Sigma Rule Update (2026-05-01 20:43:09)

This commit is contained in:
YamatoSecurity
2026-05-01 20:43:10 +00:00
committed by GitHub
parent 9e732779dd
commit 7fd2342e42
+137 -137
View File
@@ -503,8 +503,8 @@
"T1570",
"TA0002",
"T1569.002",
"T1569",
"T1021"
"T1021",
"T1569"
],
"title": "Metasploit Or Impacket Service Installation Via SMB PsExec"
},
@@ -965,8 +965,8 @@
"T1218.014",
"T1036.002",
"T1036",
"T1204",
"T1218"
"T1218",
"T1204"
],
"title": "MMC Executing Files with Reversed Extensions Using RTLO Abuse"
},
@@ -2566,8 +2566,8 @@
"attack.stealth",
"T1021.002",
"T1218.011",
"T1021",
"T1218"
"T1218",
"T1021"
],
"title": "Rundll32 UNC Path Execution"
},
@@ -3987,8 +3987,8 @@
"attack.stealth",
"T1055.001",
"T1218.013",
"T1055",
"T1218"
"T1218",
"T1055"
],
"title": "Mavinject Inject DLL Into Running Process"
},
@@ -5340,8 +5340,8 @@
"T1133",
"T1136.001",
"T1021.001",
"T1021",
"T1136"
"T1136",
"T1021"
],
"title": "User Added to Remote Desktop Users Group"
},
@@ -5489,8 +5489,8 @@
"T1563.002",
"T1021.001",
"car.2013-07-002",
"T1021",
"T1563"
"T1563",
"T1021"
],
"title": "Suspicious RDP Redirect Using TSCON"
},
@@ -6926,8 +6926,8 @@
"attack.stealth",
"T1204.004",
"T1027.010",
"T1204",
"T1027"
"T1027",
"T1204"
],
"title": "Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix"
},
@@ -8362,8 +8362,8 @@
"T1087.002",
"T1069.002",
"T1482",
"T1087",
"T1069"
"T1069",
"T1087"
],
"title": "Suspicious Active Directory Database Snapshot Via ADExplorer"
},
@@ -8606,9 +8606,9 @@
"T1059.007",
"T1218.005",
"T1027.004",
"T1059",
"T1027",
"T1218",
"T1027"
"T1059"
],
"title": "Csc.EXE Execution Form Potentially Suspicious Parent"
},
@@ -8749,8 +8749,8 @@
"T1218.007",
"TA0002",
"T1059.001",
"T1218",
"T1059",
"T1218",
"T1027"
],
"title": "Obfuscated PowerShell MSI Install via WindowsInstaller COM"
@@ -10141,8 +10141,8 @@
"TA0003",
"T1053.005",
"T1059.001",
"T1059",
"T1053"
"T1053",
"T1059"
],
"title": "Suspicious Schtasks Execution AppData Folder"
},
@@ -10489,8 +10489,8 @@
"TA0011",
"T1071.004",
"T1132.001",
"T1132",
"T1048",
"T1132",
"T1071"
],
"title": "DNS Exfiltration and Tunneling Tools Execution"
@@ -12371,8 +12371,8 @@
"T1587.001",
"TA0002",
"T1569.002",
"T1569",
"T1587"
"T1587",
"T1569"
],
"title": "PUA - CsExec Execution"
},
@@ -12636,8 +12636,8 @@
"T1218.011",
"TA0006",
"T1003.001",
"T1003",
"T1218"
"T1218",
"T1003"
],
"title": "Process Access via TrolleyExpress Exclusion"
},
@@ -13384,8 +13384,8 @@
"TA0002",
"T1552.004",
"T1059.001",
"T1552",
"T1059"
"T1059",
"T1552"
],
"title": "Certificate Exported Via PowerShell"
},
@@ -13524,8 +13524,8 @@
"T1548.002",
"T1546.001",
"T1112",
"T1546",
"T1548"
"T1548",
"T1546"
],
"title": "Registry Modification of MS-settings Protocol Handler"
},
@@ -14091,8 +14091,8 @@
"T1053.005",
"T1036.004",
"T1036.005",
"T1053",
"T1036"
"T1036",
