Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding 4 rules from MITRE's Center for Threat Informed Defense #4457

Merged
merged 5 commits into from
Sep 29, 2023

Conversation

RobertSchull
Copy link
Contributor

@RobertSchull RobertSchull commented Sep 26, 2023

Summary of the Pull Request

Summiting the Pyramid is a project from MITRE's Center for Threat Informed Defense and during the course of our research we developed a few analytics that we wanted to make them more accessible.
link to project page: https://center-for-threat-informed-defense.github.io/summiting-the-pyramid/overview/

Changelog

new: Service Registry Key Read Access Request
new: Scheduled Task Created - FileCreation
new: Scheduled Task Created - Registry

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@nasbench
Copy link
Member

Thanks for the submission @RobertSchull. I've made some changes to the rules so that they conform to the Sigma HQ standard. 2 main changes are below

@nasbench nasbench requested a review from phantinuss September 28, 2023 10:26
@nasbench nasbench added Rules 2nd Review Needed PR need a second approval Windows Pull request add/update windows related rules labels Sep 28, 2023
@nasbench nasbench removed the 2nd Review Needed PR need a second approval label Sep 29, 2023
@phantinuss phantinuss merged commit c57c076 into SigmaHQ:master Sep 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants