-02-26 18:31:58 +01:00 |
|
Florian Roth
|
ada0edb822
|
Merge pull request #621 from wagga40/new_koadic_rule
New Koadic detection rule
|
2020-02-26 13:25:03 +01:00 |
|
Florian Roth
|
0ba6874645
|
Merge pull request #638 from Neo23x0/devel
Several false positives with new rules
|
2020-02-26 09:46:02 +01:00 |
|
Florian Roth
|
1c90d6badd
|
level increased
|
2020-02-26 09:42:31 +01:00 |
|
Florian Roth
|
c8afd4a16b
|
Merge pull request #637 from tjgeorgen/patch-1
fix missing status & description in status field
|
2020-02-26 09:40:55 +01:00 |
|
Florian Roth
|
031e6d3ee6
|
Merge pull request #635 from EccoTheFlintstone/fix_fp4
wmiprvse subprocess: add fallback check on username instead of only l…
|
2020-02-26 09:40:34 +01:00 |
|
Florian Roth
|
4f3e3166d3
|
fixing false positives
|
2020-02-26 09:33:55 +01:00 |
|
Florian Roth
|
82d2b1e6f0
|
Merge branch 'master' into devel
# Conflicts:
# rules/windows/process_creation/win_susp_squirrel_lolbin.yml
|
2020-02-26 09:27:48 +01:00 |
|
Florian Roth
|
e7aff17e72
|
FP: OneDrive setup
|
2020-02-26 09:26:19 +01:00 |
|
Tom Georgen
|
74f3fe70cc
|
fix missing status & description in status field
|
2020-02-25 16:30:41 -05:00 |
|
Thomas Patzke
|
65444f7a77
|
Release 0.16.0
|
2020-02-25 22:19:52 +01:00 |
|
Thomas Patzke
|
4e42bebb34
|
Merge branch 'socprime-master'
|
2020-02-25 21:32:59 +01:00 |
|
Florian Roth
|
a152853ac3
|
Merge pull request #624 from Antonlovesdnb/master
New rules for Macro Detections
|
2020-02-25 15:44:31 +01:00 |
|
Antonlovesdnb
|
e8b861bff4
|
Update sysmon_susp_winword_vbadll_load.yml
|
2020-02-25 09:24:29 -05:00 |
|
Antonlovesdnb
|
4c5d489428
|
Update sysmon_susp_office_kerberos_dll_load.yml
|
2020-02-25 09:23:52 -05:00 |
|
Antonlovesdnb
|
f92e2f2b18
|
Update sysmon_susp_office_dotnet_assembly_dll_load.yml
|
2020-02-25 09:23:22 -05:00 |
|
Antonlovesdnb
|
8141b1ae90
|
Update sysmon_susp_office_dsparse_dll_load.yml
|
2020-02-25 09:22:56 -05:00 |
|
Antonlovesdnb
|
45e4a585bf
|
Update sysmon_susp_office_dotnet_gac_dll_load.yml
|
2020-02-25 09:22:37 -05:00 |
|
Antonlovesdnb
|
c5b42aeaed
|
Update sysmon_susp_office_dotnet_clr_dll_load.yml
|
2020-02-25 09:19:03 -05:00 |
|
Antonlovesdnb
|
bb1eecfe14
|
Update sysmon_susp_office_dotnet_assembly_dll_load.yml
|
2020-02-25 09:17:33 -05:00 |
|
Florian Roth
|
dd1a0e764c
|
docs: more false positive conditions
|
2020-02-25 11:13:58 +01:00 |
|
Florian Roth
|
950fa18418
|
fix: changed titles to avoid duplicates
|
2020-02-25 11:12:47 +01:00 |
|
Florian Roth
|
5d96f81a84
|
fix: lowered level due to false positives
|
2020-02-25 11:12:11 +01:00 |
|
Florian Roth
|
8f7ee21d5c
|
docs: detection rule license
|
2020-02-25 11:09:10 +01:00 |
|
Thomas Patzke
|
