Commit Graph

  • 8dedf37c64 Add WordShellcodeDecoder_Generic detection rule main S12cybersecurity 2026-06-08 12:03:48 +02:00
  • cefa789ea4 Add YARA rule for APC Tandem Primitive Injection detection S12cybersecurity 2026-05-20 11:58:54 +02:00
  • 0da5c526f9 Add rule to detect NtCreateThreadEx read primitive S12cybersecurity 2026-05-18 12:02:52 +02:00
  • 580e481c12 Add YARA rule for ntdll.dll hook scanning detection S12cybersecurity 2026-05-17 12:42:43 +02:00
  • 1114ef2526 Add rule for detecting APC-based memory write abuse S12cybersecurity 2026-05-14 09:17:37 +02:00
  • 3326db0e03 Remove reference from PDB symbol resolution YARA file S12cybersecurity 2026-05-12 09:46:45 +02:00
  • 8ca71c7c87 Create PDB_Symbol_Resolution_Kernel_Offsets rule S12cybersecurity 2026-05-12 09:45:35 +02:00
  • 2494aab411 Add ETWTI_Bypass_BYOVD rule for ETW detection S12cybersecurity 2026-05-07 11:57:01 +02:00
  • 49b5a4062c Add WFP Callout Patching detection rule S12cybersecurity 2026-05-05 21:47:40 +02:00
  • bce8475724 Add detection rule for MiniFilter Callback Unlinking S12cybersecurity 2026-04-29 10:50:20 +02:00
  • 59ca4f6a10 Add YARA rule for detecting kernel callback manipulation S12cybersecurity 2026-04-23 10:02:01 +02:00
  • 1e30a1f9fd Add detection rule for PspCreateProcessNotifyRoutine enumeration S12cybersecurity 2026-04-21 11:21:31 +02:00
  • 82d218f403 Add YARA rule for Worker Factory Injection detection S12cybersecurity 2026-04-14 11:52:56 +02:00
  • 26208dc1e7 Add rule to detect Code Integrity status queries S12cybersecurity 2026-04-09 11:19:04 +02:00
  • 136226babc Add detection rule for BYOVD and Defender sabotage S12cybersecurity 2026-04-07 09:20:41 +02:00
  • 952b6d5eb2 Add YARA rule for COM Surrogate injection detection S12cybersecurity 2026-04-06 12:24:24 +02:00
  • a39cfa1c65 Create BYOVD_Defender_Killer_Generic YARA rule S12cybersecurity 2026-04-01 10:09:51 +02:00
  • 1eb7b3109b Add rule to detect BYOVD Token Stealing LPE S12cybersecurity 2026-03-31 10:34:15 +02:00
  • d13f198077 Add rule for detecting Windows Code Integrity bypass S12cybersecurity 2026-03-26 10:39:18 +01:00
  • 61e7762cfe Add rule for detecting persistence via Startup directory S12cybersecurity 2026-03-25 11:36:00 +01:00
  • ad03174075 Add BYOVD detection rule for kernel R/W primitives S12cybersecurity 2026-03-18 16:35:35 +01:00
  • b21bf18948 Add Layered String Obfuscation detection rule S12cybersecurity 2026-03-10 08:50:09 +01:00
  • 2814494fd3 Add YARA rule for detecting reflective DLL loading S12cybersecurity 2026-03-03 10:24:32 +01:00
  • 0a52dc900a Add YARA rule for detecting BYOVD process termination tools S12cybersecurity 2026-02-24 10:40:29 +01:00
  • 10f4a6482c Create rule for compile-time XOR string encryption detection S12cybersecurity 2026-02-23 11:51:32 +01:00
  • bbb60001f8 Add YARA rule for Speck CBC key wrapping detection S12cybersecurity 2026-02-23 10:13:41 +01:00
  • 546ec46ab3 Add rule to detect kernel driver loading attempts S12cybersecurity 2026-02-11 11:57:31 +01:00
  • 1be8392e86 Add PPL_Weaponization_Intent rule for detection S12cybersecurity 2026-02-10 09:38:32 +01:00
  • 9e12d6c614 Add YARA rule for detecting QueueUserAPC2 injection S12cybersecurity 2026-01-29 09:50:04 +01:00
  • dacf325151 Add rule to detect PPL protection level queries S12cybersecurity 2026-01-28 14:41:56 +01:00
  • a488a3957f Create RPC_Over_TCP_Communication.yar S12cybersecurity 2026-01-15 11:10:17 +01:00
  • 71e91956f2 Rename Windows_RPC_Remote_Call.yml to Windows_RPC_Remote_Call.yar S12cybersecurity 2026-01-14 11:28:42 +01:00
  • 2b270947a3 Create Windows_RPC_Remote_Call.yml S12cybersecurity 2026-01-14 11:28:04 +01:00
  • be86905cd1 Add rule for detecting custom DLL loading via NTDLL S12cybersecurity 2026-01-12 10:17:29 +01:00
  • 0eceaa73d8 Add rule for detecting Thread Name-Calling DLL injection S12cybersecurity 2025-12-30 11:51:16 +01:00
  • c2e24cd11b Create Thread_NameCalling_Shellcode_Copy_Technique.yar S12cybersecurity 2025-12-29 12:01:03 +01:00
