mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
82f23c5f63
add 13 new rules: - rules/linux/auditd/lnx_auditd_masquerading_crond.yml - rules/linux/auditd/lnx_auditd_user_discovery.yml - rules/linux/auditd/lnx_data_compressed.yml - rules/linux/auditd/lnx_network_sniffing.yml - rules/windows/powershell/powershell_data_compressed.yml - rules/windows/powershell/powershell_winlogon_helper_dll.yml - rules/windows/process_creation/win_change_default_file_association.yml - rules/windows/process_creation/win_data_compressed_with_rar.yml - rules/windows/process_creation/win_local_system_owner_account_discovery.yml - rules/windows/process_creation/win_network_sniffing.yml - rules/windows/process_creation/win_query_registry.yml - rules/windows/process_creation/win_service_execution.yml - rules/windows/process_creation/win_xsl_script_processing.yml modify 1 rule: - rules/windows/process_creation/win_possible_applocker_bypass.yml |
||
---|---|---|
.. | ||
auditd | ||
modsecurity | ||
lnx_buffer_overflows.yml | ||
lnx_clamav.yml | ||
lnx_shell_clear_cmd_history.yml | ||
lnx_shell_priv_esc_prep.yml | ||
lnx_shell_susp_commands.yml | ||
lnx_shell_susp_log_entries.yml | ||
lnx_shell_susp_rev_shells.yml | ||
lnx_shellshock.yml | ||
lnx_ssh_cve_2018_15473.yml | ||
lnx_sudo_cve_2019_14287.yml | ||
lnx_susp_failed_logons_single_source.yml | ||
lnx_susp_jexboss.yml | ||
lnx_susp_named.yml | ||
lnx_susp_ssh.yml | ||
lnx_susp_vsftp.yml |