Commit Graph

50 Commits

Author SHA1 Message Date
Yacine Elhamer d20a7e0a48 add elaborative comment 2023-08-29 21:32:37 +02:00
Yacine Elhamer d5f05f4e88 initial commit 2023-08-29 21:23:55 +02:00
Yacine Elhamer 5b73ddcd24 manual pass 2023-08-22 09:40:13 +02:00
Yacine Elhamer 0aea484e04 updated rules 2023-08-21 19:14:45 +02:00
Yacine Elhamer c4cdd9bae7 fix improper scope for rules containing a subscope in and 2023-08-21 14:27:45 +02:00
Yacine Elhamer a55d769da8 fix author quoting 2023-08-21 09:10:33 +02:00
Yacine Elhamer 8d851f3343 updated rules 2023-08-20 15:39:29 +02:00
Yacine Elhamer e937af1ee6 initial commit 2023-08-17 10:41:11 +02:00
mr-tz 616fd90aac loosen locality of features 2023-04-25 21:06:39 +02:00
Moritz f81d04729a specify offset operand to reduce FPs (#716)
* specify offset operand to reduce FPs

* add instruction specifics
2023-03-01 16:08:17 +01:00
Moritz 761ccbab47 update ATT&CK/MBC meta data (#675)
* update ATT&CK/MBC meta data
2023-02-01 10:08:58 +01:00
Willi Ballenthin 9083a1950c linter 2022-06-28 15:30:57 -06:00
Willi Ballenthin 57e1732f5c Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
This reverts commit d43a6ee544.
2022-06-28 15:23:20 -06:00
Willi Ballenthin 7011634b0c Merge pull request #553 from sara-rn/master
added parse-pe-export-data rule
2022-06-28 14:26:17 -06:00
Willi Ballenthin 504a94444e resolve-function-by-parsing-pe-exports: fix linter suggestions 2022-06-28 14:25:11 -06:00
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
William Ballenthin d43a6ee544 Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
This reverts commit bc28847dd9, reversing
changes made to 82308c4109.
2022-04-27 06:23:36 -06:00
Willi Ballenthin 904bf3ef00 *: remove /x32 and /x64 flavors and use instruction scope 2022-04-05 12:25:14 -06:00
Baptistin Boilot efea9a37d9 Fix MBC names and IDs 2022-02-06 11:13:23 +01:00
Desiree Beck e190179ffd Merge pull request #1 from MBCProject/ryan-patches1
Update patch-process-command-line.yml
2021-11-22 11:27:15 -05:00
Ryan Xu 1cf2dbb47d Delete parse-pe-exports.yml 2021-11-22 11:26:06 -05:00
Ryan Xu 33cdd98446 Update rebuild-import-table.yml
Resolve comment
2021-11-12 08:56:54 -06:00
Ryan Xu 6a02bdae83 Update parse-pe-exports.yml
Resolve comment
2021-11-12 08:56:27 -06:00
Ryan Xu 7a80910739 Update inspect-section-memory-permissions.yml
Resolve comment
2021-11-12 08:55:39 -06:00
Ryan Xu 2cf204d959 Update enumerate-pe-sections.yml
Resolving comment
2021-11-12 08:55:07 -06:00
Willi Ballenthin 1116322059 Merge pull request #487 from mandiant/williballenthin-patch-4
Delete parse-pe-exports.yml
2021-10-27 09:27:13 -06:00
Willi Ballenthin fcdef7b105 Delete parse-pe-exports.yml
similar problem to the parse PE header when it relies on structure offsets: its very common to FP when dealing with structures of more than a few hundred bytes.
see #484
2021-10-26 16:28:01 -06:00
Willi Ballenthin ba5dbc40f3 parse PE header: be much more strict 2021-10-26 16:09:20 -06:00
William Ballenthin 8b8b584e2d injection: add ATT&CK Reflective Code Loading
closes #477
2021-10-22 12:43:30 -06:00
Moritz Raabe 25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
Moritz Raabe b2118b01df focus on os windows 2021-09-14 10:38:10 +02:00
Ryan Xu 0114138ae4 More detailed mappings 2021-08-31 11:34:09 -05:00
William Ballenthin f6b9564332 *: fix ntdll/ntoskrnl lints 2021-08-26 17:52:24 -06:00
Joakim Kennedy 5678afad06 Fix some FPs in ELF files by adding os requirement 2021-08-26 11:40:35 +01:00
Ryan Xu b4e040dc50 preliminary mapping 2021-08-23 14:11:00 -05:00
Moritz Raabe d81e757728 adding rules based on more PMA labs 2021-06-30 23:38:17 +02:00
William Ballenthin 6e501e8151 rules: convert inline comments to descriptions
closes #1
2021-05-18 10:45:41 -06:00
William Ballenthin 0f28d4a763 capafmt 2021-04-13 09:49:02 -06:00
William Ballenthin f1b450edf0 update ATT&CK and MBC mappings
thanks to Regina Elwell @ FireEye and @evandrix
closes #316
2021-04-13 09:37:10 -06:00
Ana Maria Martinez Gomez e0cefa438d update translate-characteristic-into-permission.yml
- rename it to `inspect section memory permissions` and add a
description so it is clear what it is meant.
- use the `3 or more` feature to improve the rule. Note that `optional`
doesn't behave as you may expect for this feature. Use `and` to ensure
`optional` behaves as we want.
2021-03-29 11:04:42 +02:00
Ana Maria Martinez Gomez e46c667bdb add translate-characteristic-into-permission.yml
Identify translation of PE characteristics into permissions. It could be
used in reflective dll injection to replicate the permissions of the
dll mapped in memory.
2021-03-25 19:37:39 +01:00
Ana Maria Martinez Gomez be2c552cff add load-code/pe/inject-dll-reflectively.yml
Identify reflective dll injection using `copy PE sections` and `rebuild
import table`.
References:
- https://0x00sec.org/t/reflective-dll-injection/3080
- https://www.ired.team/offensive-security/code-injection-process-injection/reflective-dll-injection
2021-03-25 19:37:29 +01:00
Ana Maria Martinez Gomez b7aa190381 add load-code/pe/parse-pe-exports.yml
Identify parsing PE export data, used when writing your own
`GetProcAddress()` implementation.