"T1053"
],
"title": "Scheduled Task Creation Masquerading as System Processes"
},
@@ -14413,8 +14413,8 @@
"T1059.001",
"T1059.003",
"T1564.003",
"T1564",
"T1059"
"T1059",
"T1564"
],
"title": "Powershell Executed From Headless ConHost Process"
},
@@ -16412,8 +16412,8 @@
"T1570",
"TA0002",
"T1569.002",
"T1569",
"T1021"
"T1021",
"T1569"
],
"title": "Rundll32 Execution Without Parameters"
},
@@ -16865,9 +16865,9 @@
"T1069.002",
"TA0002",
"T1059.001",
"T1059",
"T1087",
"T1069"
"T1069",
"T1059"
],
"title": "HackTool - Bloodhound/Sharphound Execution"
},
@@ -17577,8 +17577,8 @@
"T1047",
"T1204.002",
"T1218.010",
"T1218",
"T1204"
"T1204",
"T1218"
],
"title": "Suspicious Microsoft Office Child Process"
},
@@ -18244,8 +18244,8 @@
"T1482",
"T1069.002",
"stp.1u",
"T1087",
"T1069"
"T1069",
"T1087"
],
"title": "PUA - AdFind Suspicious Execution"
},
@@ -19462,8 +19462,8 @@
"attack.stealth",
"T1548.002",
"T1218.003",
"T1218",
"T1548"
"T1548",
"T1218"
],
"title": "Bypass UAC via CMSTP"
},
@@ -19641,12 +19641,12 @@
"T1547.002",
"T1557",
"T1082",
"T1547",
"T1556",
"T1574",
"T1505",
"T1546",
"T1564",
"T1546"
"T1505",
"T1556",
"T1547",
"T1574"
],
"title": "Potential Suspicious Activity Using SeCEdit"
},
@@ -20453,8 +20453,8 @@
"attack.stealth",
"T1059.001",
"T1027.005",
"T1059",
"T1027"
"T1027",
"T1059"
],
"title": "HackTool - CrackMapExec PowerShell Obfuscation"
},
@@ -21003,8 +21003,8 @@
"T1558.003",
"TA0008",
"T1550.003",
"T1550",
"T1558"
"T1558",
"T1550"
],
"title": "HackTool - Rubeus Execution"
},
@@ -24717,8 +24717,8 @@
"T1203",
"T1059.003",
"attack.g0032",
"T1566",
"T1059"
"T1059",
"T1566"
],
"title": "Suspicious HWP Sub Processes"
},
@@ -26279,8 +26279,8 @@
"attack.s0412",
"attack.g0001",
"detection.emerging-threats",
"T1218",
"T1059"
"T1059",
"T1218"
],
"title": "ZxShell Malware"
},
@@ -26309,8 +26309,8 @@
"T1053.005",
"T1027",
"detection.emerging-threats",
"T1059",
"T1053"
"T1053",
"T1059"
],
"title": "Turla Group Commands May 2020"
},
@@ -27704,8 +27704,8 @@
"T1059.005",
"T1105",
"detection.emerging-threats",
"T1059",
"T1195"
"T1195",
"T1059"
],
"title": "Axios NPM Compromise Indicators - Windows"
},
@@ -28137,8 +28137,8 @@
"T1059.001",
"attack.s0183",
"detection.emerging-threats",
"T1071",
"T1059"
"T1059",
"T1071"
],
"title": "Kalambur Backdoor Curl TOR SOCKS Proxy Execution"
},
@@ -28573,8 +28573,8 @@
"T1003.001",
"T1560.001",
"detection.emerging-threats",
"T1560",
"T1003"
"T1003",
"T1560"
],
"title": "APT31 Judgement Panda Activity"
},
@@ -28598,8 +28598,8 @@
"T1552.001",
"T1003.003",
"detection.emerging-threats",
"T1552",
"T1003"
"T1003",
"T1552"
],
"title": "Potential Russian APT Credential Theft Activity"
},
@@ -28678,8 +28678,8 @@
"T1059.001",
"detection.emerging-threats",
"T1059",
"T1053",
"T1036"
"T1036",
"T1053"
],
"title": "Operation Wocao Activity"
},
