File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 44 <RegistryEvent onmatch =" include" >
55 <!-- Microsoft:Office:Security _features-->
66 <!-- https://msrc.microsoft.com/update-guide/vulnerability/ADV170021-->
7- <TargetObject name =" T1559.002,office" condition =" end with" >\Word\Security\AllowDDE</TargetObject >
8- <TargetObject name =" T1559.002,office" condition =" end with" >\Excel\Security\DisableDDEServerLaunch</TargetObject >
9- <TargetObject name =" T1559.002,office" condition =" end with" >\Excel\Security\DisableDDEServerLookup</TargetObject >
7+ <TargetObject name =" technique_id= T1559.002,office" condition =" end with" >\Word\Security\AllowDDE</TargetObject >
8+ <TargetObject name =" technique_id= T1559.002,office" condition =" end with" >\Excel\Security\DisableDDEServerLaunch</TargetObject >
9+ <TargetObject name =" technique_id= T1559.002,office" condition =" end with" >\Excel\Security\DisableDDEServerLookup</TargetObject >
1010 </RegistryEvent >
1111 </RuleGroup >
1212 </EventFiltering >
Original file line number Diff line number Diff line change 44 <RegistryEvent onmatch =" include" >
55 <!-- Microsoft:Office:Security _features-->
66 <!-- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry_event/sysmon_disable_microsoft_office_security_features.yml-->
7- <TargetObject name =" T1562,office" condition =" end with" >\VBAWarnings</TargetObject >
8- <TargetObject name =" T1562,office" condition =" end with" >\DisableInternetFilesInPV</TargetObject >
9- <TargetObject name =" T1562,office" condition =" end with" >\DisableUnsafeLocationsInPV</TargetObject >
10- <TargetObject name =" T1562,office" condition =" end with" >\DisableAttachementsInPV</TargetObject >
7+ <TargetObject name =" technique_id= T1562,office" condition =" end with" >\VBAWarnings</TargetObject >
8+ <TargetObject name =" technique_id= T1562,office" condition =" end with" >\DisableInternetFilesInPV</TargetObject >
9+ <TargetObject name =" technique_id= T1562,office" condition =" end with" >\DisableUnsafeLocationsInPV</TargetObject >
10+ <TargetObject name =" technique_id= T1562,office" condition =" end with" >\DisableAttachementsInPV</TargetObject >
1111 </RegistryEvent >
1212 </RuleGroup >
1313 </EventFiltering >
Original file line number Diff line number Diff line change 77 <PipeName name =" technique_id=T1021.002,technique_name=SMB/Windows Admin Shares" condition =" end with" >-server</PipeName > <!-- default cobalt strike pipe name-->
88 </Rule >
99 <PipeName name =" technique_id=T1021.002,technique_name=SMB/Windows Admin Shares" condition =" begin with" >\msagent_</PipeName > <!-- default cobalt strike pipe name-->
10- <PipeName name =" technique_id=T1055; Possible Cobalt Strike post-exploitation jobs." condition =" begin with" >\postex_</PipeName > <!-- default cobalt strike pipe name-->
10+ <PipeName name =" technique_id=T1055, Possible Cobalt Strike post-exploitation jobs." condition =" begin with" >\postex_</PipeName > <!-- default cobalt strike pipe name-->
1111 <PipeName name =" technique_id=T1021.004,technique_name=Remote Services: SSH" condition =" begin with" >\postex_ssh_</PipeName > <!-- default cobalt strike pipe name-->
1212 <PipeName name =" technique_id=T1021.002,technique_name=SMB/Windows Admin Shares" condition =" begin with" >\status_</PipeName > <!-- default cobalt strike pipe name-->
1313 </PipeEvent >
You can’t perform that action at this time.
0 commit comments