Skip to content

Commit

Permalink
Rules Update
Browse files Browse the repository at this point in the history
  • Loading branch information
wagga40 committed Jul 12, 2024
1 parent d7b9c79 commit 8a3878d
Show file tree
Hide file tree
Showing 11 changed files with 903 additions and 295 deletions.
25 changes: 22 additions & 3 deletions rules_windows_generic.json

Large diffs are not rendered by default.

189 changes: 142 additions & 47 deletions rules_windows_generic_full.json

Large diffs are not rendered by default.

25 changes: 22 additions & 3 deletions rules_windows_generic_high.json

Large diffs are not rendered by default.

170 changes: 123 additions & 47 deletions rules_windows_generic_medium.json

Large diffs are not rendered by default.

189 changes: 142 additions & 47 deletions rules_windows_generic_pysigma.json

Large diffs are not rendered by default.

25 changes: 22 additions & 3 deletions rules_windows_sysmon.json

Large diffs are not rendered by default.

189 changes: 142 additions & 47 deletions rules_windows_sysmon_full.json

Large diffs are not rendered by default.

25 changes: 22 additions & 3 deletions rules_windows_sysmon_high.json

Large diffs are not rendered by default.

170 changes: 123 additions & 47 deletions rules_windows_sysmon_medium.json

Large diffs are not rendered by default.

189 changes: 142 additions & 47 deletions rules_windows_sysmon_pysigma.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion sigma
Submodule sigma updated 25 files
+1 −1 .github/workflows/sigma-test.yml
+2 −2 rules-emerging-threats/2024/Malware/kapeka/registry_set_malware_kapeka_backdoor_autorun_persistence.yml
+39 −0 rules/application/kubernetes/audit/kubernetes_audit_change_admission_controller.yml
+39 −0 rules/application/kubernetes/audit/kubernetes_audit_cronjob_modification.yml
+35 −0 rules/application/kubernetes/audit/kubernetes_audit_rolebinding_modification.yml
+32 −0 rules/application/kubernetes/audit/kubernetes_audit_secrets_modified_or_deleted.yml
+25 −0 rules/application/kubernetes/audit/kubernetes_audit_unauthorized_unauthenticated_actions.yml
+31 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_imds_malicious_usage.yml
+23 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_new_acl_entries.yml
+24 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_new_route_added.yml
+30 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_security_group_change_ingress_egress.yml
+27 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_security_group_change_loadbalancer.yml
+28 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_security_group_change_rds.yml
+26 −0 rules/cloud/aws/cloudtrail/aws_cloudtrail_ssm_malicious_usage.yml
+9 −2 rules/windows/builtin/security/win_security_susp_dsrm_password_change.yml
+0 −0 rules/windows/image_load/image_load_side_load_dbgcore.yml
+1 −1 rules/windows/image_load/image_load_side_load_dbghelp.yml
+32 −0 rules/windows/image_load/image_load_side_load_dbgmodel.yml
+121 −112 rules/windows/image_load/image_load_side_load_from_non_system_location.yml
+26 −0 rules/windows/image_load/image_load_side_load_mpsvc.yml
+26 −0 rules/windows/image_load/image_load_side_load_mscorsvc.yml
+28 −0 rules/windows/process_creation/proc_creation_win_bitlockertogo_execution.yml
+3 −3 rules/windows/process_creation/proc_creation_win_node_abuse.yml
+34 −0 rules/windows/registry/registry_set/registry_set_dsrm_tampering.yml
+2 −2 tests/sigma_cli_conf.yml

0 comments on commit 8a3878d

Please sign in to comment.