Commit Graph

15 Commits

Author SHA1 Message Date
sn0w0tter
0f871c7d72 rules with subtechniques 2020-09-23 00:53:06 +02:00
sn0w0tter
82846bdf0d #192 for markdown, added powershell to default targets 2020-05-15 03:15:48 +02:00
Yugoslavskiy Daniil
4d79a25830 fix #173 2020-04-05 08:17:52 +02:00
Yugoslavskiy Daniil
f101bb07fd update confluence and md kb 2020-03-23 04:13:43 +01:00
yugoslavskiy
6aab9a3e07 fix #159 2020-02-17 00:22:47 +03:00
Yugoslavskiy Daniil
3dae842b40 update DN md template, fix #153 2020-01-14 10:12:24 +03:00
Wydra Mateusz
872d9f44c3 shootgin the foot for confluence, analytics regenerated 2019-09-13 11:35:20 +02:00
yugoslavskiy
9994762d2a all analytics have been rebuilt 2019-08-11 16:39:37 +03:00
yugoslavskiy
68d4929a53 general update:
- DN calc function updated, fixed incorrect calc for multiple DRs
- updated all LPs with a preparation for a new feature (sucess/fail LP config calculcation per DR/EID)
- all the stuff (md/confluence) has been updated according to changes

updated with a log source sample:

- DN_0046_1031_dhcp_service_callout_dll_file_has_caused_an_exception.yml
- DN_0047_1032_dhcp_service_callout_dll_file_has_caused_an_exception.yml
- DN_0049_1034_dhcp_service_failed_to_load_callout_dlls.yml

created:

- DN_0086_4720_user_account_was_created.yml
- DN_0087_5156_windows_filtering_platform_has_permitted_connection.yml
- DN_0088_4616_system_time_was_changed.yml
- DN_0089_56_terminal_server_security_layer_detected_an_error.yml
- DN_0090_50_terminal_server_security_layer_detected_an_error.yml
- LP_0045_windows_audit_filtering_platform_connection.yml
- LP_0046_windows_audit_security_state_change.yml
2019-07-12 06:38:49 +03:00
yugoslavskiy
f278b6e4a0 - updated sysmon eid 1, 7, 17 and 18 (new fields)
- updated dn calculation to take enrichments to account
- updated dr class and template for both md and confluence to print enrichments (finally sigma has a rule with a link to our enrichment, I've submitted PR it a month ago)
- updated dr temlates for both md and confluence to be more verbose — if there is no info, we put some info messsage, not just empty field
2019-07-09 10:11:01 +03:00
yugoslavskiy
b15925d3a0 sysmon event id 22 (dns queries) added 2019-06-24 04:37:21 +02:00
Wydra Mateusz
d99f01b773 get rid of dot workaround for markdown, missing analitics added 2019-05-01 23:43:17 +02:00
Wydra Mateusz
80e29c836b refresh of analytics 2019-04-29 23:10:03 +02:00
Wydra Mateusz
86f88f6bb9 decrease verbosity 2019-04-01 21:15:31 +02:00
Wydra Mateusz
f4006e03bc Makefile updated, yamls2csv changed to work with customer entities, md files and analytics regenerated 2019-03-27 02:22:01 +01:00