Willi Ballenthin
94de0355cd
Merge branch 'master' into dynamic-syntax
2023-10-19 09:15:29 +00:00
Willi Ballenthin
bc63b328dc
Merge pull request #817 from Aayush-Goel-04/Aayush-Goel-04/#Issue322-COMfeature
...
Documentation for COM feature addition
2023-10-18 17:01:01 +02:00
Willi Ballenthin
c88979a1bc
fmt
2023-10-17 12:28:12 +00:00
Willi Ballenthin
796b5b3a22
readd file
2023-10-17 11:40:57 +00:00
Willi Ballenthin
05ee3df679
update scope syntax
2023-10-17 11:34:31 +00:00
Willi Ballenthin
9cb8848b03
Merge branch 'master' into dynamic-syntax
2023-10-17 10:29:30 +00:00
Capa Bot
8f806bbf6c
Update rules number badge
2023-10-16 14:52:27 +00:00
Moritz
210b86f89e
Merge pull request #836 from mandiant/update-alloc-rules
...
Update and refactor memory allocation/permission rules
2023-10-16 16:51:18 +02:00
Capa Bot
c67c2ffda2
Update rules number badge
2023-10-12 09:01:10 +00:00
Ana María Martínez Gómez
2626fc680c
Add enumerate-blocking-processes.yml ( #705 )
...
* Add enumerate-blocking-processes.yml
The AVOSLOCKER ransomware uses the APIs `RmRegisterResources` and
`RmGetList` to get a list of processes blocking the file to encrypt and
stop them.
---------
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
Co-authored-by: Willi Ballenthin <wballenthin@google.com >
2023-10-12 11:00:56 +02:00
Moritz
b778d25292
Update allocate-memory.yml
2023-10-11 12:08:01 +02:00
Moritz
a39a2c0b52
Merge branch 'master' into update-alloc-rules
2023-10-11 12:03:42 +02:00
mr-tz
1be6720131
add runtime resolved functions
2023-10-11 11:54:50 +02:00
mr-tz
7ddf609ebc
update example
2023-10-11 11:33:20 +02:00
mr-tz
66f58dffa0
update match rule name
2023-10-11 11:20:23 +02:00
mr-tz
5f223ea5ce
rename rules
2023-10-11 11:17:13 +02:00
mr-tz
ed791c9b17
separate allocate and change memory protection
2023-10-11 11:14:14 +02:00
Capa Bot
54e3a1d3dd
Update rules number badge
2023-10-10 13:34:30 +00:00
Moritz
773c75c934
Create add-value-to-global-atom-table.yml ( #831 )
...
* Create add-value-to-global-atom-table.yml
2023-10-10 15:34:15 +02:00
Moritz
330d0f9612
Merge pull request #835 from mandiant/mr-tz-patch-1
...
Update generate-random-numbers-via-rtlgenrandom.yml
2023-10-10 12:09:10 +02:00
Capa Bot
5f579460f5
Update rules number badge
2023-10-10 09:55:15 +00:00
Richard
18f8a33a4e
encrypt data using RC4 via SystemFunction032 ( #825 )
...
* RC4 encryption via Advapi32.SystemFunction032
2023-10-10 11:55:01 +02:00
Moritz
6d7191fac6
Update generate-random-numbers-via-rtlgenrandom.yml
2023-10-10 11:53:01 +02:00
Moritz
e454699082
Update generate-random-numbers-via-rtlgenrandom.yml ( #828 )
2023-10-09 12:07:38 -06:00
Capa Bot
5e1ae7943d
Update rules number badge
2023-10-09 18:01:04 +00:00
Moritz
0b6aeb7581
Create log-keystrokes-via-input-method-manager.yml ( #834 )
2023-10-09 12:00:50 -06:00
Capa Bot
8e2e86b54f
Update rules number badge
2023-10-09 18:00:05 +00:00
JJ
23cfa23626
Merge execute-dotnet-assembly-via-clr-host.yml with load-windows-common-language-runtime.yml and promote load-windows-common-language-runtime.yml ( #797 )
2023-10-09 11:59:52 -06:00
Capa Bot
26180485da
Update rules number badge
2023-10-09 16:29:59 +00:00
Mike Hunhoff
2a37df98f5
adding new rules based on private Linux sample(s) ( #821 )
...
* adding new rules based on private Linux sample(s)
---------
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
2023-10-09 18:27:33 +02:00
Moritz
fcfb7ef55f
Merge pull request #818 from mandiant/rules52-34
...
add `send SMS on Android`
2023-10-09 18:26:46 +02:00
Capa Bot
a1e83cf147
Update rules number badge
2023-10-09 16:22:09 +00:00
Moritz
6f17b655f3
Merge pull request #810 from jtothej/sharppcap
...
Add capture-packets-using-sharppcap.yml
2023-10-09 18:21:55 +02:00
Capa Bot
ff0f440ae6
Update rules number badge
2023-10-09 16:01:22 +00:00
Moritz
216b30ace8
Create capture-process-snapshot.yml ( #833 )
...
* Create capture-process-snapshot.yml
2023-10-09 18:01:04 +02:00
Capa Bot
e0a4ef2163
Update rules number badge
2023-10-06 15:20:00 +00:00
johnk3r
b33f95c9ca
set state tcp connection ( #829 )
...
* Add rule
---------
Co-authored-by: Willi Ballenthin <wballenthin@google.com >
2023-10-06 17:19:47 +02:00
Willi Ballenthin
2d615e2386
Merge pull request #832 from MBCProject/9/2023-mbc-update
...
Update Mappings for MBC (part 11)
2023-09-27 22:40:22 +02:00
ryan
6fbf5187e5
Update Mappings for MBC (part 11)
2023-09-27 15:01:03 -04:00
Moritz
b9c2bc120e
Merge pull request #826 from mandiant/rules52-36
...
add xxProtectVirtualMemory apis
2023-09-13 16:45:26 +02:00
Moritz
f971df9ab2
Update allocate-memory.yml
2023-09-09 19:22:13 +02:00
Aayush Goel
7e8dff9fa3
Merge branch 'mandiant:master' into Aayush-Goel-04/#Issue322-COMfeature
2023-09-06 16:41:32 +05:30
Capa Bot
eba332e702
Update rules number badge
2023-09-05 13:01:50 +00:00
Moritz
955d7b75a3
Merge pull request #822 from mandiant/rules52-35
...
add `get ntoskrnl base address`
2023-09-05 15:01:37 +02:00
Willi Ballenthin
d923cf4b8f
Merge pull request #823 from yelhamer/dynamic-syntax-remaining-rules
2023-09-03 13:34:15 +02:00
Yacine Elhamer
9133f8e198
initial commit
2023-09-02 22:28:39 +02:00
mr-tz
45dbe8792e
add rule
2023-09-02 18:47:56 +02:00
Aayush Goel
b47c3a7be6
Update format.md
2023-08-30 01:02:00 +05:30
Willi Ballenthin
99aefcbae5
Merge pull request #820 from yelhamer/add-unspecified
...
Add `dynamic: unspecified` to static-only rules
2023-08-29 20:51:37 +02:00
Yacine Elhamer
d20a7e0a48
add elaborative comment
2023-08-29 21:32:37 +02:00