From 9f91dc5632ab5bc14c10a2e4bc2bba13b1c4ba1c Mon Sep 17 00:00:00 2001 From: SOCFortress <95670863+socfortress@users.noreply.github.com> Date: Mon, 8 Aug 2022 22:10:02 -0500 Subject: [PATCH] Create 300001-win_sigma_rules_builtin.xml --- .../300001-win_sigma_rules_builtin.xml | 87 +++++++++++++++++++ 1 file changed, 87 insertions(+) create mode 100644 Windows Sigma Rules/300001-win_sigma_rules_builtin.xml diff --git a/Windows Sigma Rules/300001-win_sigma_rules_builtin.xml b/Windows Sigma Rules/300001-win_sigma_rules_builtin.xml new file mode 100644 index 0000000..ad3cf64 --- /dev/null +++ b/Windows Sigma Rules/300001-win_sigma_rules_builtin.xml @@ -0,0 +1,87 @@ + + +60001 +Powerview Add-DomainObjectAcl DCSync AD Extend Right + +T1098 + +no_full_log +^ntSecurityDescriptor$ +^5136$ +1131f6ad-9c07-11d1-f79f-00c04fc2dcd2|1131f6aa-9c07-11d1-f79f-00c04fc2dcd2|89e95b76-444d-4c62-991a-0facbeda640c +sigma_rules, + + +60001 +AD Object WriteDAC Access + +T1222 + +no_full_log +^4662$ +^DS$ +^0x40000$ +19195a5b-6da0-11d0-afd3-00c04fd930c9|domainDNS +sigma_rules, + + +60001 +Active Directory Replication from Non Machine Account + +T1003 + +no_full_log +^4662$ +^0x100$ +1131f6aa-9c07-11d1-f79f-00c04fc2dcd2|1131f6ad-9c07-11d1-f79f-00c04fc2dcd2|89e95b76-444d-4c62-991a-0facbeda640c +\$$|^MSOL_ +sigma_rules, + + +60001 +Chafer Activity + +T1112 + +no_full_log +^4698$ +^SC Scheduled Scan$|^UpdatMachine$ +sigma_rules, + + + + +60002 +Chafer Activity + +T1112 + +no_full_log +^7045$ +^SC Scheduled Scan$|^UpdatMachine$ +sigma_rules, + + +60002 +Turla PNG Dropper Service + +T1543 + +no_full_log +^7045$ +^WerFaultSvc$ +sigma_rules, + + + + +60003 +Audit CVE Event + +T1203 + +no_full_log +^Microsoft-Windows-Audit-CVE$ +sigma_rules, + +