@@ -28710,9 +28710,9 @@
"T1053.005",
"T1059.001",
"detection.emerging-threats",
"T1053",
"T1036",
"T1059",
"T1036"
"T1053"
],
"title": "Operation Wocao Activity - Security"
},
@@ -28739,8 +28739,8 @@
"T1566.001",
"cve.2017-0261",
"detection.emerging-threats",
"T1566",
"T1204"
"T1204",
"T1566"
],
"title": "Exploit for CVE-2017-0261"
},
@@ -28767,8 +28767,8 @@
"T1566.001",
"cve.2017-11882",
"detection.emerging-threats",
"T1566",
"T1204"
"T1204",
"T1566"
],
"title": "Droppers Exploiting CVE-2017-11882"
},
@@ -28822,8 +28822,8 @@
"T1543.003",
"T1569.002",
"detection.emerging-threats",
"T1543",
"T1569"
"T1569",
"T1543"
],
"title": "CosmicDuke Service Installation"
},
@@ -28905,8 +28905,8 @@
"car.2016-04-002",
"detection.emerging-threats",
"T1685",
"T1218",
"T1003"
"T1003",
"T1218"
],
"title": "NotPetya Ransomware Activity"
},
@@ -29328,8 +29328,8 @@
"T1053.005",
"T1059.006",
"detection.emerging-threats",
"T1053",
"T1059"
"T1059",
"T1053"
],
"title": "Serpent Backdoor Payload Execution Via Scheduled Task"
},
@@ -30290,8 +30290,8 @@
"T1071.004",
"detection.emerging-threats",
"T1053",
"T1543",
"T1071"
"T1071",
"T1543"
],
"title": "OilRig APT Activity"
},
@@ -30324,9 +30324,9 @@
"TA0011",
"T1071.004",
"detection.emerging-threats",
"T1053",
"T1543",
"T1071"
"T1071",
"T1053"
],
"title": "OilRig APT Schedule Task Persistence - Security"
},
@@ -30358,8 +30358,8 @@
"TA0011",
"T1071.004",
"detection.emerging-threats",
"T1053",
"T1071",
"T1053",
"T1543"
],
"title": "OilRig APT Registry Persistence"
@@ -30390,9 +30390,9 @@
"TA0011",
"T1071.004",
"detection.emerging-threats",
"T1543",
"T1071",
"T1053"
"T1053",
"T1543"
],
"title": "OilRig APT Schedule Task Persistence - System"
},
@@ -32073,8 +32073,8 @@
"attack.stealth",
"T1204.004",
"T1027.010",
"T1204",
"T1027"
"T1027",
"T1204"
],
"title": "Suspicious Space Characters in RunMRU Registry Path - ClickFix"
},
@@ -33377,8 +33377,8 @@
"TA0003",
"T1548.002",
"T1546.001",
"T1546",
"T1548"
"T1548",
"T1546"
],
"title": "Suspicious Shell Open Command Registry Modification"
},
@@ -34361,9 +34361,9 @@
"T1021.002",
"T1543.003",
"T1569.002",
"T1569",
"T1021",
"T1543",
"T1021"
"T1569"
],
"title": "Potential CobaltStrike Service Installations - Registry"
},
@@ -36869,8 +36869,8 @@
"T1529",
"attack.g0091",
"attack.s0363",
"T1071",
"T1059"
"T1059",
"T1071"
],
"title": "Silence.EDA Detection"
},
@@ -37076,8 +37076,8 @@
"T1558.003",
"TA0008",
"T1550.003",
"T1558",
"T1550"
"T1550",
"T1558"
],
"title": "HackTool - Rubeus Execution - ScriptBlock"
},
@@ -38899,8 +38899,8 @@
"T1059.001",
"TA0003",
"T1136.001",
"T1136",
"T1059"
"T1059",
"T1136"
],
"title": "PowerShell Create Local User"
},
@@ -39367,8 +39367,8 @@
"T1564.004",
"TA0002",
"T1059.001",
"T1564",
"T1059"
"T1059",
"T1564"
],
"title": "NTFS Alternate Data Stream"
},
@@ -39929,8 +39929,8 @@
