Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update shell open key rule #2282

Merged
merged 3 commits into from
Nov 19, 2021
Merged

Update shell open key rule #2282

merged 3 commits into from
Nov 19, 2021

Conversation

Karneades
Copy link
Contributor

Make rule more generic regarding the included exefile detection instead of only naming it "uac bypass". Add further references and attack tags. There is also an other rule regarding asep reg key manipulation which also includes exefile: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry_event/sysmon_asep_reg_keys_modification.yml.

* Make rule more generic regarding exefile detection instead of only naming it "uac bypass"
* Add further references and attack tags
@Neo23x0
Copy link
Collaborator

Neo23x0 commented Nov 19, 2021

I think, when we change the title, we should also update the modified date

@Karneades
Copy link
Contributor Author

Karneades commented Nov 19, 2021 via email

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Nov 19, 2021

No, sorry, our current way to treat the "modified" field is to only change it when the "detection" section changes. We haven't changed the rule title very often.

@Neo23x0 Neo23x0 merged commit 19a303b into SigmaHQ:master Nov 19, 2021
@Karneades Karneades deleted the exefile branch November 19, 2021 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants