8000 Add correlation rules from AT project by tonifef · Pull Request #5415 · SigmaHQ/sigma · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Add correlation rules from AT project #5415

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

tonifef
Copy link
@tonifef tonifef commented May 13, 2025

Summary of the Pull Request

Adding three new correlation rules that reduce false positives in the detection of ambiguous attack techniques.

Changelog

new: Domain Account Discovery Correlation - Multiple discovery command usage
new: File and Directory Discovery Correlation - Discovery indicative of ransomware using Bitlocker
new: Archive Collected Data Correlation - Multiple instances of archiving activity observed

Example Log Event

Detailed info on analytic development can be found at the following links:

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

tonifef added 3 commits May 13, 2025 14:23
New correlation rule looking at a loose correlation of discovery commands being run
Correlation rule to look for discovery commands followed by suspicious BitLocker activity indicative of malicious intent
Detects multiple uses of archiving utilities indicative of staging activity
@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels May 13, 2025
Copy link
Contributor
@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Welcome @tonifef 👋

It looks like this is your first pull request on the Sigma rules repository!

Please make sure to read the SigmaHQ conventions document to make sure your contribution is adhering to best practices and has all the necessary elements in place for a successful approval.

Thanks again, and welcome to the Sigma community! 😃

@tonifef tonifef changed the title Tonifef newadditions Add correlation rules from AT project May 13, 2025
@tonifef tonifef marked this pull request as draft May 21, 2025 15:51
@tonifef tonifef marked this pull request as ready for review May 21, 2025 15:51
@phantinuss
Copy link
Collaborator

Hi @tonifef, we are not ready to integrate Sigma v2 correlation rules to the rules repo yet. We will keep this PR open until we are ready to do so and then start working on integrating it.

@nasbench nasbench marked this pull request as draft June 4, 2025 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Correlation-Rules Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
0