mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
Fix YAML scanner errors: quote Name values containing colons
Five Name fields containing ": " were parsed as YAML mapping separators. Wrapped affected values in double-quotes across three chokepoint files. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
78ca6afc24
commit
d312295365
@@ -145,7 +145,7 @@ Intel:
|
||||
- Name: Talos — BYOVD Loader Behind DeadLock Ransomware
|
||||
URL: https://blog.talosintelligence.com/byovd-loader-deadlock-ransomware/
|
||||
Description: Technical analysis of purpose-built EDR-kill tooling bundled with ransomware; covers driver weaponization and service termination via kernel calls
|
||||
- Name: MITRE ATT&CK — T1562.001 Impair Defenses: Disable or Modify Tools
|
||||
- Name: "MITRE ATT&CK — T1562.001 Impair Defenses: Disable or Modify Tools"
|
||||
URL: https://attack.mitre.org/techniques/T1562/001/
|
||||
Description: Technique definition, procedure examples, and detection guidance for disabling or modifying security tools
|
||||
- Name: MITRE ATT&CK — T1489 Service Stop
|
||||
|
||||
@@ -137,7 +137,7 @@ Intel:
|
||||
- Name: Proofpoint — ClickFix Social Engineering Technique Floods Threat Landscape
|
||||
URL: https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape
|
||||
Description: Original Proofpoint research naming and first documenting ClickFix; covers TA571 initial campaigns and early payload taxonomy
|
||||
- Name: Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix
|
||||
- Name: "Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix"
|
||||
URL: https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix
|
||||
Description: Documents APT28, MuddyWater (TA450), Kimsuky (TA427), and UNK_RemoteRogue adoption of ClickFix between October 2024 and February 2025
|
||||
- Name: Microsoft Security Blog — Think Before You ClickFix
|
||||
@@ -146,10 +146,10 @@ Intel:
|
||||
- Name: Huntress — Don't Sweat the ClickFix Techniques
|
||||
URL: https://huntress.com/blog/dont-sweat-clickfix-techniques
|
||||
Description: Primary reference for the ClickFix variant taxonomy (FileFix, TerminalFix, DownloadFix); explains why the chokepoint is stable across all variants
|
||||
- Name: mr.d0x — FileFix: A ClickFix Alternative
|
||||
- Name: "mr.d0x — FileFix: A ClickFix Alternative"
|
||||
URL: https://mrd0x.com/filefix-clickfix-alternative/
|
||||
Description: Original research introducing FileFix (June 2025); details the File Explorer address bar attack surface and why it bypasses Run-dialog detection heuristics
|
||||
- Name: MITRE ATT&CK — T1204.004 User Execution: Malicious Copy and Paste
|
||||
- Name: "MITRE ATT&CK — T1204.004 User Execution: Malicious Copy and Paste"
|
||||
URL: https://attack.mitre.org/techniques/T1204/004/
|
||||
Description: Official technique definition added March 18, 2025; procedure examples and detection guidance specific to clipboard-based social engineering
|
||||
- Name: ClickGrab
|
||||
|
||||
@@ -170,7 +170,7 @@ Intel:
|
||||
- Name: Huntress — A Series of Unfortunate (RMM) Events
|
||||
URL: https://www.huntress.com/blog/series-of-unfortunate-rmm-events
|
||||
Description: Covers RMM-to-RMM chaining, detection evasion patterns, and the broader RMM abuse landscape from an MSP incident response perspective
|
||||
- Name: Microsoft — Keys to the Kingdom: RMM Exploits in Human-Operated Intrusions 2024–25
|
||||
- Name: "Microsoft — Keys to the Kingdom: RMM Exploits in Human-Operated Intrusions 2024–25"
|
||||
URL: https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/keys-to-the-kingdom-rmm-exploits-enabling-human-operated-intrusions-in-2024%E2%80%9325/4410903
|
||||
Description: Microsoft Security Experts analysis of RMM exploitation patterns across incident response engagements; covers both social engineering delivery and direct CVE exploitation vectors
|
||||
- Name: BleepingComputer — AnyDesk Production Servers Breached
|
||||
|
||||
Reference in New Issue
Block a user