If you want to help us improve the public @sigma_hq rules, this 👇 is a guide on when we filter FPs and when we accept them
Also check the rule levels: https://t.co/2LKbFdSFVB
Please provide filters for FPs with standard software as pull requests in the public repo
In addition to the documented "-e/--exec" flag in #lolbas about the "wsl.exe" binary (https://t.co/OrgJ7c7o9N). We can also use the "--system" flag to run Linux (as root) /Windows commands.
wsl --system [Command]
.@blubbfiction published a Cookiecutter template to facilitate the creation of backends for pySigma
https://t.co/Mf8sgx9RgV
pySigma is the new basis for conversions
https://t.co/iRldFnzzPK
Sigma-cli, which uses pySigma replaces the old&inflexible sigmac
https://t.co/g0214NVf1P
#Ukraine: In some significant news, it appears that the Czech Republic is supplying "dozens" of T-72M1 tanks & BVP-1 IFV to the UA forces.
Whilst the T-72M1 is rather old (slightly altered T-72A1), & so are the BVP-1 (BMP-1 with very minor changes), they would still be of use.
Here is a little more info/context from local media: https://t.co/hxY22p5J03 and some HQ images also of a few of the vehicles.
Note: This is totally separate from the supply of Pbv 501 (Mildly modernised BMP-1s formerly operated by Sweden) to Ukraine, which is also taking place.
Someone has built a huge regex to cover many obfuscated versions of the log4shell payloads
Really nice, I'll test it and update my gist
Repo
https://t.co/PWEhw7uir5
Test
https://t.co/FSMzCBsBTT