-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fixed fps in some rules specifically remote thread creation related #5222
base: master
Are you sure you want to change the base?
fixed fps in some rules specifically remote thread creation related #5222
Conversation
As discussed earlier, the Regarding the The options are either to deprecate the rule or proceed with the current filters as they are. Please share your decision on this. |
...ndows/builtin/appxdeployment_server/win_appxdeployment_server_uncommon_package_locations.yml
Outdated
Show resolved
Hide resolved
rules/windows/create_remote_thread/create_remote_thread_win_susp_relevant_source_image.yml
Outdated
Show resolved
Hide resolved
rules/windows/create_remote_thread/create_remote_thread_win_susp_uncommon_source_image.yml
Outdated
Show resolved
Hide resolved
rules/windows/create_remote_thread/create_remote_thread_win_susp_uncommon_source_image.yml
Show resolved
Hide resolved
The one you moved to the TH folder needs to have the appropriate tag so please do so. As for the |
Co-authored-by: Nasreddine Bencherchali <[email protected]>
Sorry I messed up because of similar names, the rule I was talking about was |
…handa000/sigma into false-positives-mar-2025
Summary of the Pull Request
fixed fps in some rules specifically remote thread creation related
Changelog
fix: Uncommon AppX Package Locations: added a new filter to reduce fp noise
fix: Rare Remote Thread Creation By Uncommon Source Image: added new filters to reduce fp noise
fix: Remote Thread Creation By Uncommon Source Image: added new filters to reduce fp noise
update: Remote Thread Created In Shell Application: moved to threat-hunting folder as it was causing so much fp noise
Example Log Event
Fixed Issues
SigmaHQ Rule Creation Conventions