Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

c8b00925-926c-47e3-beea-298fd563728e Possible incorrect field/value pairing #4572

Closed
Blackmore-Robert opened this issue Nov 15, 2023 · 2 comments · Fixed by #4577
Closed
Assignees
Labels
Bug Indicates a bug with one of the tools and features provided by the project

Comments

@Blackmore-Robert
Copy link

title: Remote Access Tool Services Have Been Installed - Security
id: c8b00925-926c-47e3-beea-298fd563728e

This is the first time I'm posting here and am hopefully adhering to the guidelines.

This rule uses 'ServiceFileName' in the selection; however, based on my research into this Windows event and log, I think it should be 'ServiceName' instead. We could certainly use the 'ServiceFileName' field if we want to use the executable path instead. Please let me know if I've made an error, thanks!

Rule

Copy link
Contributor

Welcome @Blackmore-Robert 👋

It looks like this is your first issue on the Sigma rules repository!

The following repository accepts issues related to false positives or 'rule ideas'.

If you're reporting an issue related to the pySigma library please consider submitting it here

If you're reporting an issue related to the deprecated sigmac library please consider submitting it here

Thanks for taking the time to open this issue, and welcome to the Sigma community! 😃

@nasbench nasbench self-assigned this Nov 15, 2023
@nasbench
Copy link
Member

Hey @Blackmore-Robert thanks for opening this issue.

I agree with you this seems to be a typo/mistake in the rule. I'll get it fixed asap :)

Cheers.

@nasbench nasbench added the Bug Indicates a bug with one of the tools and features provided by the project label Nov 15, 2023
nasbench added a commit to nasbench/sigma that referenced this issue Nov 15, 2023
@nasbench nasbench linked a pull request Nov 21, 2023 that will close this issue
nasbench added a commit to nasbench/sigma that referenced this issue Dec 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug Indicates a bug with one of the tools and features provided by the project
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants