SigmaHQ/rules
yugoslavskiy 82f23c5f63
Merge pull request #477 from zinint/oscd
add 13 new rules:

- rules/linux/auditd/lnx_auditd_masquerading_crond.yml 
- rules/linux/auditd/lnx_auditd_user_discovery.yml 
- rules/linux/auditd/lnx_data_compressed.yml 
- rules/linux/auditd/lnx_network_sniffing.yml 
- rules/windows/powershell/powershell_data_compressed.yml 
- rules/windows/powershell/powershell_winlogon_helper_dll.yml 
- rules/windows/process_creation/win_change_default_file_association.yml 
- rules/windows/process_creation/win_data_compressed_with_rar.yml 
- rules/windows/process_creation/win_local_system_owner_account_discovery.yml 
- rules/windows/process_creation/win_network_sniffing.yml 
- rules/windows/process_creation/win_query_registry.yml 
- rules/windows/process_creation/win_service_execution.yml 
- rules/windows/process_creation/win_xsl_script_processing.yml 

modify 1 rule:

- rules/windows/process_creation/win_possible_applocker_bypass.yml
2019-11-05 04:55:29 +03:00
..
application Fixes for Elasticsearch query correctness CI tests 2018-04-09 22:33:29 +02:00
apt Fixed wrong backslash escaping of * 2019-10-07 22:14:44 +02:00
compliance Added level 2019-08-05 19:51:22 +02:00
linux Merge pull request #477 from zinint/oscd 2019-11-05 04:55:29 +03:00
network Merge pull request #315 from P4T12ICK/feature/net_dnc_c2_detection 2019-05-10 00:12:39 +02:00
proxy rule: proxy malware ua - Zebrocy 2019-10-26 14:20:29 +02:00
web Web Source Code Enumeration via .git 2019-06-08 22:40:28 -04:00
windows Merge pull request #477 from zinint/oscd 2019-11-05 04:55:29 +03:00