Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FP fixes #4484

Merged
merged 5 commits into from
Oct 17, 2023
Merged

FP fixes #4484

merged 5 commits into from
Oct 17, 2023

Conversation

phantinuss
Copy link
Collaborator

@phantinuss phantinuss commented Oct 17, 2023

Summary of the Pull Request

Changelog

fix: Direct Syscall of NtOpenProcess - falsepositives meta data
fix: Potential Shellcode Injection - remove System.ni.dll as there are multiple FPs with ntdll.dll
fix: Suspicious Shim Database Installation via Sdbinst.EXE - FP with another sdbinst execution by svchost

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@nasbench nasbench added Rules Windows Pull request add/update windows related rules False-Positive Fix Pull Request fixes a false positive with one of the rules labels Oct 17, 2023
@nasbench nasbench merged commit 79bce2c into SigmaHQ:master Oct 17, 2023
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
False-Positive Fix Pull Request fixes a false positive with one of the rules Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants