Feature/addruletype to sigma rule#230 (#235)
* added ruletype to SIGMA rule #230 * added ruletype to SIGMA rule converter tool #231
This commit is contained in:
@@ -37,3 +37,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.discovery
|
- attack.discovery
|
||||||
- attack.t1012
|
- attack.t1012
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -39,3 +39,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.discovery
|
- attack.discovery
|
||||||
- attack.t1012
|
- attack.t1012
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1098
|
- attack.t1098
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -41,3 +41,4 @@ tags:
|
|||||||
- attack.discovery
|
- attack.discovery
|
||||||
- attack.t1087
|
- attack.t1087
|
||||||
- attack.t1087.002
|
- attack.t1087.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ tags:
|
|||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1222
|
- attack.t1222
|
||||||
- attack.t1222.001
|
- attack.t1222.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -39,3 +39,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.t1003.006
|
- attack.t1003.006
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ tags:
|
|||||||
- attack.discovery
|
- attack.discovery
|
||||||
- attack.t1087
|
- attack.t1087
|
||||||
- attack.t1087.002
|
- attack.t1087.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.privilege_escalation
|
- attack.privilege_escalation
|
||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -46,3 +46,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.privilege_escalation
|
- attack.privilege_escalation
|
||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -34,3 +34,4 @@ tags:
|
|||||||
- attack.t1078.002
|
- attack.t1078.002
|
||||||
- attack.t1078.003
|
- attack.t1078.003
|
||||||
- car.2016-04-005
|
- car.2016-04-005
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -26,3 +26,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1077
|
- attack.t1077
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1098
|
- attack.t1098
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -50,3 +50,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.t1098
|
- attack.t1098
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -88,3 +88,4 @@ tags:
|
|||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1089
|
- attack.t1089
|
||||||
- attack.t1562.001
|
- attack.t1562.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.t1003.001
|
- attack.t1003.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -43,3 +43,4 @@ tags:
|
|||||||
- attack.t1003.004
|
- attack.t1003.004
|
||||||
- attack.t1003.001
|
- attack.t1003.001
|
||||||
- attack.t1003.006
|
- attack.t1003.006
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -38,3 +38,4 @@ tags:
|
|||||||
- attack.t1114
|
- attack.t1114
|
||||||
- attack.t1059
|
- attack.t1059
|
||||||
- attack.t1550.002
|
- attack.t1550.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -45,3 +45,4 @@ tags:
|
|||||||
- attack.t1059.005
|
- attack.t1059.005
|
||||||
- attack.t1059.006
|
- attack.t1059.006
|
||||||
- attack.t1059.007
|
- attack.t1059.007
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.g0010
|
- attack.g0010
|
||||||
- attack.t1050
|
- attack.t1050
|
||||||
- attack.t1543.003
|
- attack.t1543.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -39,3 +39,4 @@ tags:
|
|||||||
- attack.command_and_control
|
- attack.command_and_control
|
||||||
- attack.t1071
|
- attack.t1071
|
||||||
- attack.t1071.004
|
- attack.t1071.004
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -36,3 +36,4 @@ tags:
|
|||||||
- attack.command_and_control
|
- attack.command_and_control
|
||||||
- attack.t1071
|
- attack.t1071
|
||||||
- attack.t1071.004
|
- attack.t1071.004
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -36,3 +36,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.command_and_control
|
- attack.command_and_control
|
||||||
- attack.t1071
|
- attack.t1071
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ tags:
|
|||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1053
|
- attack.t1053
|
||||||
- attack.s0111
|
- attack.s0111
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -27,3 +27,4 @@ tags:
|
|||||||
- attack.g0064
|
- attack.g0064
|
||||||
- attack.t1050
|
- attack.t1050
|
||||||
- attack.t1543.003
|
- attack.t1543.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.g0010
|
- attack.g0010
|
||||||
- attack.t1050
|
- attack.t1050
|
||||||
- attack.t1543.003
|
- attack.t1543.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -35,3 +35,4 @@ tags:
|
|||||||
- attack.t1053
|
- attack.t1053
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
- attack.t1086
|
- attack.t1086
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ tags:
|
|||||||
- attack.t1566.001
|
- attack.t1566.001
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.initial_access
|
- attack.initial_access
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -27,3 +27,4 @@ tags:
|
|||||||
- attack.t1218
|
- attack.t1218
|
||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.execution
|
- attack.execution
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -33,3 +33,4 @@ tags:
|
|||||||
- car.2013-05-004
|
- car.2013-05-004
|
||||||
- car.2015-04-001
|
- car.2015-04-001
|
||||||
- attack.t1053.002
|
- attack.t1053.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -36,3 +36,4 @@ tags:
|
|||||||
- attack.t1210
|
- attack.t1210
|
||||||
- attack.impact
|
- attack.impact
|
||||||
- attack.t1499.004
|
- attack.t1499.004
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -41,3 +41,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.resource_development
|
- attack.resource_development
|
||||||
- attack.t1588
|
- attack.t1588
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.collection
|
- attack.collection
|
||||||
- attack.t1123
|
- attack.t1123
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -46,3 +46,4 @@ tags:
|
|||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
- attack.t1543.003
|
- attack.t1543.003
|
||||||
- attack.t1569.002
|
- attack.t1569.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -27,3 +27,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
- attack.t1021.003
|
- attack.t1021.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -38,3 +38,4 @@ tags:
|
|||||||
- attack.s0002
|
- attack.s0002
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.t1003.006
|
- attack.t1003.006
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -37,3 +37,4 @@ tags:
|
|||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1054
|
- attack.t1054
|
||||||
- attack.t1562.002
|
- attack.t1562.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.t1003.004
|
- attack.t1003.004
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -26,3 +26,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.t1003.004
|
- attack.t1003.004
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -34,3 +34,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1112