  • d88fa0fe82 Add rule to detect suspicious PostThreadMessage usage S12cybersecurity 2025-12-24 10:46:02 +01:00
  • 23d7a475ba Add YARA rule for suspicious clipboard IPC behavior S12cybersecurity 2025-12-24 10:04:39 +01:00
  • c863dd6758 Create CMSTP_UAC_Bypass_General.yar S12cybersecurity 2025-12-23 11:30:23 +01:00
  • 4235461c0b Create Win_ProcInj_ThreadNameCalling_General.yar S12cybersecurity 2025-12-22 12:41:51 +01:00
  • d70af77b66 Create Suspicious_Special_User_APC_Injection_With_Handle_Enumeration_And_RWX_Scan.yar S12cybersecurity 2025-12-16 11:50:42 +01:00
  • 1fc8fbdd79 Create WIN_APC_Injection_NtQueueApcThreadEx2_SpecialUserAPC.yar S12cybersecurity 2025-12-09 10:17:01 +01:00
  • a17c2cd9c2 Add rule to detect IPC techniques using thread descriptions S12cybersecurity 2025-12-03 10:18:01 +01:00
  • c6c3322fdf Create Donut_Process_Migration.yar S12cybersecurity 2025-11-10 11:59:03 +01:00
  • 620919aa82 Add detection rule for section-based process injection S12cybersecurity 2025-11-10 09:47:27 +01:00
  • f005d939e9 Add rule for detecting LDAP/AD enumeration techniques S12cybersecurity 2025-11-06 09:35:29 +01:00
  • f110a9479b Create Win_HTTP_JSON_C2_Poller_Generic.yar S12cybersecurity 2025-11-05 10:17:48 +01:00
  • 1d523513e5 Create Windows_NamedPipe_Interactive_Shell.yar S12cybersecurity 2025-10-29 21:45:05 +01:00
  • f331342c11 Create Named_Pipe_Command_Execution_Technique.yar S12cybersecurity 2025-10-23 21:48:54 +02:00
  • dac090444a Create dns_txt_c2_tunnel.yar S12cybersecurity 2025-10-22 21:48:26 +02:00
  • 53760e4733 Add DNS_Tunnel_Client_Technique rule for detection S12cybersecurity 2025-10-20 21:49:28 +02:00
  • a39c2a322f Create discord_exfiltrate.yar S12cybersecurity 2025-10-13 21:54:37 +02:00
  • 4562ac03a9 Create blindshell.yar S12cybersecurity 2025-10-07 21:24:36 +02:00
  • 920423367c Update README.md S12cybersecurity 2025-10-02 10:41:04 +02:00
  • 1525aba751 Update README.md S12cybersecurity 2025-10-02 10:40:31 +02:00
  • 9810d7f5fa Create wincred_dump.yar S12cybersecurity 2025-10-01 21:38:05 +02:00
  • 9c111667af Create process-dump.yar S12cybersecurity 2025-09-25 21:55:58 +02:00
  • 56db59e6da Create CXX_Constexpr_XOR_String_Obfuscation.yar S12cybersecurity 2025-09-15 22:32:22 +02:00
  • 4f1e34dcb2 Create ETWEventRegisterAbuser.yar S12cybersecurity 2025-08-28 21:39:21 +02:00
  • 4ceb00de6c Create ETWSpoofing.yar S12cybersecurity 2025-08-26 21:45:19 +02:00
  • 688129b0e8 Create LSB_Steganography_Payload_Operations.yar S12cybersecurity 2025-08-12 21:29:44 +02:00
  • 58a63e196b Create RC5_Shellcode_Encryption.yar S12cybersecurity 2025-07-28 21:37:12 +02:00
  • f3d20ba982 Create rc4_encryption.yar S12cybersecurity 2025-07-22 21:46:48 +02:00
  • 4d25b77327 Create Selective_In_Memory_NTDLL_Unhooking.yar S12cybersecurity 2025-07-03 22:18:44 +02:00
  • 6e22c3b827 Create detect_userland_hook_scanner.yar S12cybersecurity 2025-07-01 21:19:33 +02:00
  • c4857cc2fe Create detect_RC6_decryption.yar S12cybersecurity 2025-06-25 21:46:46 +02:00
  • c4d5269c9e Create speck-shellcode-loader.yar S12cybersecurity 2025-06-24 21:18:59 +02:00
  • 2c6a7fafa9 Create speckShellcodeEncryption.yar S12cybersecurity 2025-06-19 21:23:53 +02:00
  • 310e0f6c47 Create unhookNTDLLPerunFarts.yar S12cybersecurity 2025-06-05 21:53:24 +02:00
  • 0974bff0b1 Create ghostDriverLoader.yar S12cybersecurity 2025-06-04 21:34:04 +02:00
  • 14b1cfc06d Create kernelDriverLoader.yar S12cybersecurity 2025-06-03 21:18:36 +02:00
  • 2a387e4c9a Create ghost_files.yar S12cybersecurity 2025-05-27 21:21:10 +02:00
  • 5c518b418b Create ghostly_hollowing.yar S12cybersecurity 2025-05-21 21:52:39 +02:00
  • dd0e968e00 Update and rename msfvenom.yar to windowsmeterpreterreverse_tcp.yar S12cybersecurity 2025-05-13 21:58:05 +02:00
  • 81532a299b Add files via upload S12cybersecurity 2025-05-13 21:55:18 +02:00
  • dd759312ec Initial commit S12cybersecurity 2025-05-12 21:59:43 +02:00