Rule Library

Sigma Rules

16 rules found for "Ömer Günal"

3,731Total
3,132Detection
457Emerging
139Hunting
Detectionlowstable

Password Policy Discovery - Linux

Detects password policy discovery commands

Linuxauditd
Ömer Günal+2Thu Oct 08linux
Detectioninformationalstable

System and Hardware Information Discovery

Detects system information discovery commands

Linuxauditd
Ömer Günal+1Thu Oct 08linux
Detectionlowstable

Remote File Copy

Detects the use of tools that copy files from or to remote systems

Linux
Ömer GünalThu Jun 18linux
Detectionmediumtest

Disabling Security Tools - Builtin

Detects disabling security tools

Linuxsyslog
Ömer Günal+2Wed Jun 17linux
Detectionlowstable

Scheduled Task/Job At

Detects the use of at/atd which are utilities that are used to schedule tasks. They are often abused by adversaries to maintain persistence or to perform task scheduling for initial or recurring execution of malicious code

LinuxProcess Creation
Ömer Günal+1Tue Oct 06linux
Detectionmediumstable

Linux Logs Clearing Attempts

Detects logs clearing attempts on Linux systems via utilities such as 'rm', 'rmdir', 'shred', and 'unlink' targeting log files and directories. Adversaries often try to clear logs to cover their tracks after performing malicious activities.

LinuxProcess Creation
Ömer Günal+1Wed Oct 07linux
Detectioninformationalstable

File Deletion

Detects file deletion using "rm", "shred" or "unlink" commands which are used often by adversaries to delete files left behind by the actions of their intrusion activity

LinuxProcess Creation
Ömer Günal+1Wed Oct 07linux
Detectionlowtest

Install Root Certificate

Detects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s

LinuxProcess Creation
Ömer Günal+1Mon Oct 05linux
Detectionlowtest

Local Groups Discovery - Linux

Detects enumeration of local system groups. Adversaries may attempt to find local system groups and permission settings

LinuxProcess Creation
Ömer Günal+2Sun Oct 11linux
Detectionlowtest

Connection Proxy

Detects setting proxy configuration

LinuxProcess Creation
Ömer GünalWed Jun 17linux
Detectionmediumtest

Disabling Security Tools

Detects disabling security tools

LinuxProcess Creation
Ömer Günal+2Wed Jun 17linux
Detectionlowtest

Setuid and Setgid

Detects suspicious change of file privileges with chown and chmod commands

LinuxProcess Creation
Ömer GünalTue Jun 16linux
Detectioninformationalstable

System Information Discovery

Detects system information discovery commands

LinuxProcess Creation
Ömer Günal+1Thu Oct 08linux
Detectioninformationaltest

System Network Discovery - Linux

Detects enumeration of local network configuration

LinuxProcess Creation
Ömer Günal and remotephone+1Tue Oct 06linux
Detectioninformationaltest

Local Groups Discovery - MacOs

Detects enumeration of local system groups

macOSProcess Creation
Ömer Günal+2Sun Oct 11macos
Threat Huntlowstable

Process Discovery

Detects process discovery commands. Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network

LinuxProcess Creation
Ömer Günal+2Tue Oct 06linux