2 files changed
+2
-2
lines changed- .github/workflows/supported_modifier.yaml+1-1
- config/target_event_IDs.txt+3-1
- doc/SupportedSigmaFieldModifiers.md+2-2
- hayabusa/builtin/Security/AccountManagement/UserAccountManagement/Sec_4723_Med_AcctPassword_OwnChanged.yml+69
- hayabusa/builtin/Security/AccountManagement/UserAccountManagement/Sec_4724_Med_AcctPassword_OtherChanged.yml+71
- hayabusa/builtin/Security/LogonLogoff/Logon/Sec_4624_Med_Logon-Type9-NewInteractive_SuspProc.yml+1-1
- hayabusa/builtin/System/Sys_7045_High_ServiceInstalled_SuspiciousServiceName.yml+1-1
- sigma/builtin/emerging-threats/2023/Malware/Qakbot/proc_creation_win_malware_qakbot_regsvr32_calc_pattern.yml+1-1
- sigma/builtin/emerging-threats/2024/Exploits/CVE-2024-1708/win_security_exploit_cve_2024_1708_screenconnect.yml+1-1
- sigma/builtin/emerging-threats/2024/Exploits/CVE-2024-1709/win_security_exploit_cve_2024_1709_user_database_modification_screenconnect.yml+1-1
- sigma/builtin/emerging-threats/2024/Exploits/CVE-2024-49113/win_application_error_exploit_cve_2024_49113_ldap_nightmare.yml+36
- sigma/builtin/emerging-threats/2024/Malware/Raspberry-Robin/proc_creation_win_malware_raspberry_robin_rundll32_shell32_cpl_exection.yml+1-1
- sigma/builtin/emerging-threats/2024/TA/Forest-Blizzard/proc_creation_win_apt_forest_blizzard_activity.yml+3-3
- sigma/builtin/powershell/powershell_module/posh_pm_hktl_evil_winrm_execution.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_certutil_encode_susp_extensions.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_certutil_encode_susp_location.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_cmd_ping_copy_combined_execution.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_dctask64_arbitrary_command_and_dll_execution.yml+5-5
- sigma/builtin/process_creation/proc_creation_win_diskshadow_script_mode_susp_ext.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_findstr_download.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_findstr_subfolder_search.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_lodctr_performance_counter_tampering.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_odbcconf_response_file.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_powershell_invoke_webrequest_download.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_remote_access_tools_anydesk_revoked_cert.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_remote_access_tools_screenconnect_remote_execution.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_remote_access_tools_screenconnect_webshell.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_remote_access_tools_simple_help.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_sc_query_interesting_services.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_ssh_port_forward.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_wget_download_susp_locations.yml+1-1
- sigma/builtin/process_creation/proc_creation_win_whoami_all_execution.yml+1-1
- sigma/builtin/registry/registry_set/registry_set_sentinelone_shell_context_tampering.yml+1-1
- sigma/builtin/system/microsoft_windows_certification_authority/win_system_adcs_enrollment_request_denied.yml+1-1
- sigma/builtin/system/microsoft_windows_kerberos_key_distribution_center/win_system_kdcsvc_tgs_no_suitable_encryption_key_found.yml+1-1
- sigma/builtin/threat-hunting/process_creation/proc_creation_win_remote_access_tools_screenconnect_child_proc.yml+1-1
- sigma/builtin/threat-hunting/registry/registry_set/registry_set_shell_context_menu_tampering.yml+1-1
- sigma/sysmon/dns_query/dns_query_win_onelaunch_update_service.yml+1-1
- sigma/sysmon/emerging-threats/2023/Exploits/CVE-2023-36874/file_event_win_exploit_cve_2023_36874_wermgr_creation.yml+2-1
- sigma/sysmon/emerging-threats/2023/Malware/Qakbot/proc_creation_win_malware_qakbot_regsvr32_calc_pattern.yml+1-1
- sigma/sysmon/emerging-threats/2024/Exploits/CVE-2024-1708/file_event_win_exploit_cve_2024_1708_screenconnect.yml+1-1
- sigma/sysmon/emerging-threats/2024/Exploits/CVE-2024-1709/file_event_win_exploit_cve_2024_1709_user_database_modification_screenconnect.yml+1-1
- sigma/sysmon/emerging-threats/2024/Malware/Raspberry-Robin/proc_creation_win_malware_raspberry_robin_rundll32_shell32_cpl_exection.yml+1-1
- sigma/sysmon/emerging-threats/2024/TA/DPRK/dns_query_win_apt_dprk_malicious_domains.yml+1-1
- sigma/sysmon/emerging-threats/2024/TA/Forest-Blizzard/proc_creation_win_apt_forest_blizzard_activity.yml+3-3
- sigma/sysmon/emerging-threats/2024/TA/SlashAndGrab-Exploitation-In-Wild/file_event_win_apt_unknown_exploitation_indicators.yml+1-1
- sigma/sysmon/image_load/image_load_dll_vsstrace_susp_load.yml+6-5
- sigma/sysmon/image_load/image_load_susp_unsigned_dll.yml+1-1
- sigma/sysmon/process_access/proc_access_win_lsass_memdump.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_certutil_encode_susp_extensions.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_certutil_encode_susp_location.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_chcp_codepage_lookup.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_cmd_ping_copy_combined_execution.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_dctask64_arbitrary_command_and_dll_execution.yml+5-5
- sigma/sysmon/process_creation/proc_creation_win_diskshadow_script_mode_susp_ext.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_findstr_download.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_findstr_subfolder_search.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_hktl_dumpert.yml+2-2
- sigma/sysmon/process_creation/proc_creation_win_lodctr_performance_counter_tampering.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_odbcconf_response_file.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_powershell_invoke_webrequest_download.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_remote_access_tools_anydesk_revoked_cert.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_remote_access_tools_screenconnect_remote_execution.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_remote_access_tools_screenconnect_webshell.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_remote_access_tools_simple_help.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_renamed_dctask64.yml+5-5
- sigma/sysmon/process_creation/proc_creation_win_sc_query_interesting_services.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_ssh_port_forward.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_wget_download_susp_locations.yml+1-1
- sigma/sysmon/process_creation/proc_creation_win_whoami_all_execution.yml+1-1
- sigma/sysmon/registry/registry_set/registry_set_sentinelone_shell_context_tampering.yml+1-1
- sigma/sysmon/threat-hunting/process_creation/proc_creation_win_remote_access_tools_screenconnect_child_proc.yml+1-1
- sigma/sysmon/threat-hunting/registry/registry_set/registry_set_shell_context_menu_tampering.yml+1-1
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1882 | 1882 | | |
1883 | 1883 | | |
1884 | 1884 | | |
1885 | | - | |
| 1885 | + | |
1886 | 1886 | | |
1887 | 1887 | | |
1888 | 1888 | | |
| |||
0 commit comments