From 4917f83c851c4b6a534666ad903d9108523ace19 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 9 Apr 2026 10:17:55 +0200 Subject: [PATCH] =?UTF-8?q?Cr=C3=A9ation=20r=C3=A8gle=20modif=20groupes=20?= =?UTF-8?q?windows?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- Brut-force-linux.xml | 4 +- Connexion-Linux-PBS.xml | 24 +++++++ Connexion-admin.xml | 26 +++++++ Group-Windows.xml | 155 ++++++++++++++++++++++++++++++++++++++++ fim-fs17101.xml | 15 +++- fortigate.xml | 2 +- 6 files changed, 220 insertions(+), 6 deletions(-) create mode 100644 Connexion-Linux-PBS.xml create mode 100644 Group-Windows.xml diff --git a/Brut-force-linux.xml b/Brut-force-linux.xml index f199a38..c4f092c 100644 --- a/Brut-force-linux.xml +++ b/Brut-force-linux.xml @@ -1,7 +1,7 @@ - + 5503 srcip Brut force Linux @@ -12,7 +12,7 @@ - + 5503 tty Brut force Linux diff --git a/Connexion-Linux-PBS.xml b/Connexion-Linux-PBS.xml new file mode 100644 index 0000000..569fb70 --- /dev/null +++ b/Connexion-Linux-PBS.xml @@ -0,0 +1,24 @@ + + + + + 5501 + pbs + Connexion SSH sur PBS-LR + + T1078 + + + + + + + + 5501 + pbs03 + Connexion SSH sur PBS-LR + + T1078 + + + \ No newline at end of file diff --git a/Connexion-admin.xml b/Connexion-admin.xml index 7a96df8..3795846 100644 --- a/Connexion-admin.xml +++ b/Connexion-admin.xml @@ -51,6 +51,32 @@ + + + + + 60118 + ^CodexSandboxOffline$ + Filtre anti bruit pour co sandbox windows offline + no_full_log + + T1078 + + + + + + + + 67023 + ^CodexSandboxOffline$ + Filtre anti bruit pour déco sandbox windows offline + no_full_log + + T1078 + + + diff --git a/Group-Windows.xml b/Group-Windows.xml new file mode 100644 index 0000000..ed03d6b --- /dev/null +++ b/Group-Windows.xml @@ -0,0 +1,155 @@ + + + + + + + + + 60144,60145 + ^S-1-5-32-544$ + ^636$|^4732$ + Ajout membre Administrateurs + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + 60145 + ^S-1-5-32-544$ + ^637$|^4733$ + Suppression membre Administrateurs + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + + + + 60141 + ^S-1-5-21-888472903-3453034670-1221216045-526$ + Ajout membre Administrateurs clés + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + 60142 + ^S-1-5-21-888472903-3453034670-1221216045-526$ + Suppression membre Administrateurs clés + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + + + + 60151 + ^S-1-5-21-888472903-3453034670-1221216045-527$ + Ajout membre Administrateurs clés Entreprise + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + 60152 + ^S-1-5-21-888472903-3453034670-1221216045-527$ + Suppression membre Administrateurs clés Entreprise + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + + + + 60149,60150,60151,60152 + ^S-1-5-\S+-519$ + Groupe Administrateurs de l'entreprise modifié + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + + + + + 60149,60150,60151,60152 + ^S-1-5-\S+-518$ + Groupe Administrateurs du schéma modifié + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + + + + 60141,60142 + ^S-1-5-\S+-512$ + ^632$|^4728$ + Ajout membre Admins du domaine + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + 60142 + ^S-1-5-\S+-512$ + ^633$|^4729$ + Ajout membre Admins du domaine + no_full_log + group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, + + T1484 + + + + + + + + + + + + \ No newline at end of file diff --git a/fim-fs17101.xml b/fim-fs17101.xml index f5d44c2..af48aa0 100644 --- a/fim-fs17101.xml +++ b/fim-fs17101.xml @@ -22,6 +22,15 @@ + 100100 + .db$ + Filtre modif fichier temporaire + + + + + + 100100 Zone.Identifier$ Filtre modif fichier temporaire @@ -30,7 +39,7 @@ - + 100100 ^4663$ Alerte fichier modifié @@ -40,7 +49,7 @@ - + 100100 ^4659$ Alerte fichier supprimé @@ -50,7 +59,7 @@ - + 100100 Écriture données (ou ajout fichier) Alerte fichier Créé diff --git a/fortigate.xml b/fortigate.xml index e4bfc0f..e721096 100644 --- a/fortigate.xml +++ b/fortigate.xml @@ -33,7 +33,7 @@ 100251 - ^\d{10,}$ + ^(?:[1-9]\d{9})$ CRITICAL - Fortigate: Massive outbound transfer 1GB from $(srcip) to $(dstip)