Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clean old sigmac hash trick #5088

Merged
merged 4 commits into from
Nov 25, 2024

Conversation

frack113
Copy link
Member

Summary of the Pull Request

Now pySigma can deal with KV haches , we can remove the fields we create for hash because of sigmac
Deprecated rules are updated only to avoid keeping these olds fields

Changelog

chore: test_logsource.py remove custom sigmac field

  • deprecated

update: Usage Of Malicious POORTRY Signed Driver - remove custom field
update: Vulnerable AVAST Anti Rootkit Driver Load - remove custom field
update: Vulnerable Dell BIOS Update Driver Load - remove custom field
update: Vulnerable GIGABYTE Driver Load - remove custom field
update: Vulnerable HW Driver Load - remove custom field
update: Vulnerable Lenovo Driver Load - remove custom field
update: GALLIUM Artefacts - remove custom field
update: Renamed PaExec Execution - remove custom field

  • Rules

update: GALLIUM IOCs - remove custom field
update: Malicious DLL Load By Compromised 3CXDesktopApp - remove custom field
update: Potential Compromised 3CXDesktopApp Execution - remove custom field
update: HackTool Named File Stream Created - remove custom field
update: PUA - Process Hacker Driver Load - remove custom field
update: PUA - System Informer Driver Load - remove custom field
update: Vulnerable HackSys Extreme Vulnerable Driver Load - remove custom field
update: Vulnerable WinRing0 Driver Load - remove custom field
update: WinDivert Driver Load - remove custom field
update: HackTool - SharpEvtMute DLL Load - remove custom field
update: HackTool - CoercedPotato Execution - remove custom field
update: HackTool - CreateMiniDump Execution - remove custom field
update: Hacktool Execution - Imphash - remove custom field
update: HackTool - GMER Rootkit Detector and Remover Execution - remove custom field
update: HackTool - HandleKatz LSASS Dumper Execution - remove custom field
update: HackTool - Impersonate Execution - remove custom field
update: HackTool - LocalPotato Execution - remove custom field
update: HackTool - PCHunter Execution - remove custom field
update: HackTool - PPID Spoofing SelectMyParent Tool Execution - remove custom field
update: HackTool - Stracciatella Execution - remove custom field
update: HackTool - SysmonEOP Execution - remove custom field
update: HackTool - UACMe Akagi Execution - remove custom field
update: HackTool - Windows Credential Editor (WCE) Execution - remove custom field
update: MpiExec Lolbin - remove custom field
update: PUA - Fast Reverse Proxy (FRP) Execution - remove custom field
update: PUA- IOX Tunneling Tool Execution - remove custom field
update: PUA - Nimgrab Execution - remove custom field
update: PUA - NPS Tunneling Tool Execution - remove custom field
update: PUA - Process Hacker Execution - remove custom field
update: PUA - System Informer Execution - remove custom field
update: Remote Access Tool - NetSupport Execution From Unusual Location - remove custom field
update: Renamed AdFind Execution - remove custom field
update: Renamed AutoIt Execution - remove custom field
update: Renamed NetSupport RAT Execution - remove custom field
update: Renamed PAExec Execution - remove custom field
update: Potential SquiblyTwo Technique Execution - remove custom field

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules Maintenance Related to additions and update of the repository features Emerging-Threats labels Nov 24, 2024
@nasbench nasbench merged commit d804e9c into SigmaHQ:master Nov 25, 2024
12 checks passed
@frack113 frack113 deleted the clean-old-sigmac-hash-trick branch November 25, 2024 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Emerging-Threats Maintenance Related to additions and update of the repository features Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants