Willi Ballenthin
c1d20764ad
use "span of calls" scope ( #973 )
...
* use sequence scope instead of thread scope for "static: function" rules
* use sequence scope instead of thread scope for "static: basic block" rules
* make runtime linking rules more concise
* doc: describe sequence scope
* rename "sequence" scope to "span of calls" scope
* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/get-geographical-location.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/file-managers/gather-classicftp-information.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/database/wmi/reference-wmi-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/database/sql/reference-sql-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
---------
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
2025-01-29 10:27:13 +01:00
Jorik
ce5e041006
Improve existing persistence rules ( #953 )
...
* Improve existing persistence rules by limiting their scope, and adding some more details.
* Update persistence/startup-folder/write-file-to-startup-folder.yml
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
* change scope to call for shell command via WRM
* Update persistence/startup-folder/write-file-to-startup-folder.yml
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
* fix startup folder persistence rule
* change name screensaver persistence technique
* change name screensaver persistence technique pt 2
* fix write to startup folder persistence rule
---------
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
2024-12-09 10:51:47 +01:00
mr-tz
e18704545a
fix call/thread scopes manually
2023-11-24 11:35:00 +01:00
mr-tz
784c9dca53
upgrade rules using updated script
2023-11-24 11:34:28 +01:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
William Ballenthin
ea3ea14c22
minor reorg linux rules and logic
...
ref #442
2021-08-25 15:31:51 -06:00
Moritz Raabe
5a67716572
fix att&ck
2020-10-01 10:57:44 +02:00
William Ballenthin
1c39bd8349
graduate rules that pass the linter
2020-07-23 17:30:37 -06:00
William Ballenthin
54cfb05bd0
rules: address comments in #14
2020-06-26 17:45:56 -06:00
William Ballenthin
0482c936fb
rules: fix ATT&CK and MBC tags
2020-06-21 17:57:25 -06:00
William Ballenthin
7b4f4d10fb
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9
rules: reorganize rule names, namespaces, and ATT&CK mappings
2020-06-21 17:25:43 -06:00