Commit Graph

1704 Commits

Author SHA1 Message Date
Willi Ballenthin 94de0355cd Merge branch 'master' into dynamic-syntax 2023-10-19 09:15:29 +00:00
Willi Ballenthin bc63b328dc Merge pull request #817 from Aayush-Goel-04/Aayush-Goel-04/#Issue322-COMfeature
Documentation for COM feature addition
2023-10-18 17:01:01 +02:00
Willi Ballenthin c88979a1bc fmt 2023-10-17 12:28:12 +00:00
Willi Ballenthin 796b5b3a22 readd file 2023-10-17 11:40:57 +00:00
Willi Ballenthin 05ee3df679 update scope syntax 2023-10-17 11:34:31 +00:00
Willi Ballenthin 9cb8848b03 Merge branch 'master' into dynamic-syntax 2023-10-17 10:29:30 +00:00
Capa Bot 8f806bbf6c Update rules number badge 2023-10-16 14:52:27 +00:00
Moritz 210b86f89e Merge pull request #836 from mandiant/update-alloc-rules
Update and refactor memory allocation/permission rules
2023-10-16 16:51:18 +02:00
Capa Bot c67c2ffda2 Update rules number badge 2023-10-12 09:01:10 +00:00
Ana María Martínez Gómez 2626fc680c Add enumerate-blocking-processes.yml (#705)
* Add enumerate-blocking-processes.yml

The AVOSLOCKER ransomware uses the APIs `RmRegisterResources` and
`RmGetList` to get a list of processes blocking the file to encrypt and
stop them.

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
Co-authored-by: Willi Ballenthin <wballenthin@google.com>
2023-10-12 11:00:56 +02:00
Moritz b778d25292 Update allocate-memory.yml 2023-10-11 12:08:01 +02:00
Moritz a39a2c0b52 Merge branch 'master' into update-alloc-rules 2023-10-11 12:03:42 +02:00
mr-tz 1be6720131 add runtime resolved functions 2023-10-11 11:54:50 +02:00
mr-tz 7ddf609ebc update example 2023-10-11 11:33:20 +02:00
mr-tz 66f58dffa0 update match rule name 2023-10-11 11:20:23 +02:00
mr-tz 5f223ea5ce rename rules 2023-10-11 11:17:13 +02:00
mr-tz ed791c9b17 separate allocate and change memory protection 2023-10-11 11:14:14 +02:00
Capa Bot 54e3a1d3dd Update rules number badge 2023-10-10 13:34:30 +00:00
Moritz 773c75c934 Create add-value-to-global-atom-table.yml (#831)
* Create add-value-to-global-atom-table.yml
2023-10-10 15:34:15 +02:00
Moritz 330d0f9612 Merge pull request #835 from mandiant/mr-tz-patch-1
Update generate-random-numbers-via-rtlgenrandom.yml
2023-10-10 12:09:10 +02:00
Capa Bot 5f579460f5 Update rules number badge 2023-10-10 09:55:15 +00:00
Richard 18f8a33a4e encrypt data using RC4 via SystemFunction032 (#825)
* RC4 encryption via Advapi32.SystemFunction032
2023-10-10 11:55:01 +02:00
Moritz 6d7191fac6 Update generate-random-numbers-via-rtlgenrandom.yml 2023-10-10 11:53:01 +02:00
Moritz e454699082 Update generate-random-numbers-via-rtlgenrandom.yml (#828) 2023-10-09 12:07:38 -06:00
Capa Bot 5e1ae7943d Update rules number badge 2023-10-09 18:01:04 +00:00
Moritz 0b6aeb7581 Create log-keystrokes-via-input-method-manager.yml (#834) 2023-10-09 12:00:50 -06:00
Capa Bot 8e2e86b54f Update rules number badge 2023-10-09 18:00:05 +00:00
JJ 23cfa23626 Merge execute-dotnet-assembly-via-clr-host.yml with load-windows-common-language-runtime.yml and promote load-windows-common-language-runtime.yml (#797) 2023-10-09 11:59:52 -06:00
Capa Bot 26180485da Update rules number badge 2023-10-09 16:29:59 +00:00
Mike Hunhoff 2a37df98f5 adding new rules based on private Linux sample(s) (#821)
* adding new rules based on private Linux sample(s)

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2023-10-09 18:27:33 +02:00
Moritz fcfb7ef55f Merge pull request #818 from mandiant/rules52-34
add `send SMS on Android`
2023-10-09 18:26:46 +02:00
Capa Bot a1e83cf147 Update rules number badge 2023-10-09 16:22:09 +00:00
Moritz 6f17b655f3 Merge pull request #810 from jtothej/sharppcap
Add capture-packets-using-sharppcap.yml
2023-10-09 18:21:55 +02:00
Capa Bot ff0f440ae6 Update rules number badge 2023-10-09 16:01:22 +00:00
Moritz 216b30ace8 Create capture-process-snapshot.yml (#833)
* Create capture-process-snapshot.yml
2023-10-09 18:01:04 +02:00
Capa Bot e0a4ef2163 Update rules number badge 2023-10-06 15:20:00 +00:00
johnk3r b33f95c9ca set state tcp connection (#829)
* Add rule

---------

Co-authored-by: Willi Ballenthin <wballenthin@google.com>
2023-10-06 17:19:47 +02:00
Willi Ballenthin 2d615e2386 Merge pull request #832 from MBCProject/9/2023-mbc-update
Update Mappings for MBC (part 11)
2023-09-27 22:40:22 +02:00
ryan 6fbf5187e5 Update Mappings for MBC (part 11) 2023-09-27 15:01:03 -04:00
Moritz b9c2bc120e Merge pull request #826 from mandiant/rules52-36
add xxProtectVirtualMemory apis
2023-09-13 16:45:26 +02:00
Moritz f971df9ab2 Update allocate-memory.yml 2023-09-09 19:22:13 +02:00
Aayush Goel 7e8dff9fa3 Merge branch 'mandiant:master' into Aayush-Goel-04/#Issue322-COMfeature 2023-09-06 16:41:32 +05:30
Capa Bot eba332e702 Update rules number badge 2023-09-05 13:01:50 +00:00
Moritz 955d7b75a3 Merge pull request #822 from mandiant/rules52-35
add `get ntoskrnl base address`
2023-09-05 15:01:37 +02:00
Willi Ballenthin d923cf4b8f Merge pull request #823 from yelhamer/dynamic-syntax-remaining-rules 2023-09-03 13:34:15 +02:00
Yacine Elhamer 9133f8e198 initial commit 2023-09-02 22:28:39 +02:00
mr-tz 45dbe8792e add rule 2023-09-02 18:47:56 +02:00
Aayush Goel b47c3a7be6 Update format.md 2023-08-30 01:02:00 +05:30
Willi Ballenthin 99aefcbae5 Merge pull request #820 from yelhamer/add-unspecified
Add `dynamic: unspecified` to static-only rules
2023-08-29 20:51:37 +02:00
Yacine Elhamer d20a7e0a48 add elaborative comment 2023-08-29 21:32:37 +02:00