From 9f91dc5632ab5bc14c10a2e4bc2bba13b1c4ba1c Mon Sep 17 00:00:00 2001
From: SOCFortress <95670863+socfortress@users.noreply.github.com>
Date: Mon, 8 Aug 2022 22:10:02 -0500
Subject: [PATCH] Create 300001-win_sigma_rules_builtin.xml
---
.../300001-win_sigma_rules_builtin.xml | 87 +++++++++++++++++++
1 file changed, 87 insertions(+)
create mode 100644 Windows Sigma Rules/300001-win_sigma_rules_builtin.xml
diff --git a/Windows Sigma Rules/300001-win_sigma_rules_builtin.xml b/Windows Sigma Rules/300001-win_sigma_rules_builtin.xml
new file mode 100644
index 0000000..ad3cf64
--- /dev/null
+++ b/Windows Sigma Rules/300001-win_sigma_rules_builtin.xml
@@ -0,0 +1,87 @@
+
+
+60001
+Powerview Add-DomainObjectAcl DCSync AD Extend Right
+
+T1098
+
+no_full_log
+^ntSecurityDescriptor$
+^5136$
+1131f6ad-9c07-11d1-f79f-00c04fc2dcd2|1131f6aa-9c07-11d1-f79f-00c04fc2dcd2|89e95b76-444d-4c62-991a-0facbeda640c
+sigma_rules,
+
+
+60001
+AD Object WriteDAC Access
+
+T1222
+
+no_full_log
+^4662$
+^DS$
+^0x40000$
+19195a5b-6da0-11d0-afd3-00c04fd930c9|domainDNS
+sigma_rules,
+
+
+60001
+Active Directory Replication from Non Machine Account
+
+T1003
+
+no_full_log
+^4662$
+^0x100$
+1131f6aa-9c07-11d1-f79f-00c04fc2dcd2|1131f6ad-9c07-11d1-f79f-00c04fc2dcd2|89e95b76-444d-4c62-991a-0facbeda640c
+\$$|^MSOL_
+sigma_rules,
+
+
+60001
+Chafer Activity
+
+T1112
+
+no_full_log
+^4698$
+^SC Scheduled Scan$|^UpdatMachine$
+sigma_rules,
+
+
+
+
+60002
+Chafer Activity
+
+T1112
+
+no_full_log
+^7045$
+^SC Scheduled Scan$|^UpdatMachine$
+sigma_rules,
+
+
+60002
+Turla PNG Dropper Service
+
+T1543
+
+no_full_log
+^7045$
+^WerFaultSvc$
+sigma_rules,
+
+
+
+
+60003
+Audit CVE Event
+
+T1203
+
+no_full_log
+^Microsoft-Windows-Audit-CVE$
+sigma_rules,
+
+