File tree
6 files changed
+43
-35
lines changed- src/detections
6 files changed
+43
-35
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
11 | 15 | | |
12 | 16 | | |
13 | 17 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
11 | 15 | | |
12 | 16 | | |
13 | 17 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
41 | | - | |
| 41 | + | |
42 | 42 | | |
43 | | - | |
| 43 | + | |
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
55 | | - | |
56 | | - | |
| 55 | + | |
| 56 | + | |
57 | 57 | | |
58 | | - | |
| 58 | + | |
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
| |||
- doc/SupportedSigmaFieldModifiers.md+5-5
- sigma/builtin/deprecated/proc_creation_win_bitsadmin_download_uncommon_targetfolder.yml+2-2
- sigma/builtin/process_creation/proc_creation_win_amsi_registry_tampering.yml+61
- sigma/builtin/process_creation/proc_creation_win_bitsadmin_download.yml+8
- sigma/builtin/process_creation/proc_creation_win_bitsadmin_download_direct_ip.yml+1
- sigma/builtin/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains.yml+10-1
- sigma/builtin/process_creation/proc_creation_win_bitsadmin_download_susp_extensions.yml+8
- sigma/builtin/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder.yml+26-2
- sigma/builtin/process_creation/proc_creation_win_credential_guard_registry_tampering.yml+68
- sigma/builtin/process_creation/proc_creation_win_reg_direct_asep_registry_keys_modification.yml+1-2
- sigma/builtin/process_creation/proc_creation_win_user_shell_folders_registry_modification.yml+61
- sigma/builtin/registry/registry_set/registry_set_amsi_disable.yml+43
- sigma/builtin/registry/registry_set/registry_set_credential_guard_disabled.yml+37
- sigma/builtin/registry/registry_set/registry_set_susp_user_shell_folders.yml+37-6
- sigma/sysmon/deprecated/proc_creation_win_bitsadmin_download_uncommon_targetfolder.yml+2-2
- sigma/sysmon/file/file_change/file_change_win_2022_timestomping.yml-51
- sigma/sysmon/file/file_event/file_event_win_susp_legitimate_app_dropping_in_uncommon_location.yml+78
- sigma/sysmon/process_creation/proc_creation_win_amsi_registry_tampering.yml+62
- sigma/sysmon/process_creation/proc_creation_win_bitsadmin_download.yml+8
- sigma/sysmon/process_creation/proc_creation_win_bitsadmin_download_direct_ip.yml+1
- sigma/sysmon/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains.yml+10-1
- sigma/sysmon/process_creation/proc_creation_win_bitsadmin_download_susp_extensions.yml+8
- sigma/sysmon/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder.yml+26-2
- sigma/sysmon/process_creation/proc_creation_win_credential_guard_registry_tampering.yml+69
- sigma/sysmon/process_creation/proc_creation_win_reg_direct_asep_registry_keys_modification.yml+1-2
- sigma/sysmon/process_creation/proc_creation_win_user_shell_folders_registry_modification.yml+62
- sigma/sysmon/registry/registry_delete/registry_delete_disable_credential_guard.yml+39
- sigma/sysmon/registry/registry_set/registry_set_amsi_disable.yml+44
- sigma/sysmon/registry/registry_set/registry_set_credential_guard_disabled.yml+38
- sigma/sysmon/registry/registry_set/registry_set_susp_user_shell_folders.yml+37-7
- sigma/sysmon/threat-hunting/file/file_change/file_change_win_date_changed_to_another_year.yml+68
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
956 | 956 | | |
957 | 957 | | |
958 | 958 | | |
959 | | - | |
| 959 | + | |
960 | 960 | | |
961 | 961 | | |
962 | 962 | | |
| |||
966 | 966 | | |
967 | 967 | | |
968 | 968 | | |
969 | | - | |
| 969 | + | |
970 | 970 | | |
971 | 971 | | |
972 | 972 | | |
| |||
976 | 976 | | |
977 | 977 | | |
978 | 978 | | |
979 | | - | |
| 979 | + | |
980 | 980 | | |
981 | 981 | | |
982 | 982 | | |
| |||
986 | 986 | | |
987 | 987 | | |
988 | 988 | | |
989 | | - | |
| 989 | + | |
990 | 990 | | |
991 | 991 | | |
992 | 992 | | |
| |||
996 | 996 | | |
997 | 997 | | |
998 | 998 | | |
999 | | - | |
| 999 | + | |
1000 | 1000 | | |
1001 | 1001 | | |
1002 | 1002 | | |
| |||
1006 | 1006 | | |
1007 | 1007 | | |
1008 | 1008 | | |
1009 | | - | |
| 1009 | + | |
1010 | 1010 | | |
1011 | 1011 | | |
1012 | 1012 | | |
| |||
1016 | 1016 | | |
1017 | 1017 | | |
1018 | 1018 | | |
1019 | | - | |
| 1019 | + | |
1020 | 1020 | | |
1021 | 1021 | | |
1022 | 1022 | | |
| |||
1026 | 1026 | | |
1027 | 1027 | | |
1028 | 1028 | | |
1029 | | - | |
| 1029 | + | |
1030 | 1030 | | |
1031 | 1031 | | |
1032 | 1032 | | |
| |||
1036 | 1036 | | |
1037 | 1037 | | |
1038 | 1038 | | |
1039 | | - | |
| 1039 | + | |
1040 | 1040 | | |
1041 | 1041 | | |
1042 | 1042 | | |
| |||
1046 | 1046 | | |
1047 | 1047 | | |
1048 | 1048 | | |
1049 | | - | |
| 1049 | + | |
1050 | 1050 | | |
1051 | 1051 | | |
1052 | 1052 | | |
| |||
1056 | 1056 | | |
1057 | 1057 | | |
1058 | 1058 | | |
1059 | | - | |
| 1059 | + | |
1060 | 1060 | | |
1061 | 1061 | | |
1062 | 1062 | | |
| |||
1066 | 1066 | | |
1067 | 1067 | | |
1068 | 1068 | | |
1069 | | - | |
| 1069 | + | |
1070 | 1070 | | |
1071 | 1071 | | |
1072 | 1072 | | |
| |||
1084 | 1084 | | |
1085 | 1085 | | |
1086 | 1086 | | |
1087 | | - | |
| 1087 | + | |
1088 | 1088 | | |
1089 | 1089 | | |
1090 | 1090 | | |
| |||
1094 | 1094 | | |
1095 | 1095 | | |
1096 | 1096 | | |
1097 | | - | |
| 1097 | + | |
1098 | 1098 | | |
1099 | 1099 | | |
1100 | 1100 | | |
| |||
2029 | 2029 | | |
2030 | 2030 | | |
2031 | 2031 | | |
2032 | | - | |
| 2032 | + | |
2033 | 2033 | | |
2034 | 2034 | | |
2035 | 2035 | | |
| |||
0 commit comments