-
Notifications
You must be signed in to change notification settings - Fork 425
Fix Issues & Updates #3705
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
nasbench
wants to merge
19
commits into
develop
Choose a base branch
from
fix-issues-nn
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Fix Issues & Updates #3705
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR fixes the following issues
message
field reference for linux_service_started_or_enabled #3714It also updates/adds these rules
Deprecate
Detect Rundll32 Application Control Bypass - advpack
,Detect Rundll32 Application Control Bypass - setupapi
andDetect Rundll32 Application Control Bypass - syssetup
in favor of a unified ruleWindows Application Whitelisting Bypass Attempt via Rundll32
since they are all related. - cc @MHaggisDeprecate
Windows Change Default File Association For No File Ext
and replace it byWindows Change File Association Command To Notepad
. The reason is that the original rule was incorrectly looking file without extensions, but in reality the TTP is a TA after encrypting files with a certain extensions (in this case.enc
they add a handler for that extensions to open all files with notepad and the ransom note). cc @t-contrerasUpdates
Add or Set Windows Defender Exclusion
with additional flags, namelyControlledFolderAccessAllowedApplications
andAttackSurfaceReductionOnlyExclusions
Reduce the
Attempt To Add Certificate To Untrusted Store
analytic to anAnomaly
because this is found to be common by some installers.Fix the regex in
Common Ransomware Extensions
to account for double extension files.Updated
Linux Java Spawning Shell
andWindows Java Spawning Shells
by removingapache
andw3wp.exe
respectively as they are unrelated to those rules. I did createWeb or Application Server Spawning a Shell
as a generic rule covering both linux and windows instances with a lot more web server and app server names.Updated
USN Journal Deletion
in order to filter for the deletion keyword at the search level not after the results for better performance.Updated
Windows Archived Collected Data In TEMP Folder
to used specific folders instead of just\\temp\\
to avoid accidental FPs. As well as reducing it to an Anomaly rule since I found multiple cases where a match was found.Updated
Windows AutoIt3 Execution
- Added an OFN field and removed the overlap of the string.Updated
Windows Certutil Root Certificate Addition
by focusing on specific paths in order to avoid FPs. Since installers were found doing this as per elastic rule and VT results.Added the
--output-dir
flag to the ruleWindows Curl Download to Suspicious Path
Updated
Windows Information Discovery Fsutil
with additional flags, namely thevolume
sub-command that allows the discovery of disk information and was used by a TA before.Added
pwsh.exe
as a possible value toWindows Remote Management Execute Shell
Enhanced
Windows Renamed Powershell Execution
by adding OFN fields,powershell_ise.exe
and split the logic to be more accurate.Split the string logic in
Windows Rundll32 Apply User Settings Changes
to be more generic and avoid easy bypass using spaces.Updated
Windows Scheduled Task Created Via XML
with additional flags and OFN field as well as updated the different metadata sections.Added new analytic
Windows Symlink Evaluation Change via Fsutil