"attack.stealth",
"T1059.001",
"T1036.003",
"T1059",
"T1036"
"T1036",
"T1059"
],
"title": "Renamed Powershell Under Powershell Channel"
},
@@ -39950,8 +39950,8 @@
"T1059.001",
"TA0008",
"T1021.003",
"T1059",
"T1021"
"T1021",
"T1059"
],
"title": "Suspicious Non PowerShell WSMAN COM Provider"
},
@@ -42979,9 +42979,9 @@
"T1021.002",
"T1543.003",
"T1569.002",
"T1569",
"T1021",
"T1543"
"T1543",
"T1569"
],
"title": "CobaltStrike Service Installations - System"
},
@@ -44968,8 +44968,8 @@
"T1071.004",
"TA0002",
"T1059.003",
"T1071",
"T1059"
"T1059",
"T1071"
],
"title": "Network Connection Initiated via Finger.EXE"
},
@@ -45036,8 +45036,8 @@
"attack.stealth",
"T1559.001",
"T1218.010",
"T1559",
"T1218"
"T1218",
"T1559"
],
"title": "Network Connection Initiated By Regsvr32.EXE"
},
@@ -45607,8 +45607,8 @@
"T1059.001",
"T1027.010",
"detection.threat-hunting",
"T1027",
"T1059"
"T1059",
"T1027"
],
"title": "Invocation Of Crypto-Classes From The \"Cryptography\" PowerShell Namespace"
},
@@ -45935,9 +45935,9 @@
"T1021.002",
"attack.s0039",
"detection.threat-hunting",
"T1069",
"T1087",
"T1021",
"T1069"
"T1021"
],
"title": "Net.EXE Execution"
},
@@ -46511,9 +46511,9 @@
"T1027.010",
"T1547.001",
"detection.threat-hunting",
"T1059",
"T1027",
"T1547"
"T1547",
"T1059"
],
"title": "Registry Set With Crypto-Classes From The \"Cryptography\" PowerShell Namespace"
},
@@ -46713,8 +46713,8 @@
"TA0009",
"T1114.003",
"detection.threat-hunting",
"T1564",
"T1114"
"T1114",
"T1564"
],
"title": "Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet"
},
@@ -47197,8 +47197,8 @@
"T1087.002",
"T1069.002",
"attack.s0039",
"T1087",
"T1069"
"T1069",
"T1087"
],
"title": "Reconnaissance Activity"
},
@@ -47679,8 +47679,8 @@
"TA0002",
"T1543.003",
"T1569.002",
"T1543",
"T1569"
"T1569",
"T1543"
],
"title": "Remote Access Tool Services Have Been Installed - Security"
},
@@ -48599,8 +48599,8 @@
"T1570",
"TA0002",
"T1569.002",
"T1569",
"T1021"
"T1021",
"T1569"
],
"title": "Metasploit Or Impacket Service Installation Via SMB PsExec"
},
@@ -49539,9 +49539,9 @@
"T1021.002",
"T1543.003",
"T1569.002",
"T1543",
"T1021",
"T1569",
"T1021"
"T1543"
],
"title": "CobaltStrike Service Installations - Security"
},
@@ -49967,8 +49967,8 @@
"T1553.002",
"attack.s0195",
"T1070",
"T1553",
"T1027"
"T1027",
"T1553"
],
"title": "Potential Secure Deletion with SDelete"
},
@@ -52366,8 +52366,8 @@
"T1218.010",
"TA0002",
"TA0005",
"T1204",
"T1218"
"T1218",
"T1204"
],
"title": "WMI Execution Via Office Process"
},
@@ -52779,8 +52779,8 @@
"T1218.010",
"TA0002",
"TA0005",
"T1204",
"T1218"
"T1218",
"T1204"
],
"title": "Excel Proxy Executing Regsvr32 With Payload Alternate"
},
@@ -55393,10 +55393,10 @@
"T1570",
"T1021.002",
"T1569.002",
"T1569",
"T1543",
"T1136",
"T1021",
"T1543"
"T1569",
"T1021"
],
"title": "PSExec Lateral Movement"
},