Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix false positive found in testing #4762

Merged
merged 7 commits into from
Mar 11, 2024
Merged

Conversation

nasbench
Copy link
Member

@nasbench nasbench commented Mar 11, 2024

Summary of the Pull Request

This PR fixes some FP seen in testing.

Changelog

fix: Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process - Add multiple new FP filters seen in the wild
fix: Potential System DLL Sideloading From Non System Locations - Add multiple new FP filters seen in the wild
new: CrackMapExec File Indicators
remove: CrackMapExec File Creation Patterns
remove: Suspicious Epmap Connection

Example Log Event

N/A

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels Mar 11, 2024
@nasbench nasbench added the Work In Progress Some changes are needed label Mar 11, 2024
@nasbench nasbench removed the Work In Progress Some changes are needed label Mar 11, 2024
@nasbench nasbench added the 2nd Review Needed PR need a second approval label Mar 11, 2024
@nasbench nasbench removed the 2nd Review Needed PR need a second approval label Mar 11, 2024
@nasbench nasbench merged commit 1758511 into SigmaHQ:master Mar 11, 2024
12 checks passed
@nasbench nasbench deleted the fix-fp-mm branch March 11, 2024 21:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants