31 Commits

Author SHA1 Message Date
Tarang 03a20f69ae Split .NET features from windows file & process rules (#1130)
* remove .NET features

* create separate read-file-in-dotnet.yml

* remove .NET features

* create separate write-file-dotnet.yml

* split create process rule into windows & .NET

* change static scope to instruction

* change static scope to insn and add dotnet match

* change static & dynamic scope to insn & call and add dotnet match

* change static scope to insn
2026-03-12 11:41:24 -06:00
Mike Hunhoff 6221d9b72b add more APIs to remove use-process-replacement FNs (#1009) 2025-02-25 08:59:09 -07:00
Mike Hunhoff ff9db74425 update create-process-suspended to include DEBUG_ONLY_THIS_PROCESS (#978) 2025-01-07 13:02:37 -07:00
Mike Hunhoff ea14b38fbf adding / updating linux / android rules (#907)
* adding / updating linux / android rules

* update statement

* apply review feedback

* add additional android rules

* fix feedback
2024-06-11 12:10:57 -06:00
Mike Hunhoff ded2744733 adding new and updating linux / android rules (#903)
* adding new and updating linux / android rules

* fix lints
2024-05-31 13:24:19 -04:00
mr-tz f344af3327 add android OS where applicable 2024-04-23 13:49:05 +02:00
mr-tz e18704545a fix call/thread scopes manually 2023-11-24 11:35:00 +01:00
mr-tz 784c9dca53 upgrade rules using updated script 2023-11-24 11:34:28 +01:00
Anushka Virgaonkar 1fbee15a3c Add dotnet rules having property features (#601) 2022-10-03 09:28:05 -06:00
Moritz e88db21de4 fix: rule logic (#592)
* fix: rule logic

* fix: rule logic
2022-07-12 18:09:51 +02:00
Willi Ballenthin 57e1732f5c Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
This reverts commit d43a6ee544.
2022-06-28 15:23:20 -06:00
William Ballenthin 2d66aace99 *: add APIs used by .NET samples for basic interactions 2022-06-08 11:18:23 -06:00
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
William Ballenthin d43a6ee544 Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
This reverts commit bc28847dd9, reversing
changes made to 82308c4109.
2022-04-27 06:23:36 -06:00
Willi Ballenthin 904bf3ef00 *: remove /x32 and /x64 flavors and use instruction scope 2022-04-05 12:25:14 -06:00
Moritz Raabe 25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
William Ballenthin c0fa8a2318 linux: add examples 2021-08-26 17:48:20 -06:00
William Ballenthin ea3ea14c22 minor reorg linux rules and logic
ref #442
2021-08-25 15:31:51 -06:00
Willi Ballenthin 6f582bd395 Merge pull request #442 from TcM1911/linux-rules
A set of rules for Linux ELFs
2021-08-25 14:33:25 -06:00
William Ballenthin 39e87e6cb4 execute-command: use better example 2021-08-18 14:45:48 -06:00
Joakim Kennedy 78fbf5f3c5 Fix linting errors 2021-08-05 15:35:27 +01:00
Joakim Kennedy 765e182553 A set of rules for Linux ELFs 2021-08-04 15:47:00 +01:00
Moritz Raabe d81e757728 adding rules based on more PMA labs 2021-06-30 23:38:17 +02:00
William Ballenthin 913cebdb38 Merge branch 'master' into fix-1 2021-05-18 10:48:06 -06:00
William Ballenthin 6e501e8151 rules: convert inline comments to descriptions
closes #1
2021-05-18 10:45:41 -06:00
Moritz c24ab23bc1 ATT&CK v9 updates (#341)
* update rules

* add example

* update namespace and move

* add rule

* remove HKCU

* update rules

* update rule
2021-05-06 20:06:24 +02:00
Moritz Raabe 77b737fcf0 rule tweaks based on PMA Lab 03-02.dll
see #296
2021-03-22 19:05:08 +01:00
Desiree Beck c5d24c671a added mbc mappings in the host-interaction namespace 2020-12-16 15:30:06 -05:00
William Ballenthin 54cfb05bd0 rules: address comments in #14 2020-06-26 17:45:56 -06:00
William Ballenthin 7b4f4d10fb rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better 2020-06-21 17:54:01 -06:00
William Ballenthin 5f57dbdbc9 rules: reorganize rule names, namespaces, and ATT&CK mappings 2020-06-21 17:25:43 -06:00