reference: Practical Malware Analysis, Chapter 19

f
2021-03-25 19:34:47 +01:00
Ana Maria Martinez Gomez 684f817111 add load-code/pe/rebuild-import-table.yml
Identify rebuilding of import table, used in reflective-dll-injection.
References:
- https://0x00sec.org/t/reflective-dll-injection/3080
- https://www.ired.team/offensive-security/code-injection-process-injection/reflective-dll-injection
2021-03-25 19:34:47 +01:00
Ana Maria Martinez Gomez 02915b3ade add load-code/pe/enumerate-pe-sections.yml
Identify copying of PE sections, used in reflective-dll-injection.
References:
- https://0x00sec.org/t/reflective-dll-injection/3080
- https://www.ired.team/offensive-security/code-injection-process-injection/reflective-dll-injection
2021-03-25 19:34:31 +01:00
Moritz Raabe 873ed713e8 rule updates based on PMA labs
see #296
2021-03-22 09:45:56 +01:00
Michael Hunhoff 750e164a41 removing ntdll requirement from function features exported by both ntdll and ntoskrnl 2021-02-16 18:28:05 -07:00
Moritz Raabe 30d6da2362 new rule and some tweaks 2020-10-06 18:28:38 +02:00
William Ballenthin 7b4f4d10fb rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better 2020-06-21 17:54:01 -06:00
William Ballenthin 5f57dbdbc9 rules: reorganize rule names, namespaces, and ATT&CK mappings 2020-06-21 17:25:43 -06:00