|
- attack.t1112
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.t1107
|
- attack.t1107
|
||||||
- attack.t1070.001
|
- attack.t1070.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1505.002
|
- attack.t1505.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -43,3 +43,4 @@ tags:
|
|||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1569
|
- attack.t1569
|
||||||
- cve.2021.1675
|
- cve.2021.1675
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ tags:
|
|||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1569
|
- attack.t1569
|
||||||
- cve.2021.1675
|
- cve.2021.1675
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ tags:
|
|||||||
- attack.t1569
|
- attack.t1569
|
||||||
- cve.2021.1675
|
- cve.2021.1675
|
||||||
- cve.2021.34527
|
- cve.2021.34527
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -26,3 +26,4 @@ tags:
|
|||||||
- attack.t1200
|
- attack.t1200
|
||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.initial_access
|
- attack.initial_access
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -31,3 +31,4 @@ tags:
|
|||||||
- attack.discovery
|
- attack.discovery
|
||||||
- attack.t1087
|
- attack.t1087
|
||||||
- attack.t1087.002
|
- attack.t1087.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -35,3 +35,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1053
|
- attack.t1053
|
||||||
- attack.t1053.005
|
- attack.t1053.005
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -33,3 +33,4 @@ tags:
|
|||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
- attack.t1035
|
- attack.t1035
|
||||||
- attack.t1569.002
|
- attack.t1569.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -26,3 +26,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1136.001
|
- attack.t1136.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1554
|
- attack.t1554
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.t1554
|
- attack.t1554
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ tags:
|
|||||||
- attack.t1003.002
|
- attack.t1003.002
|
||||||
- attack.t1003.004
|
- attack.t1003.004
|
||||||
- attack.t1003.003
|
- attack.t1003.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -35,3 +35,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1027
|
- attack.t1027
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -40,3 +40,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1027
|
- attack.t1027
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.t1027
|
- attack.t1027
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1059.001
|
- attack.t1059.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -34,3 +34,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.initial_access
|
- attack.initial_access
|
||||||
- attack.t1566.001
|
- attack.t1566.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -51,3 +51,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1077
|
- attack.t1077
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ tags:
|
|||||||
- attack.t1482
|
- attack.t1482
|
||||||
- attack.t1018
|
- attack.t1018
|
||||||
- attack.t1016
|
- attack.t1016
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -67,3 +67,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.t1003.001
|
- attack.t1003.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -40,3 +40,4 @@ tags:
|
|||||||
- attack.t1035
|
- attack.t1035
|
||||||
- attack.t1569.002
|
- attack.t1569.002
|
||||||
- attack.s0005
|
- attack.s0005
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -31,3 +31,4 @@ tags:
|
|||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1003
|
- attack.t1003
|
||||||
- attack.s0005
|
- attack.s0005
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -37,3 +37,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1077
|
- attack.t1077
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -63,3 +63,4 @@ tags:
|
|||||||
- attack.t1134
|
- attack.t1134
|
||||||
- attack.t1134.001
|
- attack.t1134.001
|
||||||
- attack.t1134.002
|
- attack.t1134.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -31,3 +31,4 @@ tags:
|
|||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1175
|
- attack.t1175
|
||||||
- attack.t1021.003
|
- attack.t1021.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ tags:
|
|||||||
- attack.persistence
|
- attack.persistence
|
||||||
- attack.privilege_escalation
|
- attack.privilege_escalation
|
||||||
- attack.t1543.003
|
- attack.t1543.003
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -38,3 +38,4 @@ tags:
|
|||||||
- attack.t1089
|
- attack.t1089
|
||||||
- attack.t1562.001
|
- attack.t1562.001
|
||||||
- attack.t1112
|
- attack.t1112
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -30,3 +30,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -27,3 +27,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.defense_evasion
|
- attack.defense_evasion
|
||||||
- attack.t1036
|
- attack.t1036
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1076
|
- attack.t1076
|
||||||
- attack.t1021.001
|
- attack.t1021.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -31,3 +31,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.impact
|
- attack.impact
|
||||||
- attack.t1499.001
|
- attack.t1499.001
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ tags:
|
|||||||
- attack.t1075
|
- attack.t1075
|
||||||
- attack.s0002
|
- attack.s0002
|
||||||
- attack.t1550.002
|
- attack.t1550.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -40,3 +40,4 @@ tags:
|
|||||||
- attack.t1075
|
- attack.t1075
|
||||||
- car.2016-04-004
|
- car.2016-04-004
|
||||||
- attack.t1550.002
|
- attack.t1550.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -42,3 +42,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1075
|
- attack.t1075
|
||||||
- attack.t1550.002
|
- attack.t1550.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -31,3 +31,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1187
|
- attack.t1187
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -41,3 +41,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1187
|
- attack.t1187
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -32,3 +32,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.credential_access
|
- attack.credential_access
|
||||||
- attack.t1207
|
- attack.t1207
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -25,3 +25,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.execution
|
- attack.execution
|
||||||
- attack.t1569.002
|
- attack.t1569.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -29,3 +29,4 @@ status: experimental
|
|||||||
tags:
|
tags:
|
||||||
- attack.t1068
|
- attack.t1068
|
||||||
- attack.privilege_escalation
|
- attack.privilege_escalation
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
@@ -27,3 +27,4 @@ tags:
|
|||||||
- attack.lateral_movement
|
- attack.lateral_movement
|
||||||
- attack.t1021
|
- attack.t1021
|
||||||
- attack.t1021.002
|
- attack.t1021.002
|
||||||
|
ruletype: SIGMA
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user