Commit Graph

46 Commits

Author SHA1 Message Date
Michael Haag 2057e0ab23 Update malicious_powershell_process___encoded_command.yml
Fixed for #2982
2024-07-26 10:45:25 -06:00
Patrick 87108a5aac Improved data sources 2024-07-17 14:41:50 +02:00
Patrick 9e0d8426c1 improved data source field 2024-07-16 14:06:31 +02:00
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel b0eaed8f75 ESCU Release v4.31.0 2024-05-08 16:05:40 +00:00
Gowthamaraj rajendran e06cfa133d Edit how_to_implement for Endpoint.Processes 2023-09-15 10:58:38 -07:00
tccontre aad413f44c volt_typhoon 2023-05-25 12:16:00 +02:00
tccontre 5311028ec7 Update malicious_powershell_process___encoded_command.yml 2023-04-14 10:42:16 +02:00
tccontre 52391f5615 Merge branch 'develop' into sandworm_data_destruction 2023-04-13 19:07:10 +02:00
tccontre e0b697ab6e sandworm_data_destruction 2023-04-12 12:17:43 +02:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
Michael Haag c6db7b5415 CISA AA22-320A 2022-11-16 12:10:42 -07:00
tccontre c96c6d03d3 qakbot_1 2022-10-18 11:57:58 +02:00
tccontre 2dd87d6d33 dcrat-analytics 2022-07-26 12:02:35 +02:00
Rod Soto 8298acf18e powershelldetectionstaghermetic 2022-03-31 15:29:51 -07:00
P4T12ICK e6c8254ede Added automaticc generation of finding report 2022-03-14 12:12:48 +01:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 5fbff3630e merged with develop 2022-02-07 14:55:34 +01:00
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
Michael Haag 9793232a8a Added whispergate story 2022-01-24 11:27:35 -07:00
mhaag-spl bbea800499 whisper1 2022-01-18 19:36:58 -07:00
research bot a1afa0fa60 updating docs and package bits [ci skip] 2021-10-28 19:55:37 +00:00
mhaag-spl eb39fe5937 Updated PowerShell and Exchange Web Shell 2021-10-05 09:50:13 -06:00
mhaag-spl 8ad7757739 Update malicious_powershell_process___encoded_command.yml 2021-09-22 14:45:46 -06:00
P4T12ICK 5e6e987fb7 resolved merge conflicts 2021-07-21 09:22:09 +02:00
research bot 44ea56053d updating docs and package bits [ci skip] 2021-07-20 21:12:30 +00:00
mvelazco 589d3f92ed fixing extra space 2021-07-20 13:53:50 -04:00
P4T12ICK 4ddd09fd87 add analytic types to detections 2021-07-19 17:12:54 +02:00
mvelazco 31496ca1b5 fixing variables on message 2021-07-14 14:40:09 -04:00
mvelazco 8a7629740c RBA support take 4 2021-07-13 14:28:33 -04:00
P4T12ICK 6e826b4e68 add required fields and check 2021-03-11 09:11:48 +01:00
P4T12ICK 7c134dbb5d WIP 2021-03-10 14:44:44 +01:00
mhaag-spl 51823d81d3 Sunburst malware renamed NOBELIUM Group
Renaming Sunburst Malware to NOBELIUM Group
2021-03-05 10:30:34 -07:00
divious1 b58843ca9f added datamodels as an array 2021-02-10 22:35:58 -05:00
divious1 d0c9c92857 added datamodel field and made all objects also pretty via new tool called pretty_yaml.py 2021-02-10 22:11:24 -05:00
divious1 1ec15cf044 renamed on all detections 2021-02-08 10:18:16 -05:00
divious1 b68e05685e modified type for detections 2021-02-05 14:35:49 -05:00
divious1 e14fade976 adding product tag to all detections 2021-02-03 21:42:46 -05:00
bpatel 7fa41599d5 adding sunburst as tags for relavant detections 2020-12-14 20:29:04 -08:00
P4T12ICK b36ca748cd updated url links for dataset 2020-12-03 15:03:50 +01:00
root 6859627fdc Added detection testing service results inMalicious PowerShell Process - Encoded Command 2020-11-04 13:58:12 +00:00
divious1 443d86c864 moved detections to their respective folders 2020-10-07 10:31:25 -04:00