mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
1f1fd68331
add 11 new rules: - rules/linux/auditd/lnx_auditd_web_rce.yml - rules/windows/process_creation/process_creation_susp_bginfo.yml - rules/windows/process_creation/process_creation_susp_cdb.yml - rules/windows/process_creation/process_creation_susp_devtoolslauncher.yml - rules/windows/process_creation/process_creation_susp_dnx.yml - rules/windows/process_creation/process_creation_susp_dxcap.yml - rules/windows/process_creation/process_creation_susp_msoffice.yml - rules/windows/process_creation/process_creation_susp_odbcconf.yml - rules/windows/process_creation/process_creation_susp_openwith.yml - rules/windows/process_creation/process_creation_susp_psr_capture_screenshots.yml - rules/windows/sysmon/sysmon_webshell_creation_detect.yml |
||
---|---|---|
.. | ||
sysmon_ads_executable.yml | ||
sysmon_cactustorch.yml | ||
sysmon_cmstp_execution.yml | ||
sysmon_cobaltstrike_process_injection.yml | ||
sysmon_dhcp_calloutdll.yml | ||
sysmon_dns_serverlevelplugindll.yml | ||
sysmon_ghostpack_safetykatz.yml | ||
sysmon_logon_scripts_userinitmprlogonscript.yml | ||
sysmon_lsass_memdump.yml | ||
sysmon_mal_namedpipes.yml | ||
sysmon_malware_backconnect_ports.yml | ||
sysmon_malware_verclsid_shellcode.yml | ||
sysmon_mimikatz_detection_lsass.yml | ||
sysmon_mimikatz_inmemory_detection.yml | ||
sysmon_mimikatz_trough_winrm.yml | ||
sysmon_password_dumper_lsass.yml | ||
sysmon_powershell_exploit_scripts.yml | ||
sysmon_powershell_network_connection.yml | ||
sysmon_quarkspw_filedump.yml | ||
sysmon_rdp_reverse_tunnel.yml | ||
sysmon_rdp_settings_hijack.yml | ||
sysmon_renamed_powershell.yml | ||
sysmon_renamed_psexec.yml | ||
sysmon_rundll32_net_connections.yml | ||
sysmon_ssp_added_lsa_config.yml | ||
sysmon_stickykey_like_backdoor.yml | ||
sysmon_susp_download_run_key.yml | ||
sysmon_susp_driver_load.yml | ||
sysmon_susp_file_characteristics.yml | ||
sysmon_susp_image_load.yml | ||
sysmon_susp_lsass_dll_load.yml | ||
sysmon_susp_powershell_rundll32.yml | ||
sysmon_susp_prog_location_network_connection.yml | ||
sysmon_susp_rdp.yml | ||
sysmon_susp_reg_persist_explorer_run.yml | ||
sysmon_susp_run_key_img_folder.yml | ||
sysmon_suspicious_keyboard_layout_load.yml | ||
sysmon_sysinternals_eula_accepted.yml | ||
sysmon_tsclient_filewrite_startup.yml | ||
sysmon_uac_bypass_eventvwr.yml | ||
sysmon_uac_bypass_sdclt.yml | ||
sysmon_webshell_creation_detect.yml | ||
sysmon_win_binary_github_com.yml | ||
sysmon_win_binary_susp_com.yml | ||
sysmon_win_reg_persistence.yml | ||
sysmon_wmi_event_subscription.yml | ||
sysmon_wmi_persistence_commandline_event_consumer.yml | ||
sysmon_wmi_persistence_script_event_consumer_write.yml | ||
sysmon_wmi_susp_scripting.yml |