5a2ccbd040
|
Fixed ArcSight backend visibility
|
2020-02-24 23:27:22 +01:00 |
|
Thomas Patzke
|
6236429f3d
|
Added/changed CI tests
|
2020-02-24 23:21:11 +01:00 |
|
Thomas Patzke
|
5b42135935
|
Added es-rule backend to all ES configurations
|
2020-02-24 23:20:48 +01:00 |
|
Thomas Patzke
|
d9b48ea747
|
Fixes in es-rule backend
|
2020-02-24 23:20:19 +01:00 |
|
Thomas Patzke
|
4ee2c2762e
|
Sorting of backend and configuration lists
|
2020-02-24 22:59:59 +01:00 |
|
Thomas Patzke
|
4ac6ddc8ef
|
Merge branch 'changelog'
|
2020-02-24 22:35:41 +01:00 |
|
Thomas Patzke
|
fa717233a9
|
Updated changelog
|
2020-02-24 22:30:36 +01:00 |
|
vh
|
5dc30bd388
|
Carbonblack, Arcsight ESM, Elastic Rule
|
2020-02-24 19:29:45 +02:00 |
|
vh
|
516e61fdb0
|
t
|
2020-02-24 19:23:11 +02:00 |
|
ecco
|
3247d5692a
|
wmiprvse subprocess: add fallback check on username instead of only logonid
|
2020-02-24 09:25:20 -05:00 |
|
Florian Roth
|
91d1586b97
|
Merge pull request #633 from EccoTheFlintstone/fix_fp
rule local account discovery: fix FP on rmdir matching dir
|
2020-02-24 13:41:39 +01:00 |
|
ecco
|
aa1eff5419
|
fix FP on rmdir matching dir
|
2020-02-24 05:23:23 -05:00 |
|
Florian Roth
|
bfab143c7c
|
Merge pull request #632 from EccoTheFlintstone/fp_fix
fix false positive on taskkill.exe not related to service stop at all
|
2020-02-24 09:58:33 +01:00 |
|
Florian Roth
|
53ca71e7ae
|
Merge pull request #631 from EccoTheFlintstone/ascii_fix
fix non ascii character in rule (probably a typo)
|
2020-02-24 09:58:13 +01:00 |
|
ecco
|
f807dae69a
|
fix false positive on taskkill.exe not related to service stop at all
|
2020-02-24 03:03:46 -05:00 |
|
ecco
|
1703b725d3
|
fix non ascii character in rule
|
2020-02-24 02:58:34 -05:00 |
|
Thomas Patzke
|
12be884aa5
|
Merge branch 'sql-backend'
|
2020-02-21 22:41:53 +01:00 |
|
Thomas Patzke
|
776b58b594
|
Improved Splunk Zeek configuration
|
2020-02-21 22:31:14 +01:00 |
|
Thomas Patzke
|
fa4c76871f
|
Added CI test for sql backend
|
2020-02-21 22:27:55 +01:00 |
|
Thomas Patzke
|
746f957a63
|
Merge branch 'patch-1' of https://github.com/fuseyjz/sigma into fuseyjz-patch-1
|
2020-02-21 22:24:44 +01:00 |
|
Thomas Patzke
|
3047571132
|
Merge pull request #625 from ninoseki/fix-sigma2misp
Update sigma2misp
|
2020-02-21 22:22:54 +01:00 |
|
Florian Roth
|
ab1dda7685
|
fix: non-ascii rule
|
2020-02-21 16:21:39 +01:00 |
|
Thomas Patzke
|
61d31c3f3a
|
Fixed tagging
|
2020-02-20 23:51:12 +01:00 |
|
Thomas Patzke
|
48d95f027c
|
Merge branch 'oscd'
|
2020-02-20 23:11:57 +01:00 |
|
Thomas Patzke
|
373424f145
|
Rule fixes
Made tests pass the new CI tests. Added further allowed lower case words
in rule test.
|
2020-02-20 23:00:16 +01:00 |
|