Tarang
03a20f69ae
Split .NET features from windows file & process rules ( #1130 )
...
* remove .NET features
* create separate read-file-in-dotnet.yml
* remove .NET features
* create separate write-file-dotnet.yml
* split create process rule into windows & .NET
* change static scope to instruction
* change static scope to insn and add dotnet match
* change static & dynamic scope to insn & call and add dotnet match
* change static scope to insn
2026-03-12 11:41:24 -06:00
Mike Hunhoff
6221d9b72b
add more APIs to remove use-process-replacement FNs ( #1009 )
2025-02-25 08:59:09 -07:00
Mike Hunhoff
ff9db74425
update create-process-suspended to include DEBUG_ONLY_THIS_PROCESS ( #978 )
2025-01-07 13:02:37 -07:00
Mike Hunhoff
ea14b38fbf
adding / updating linux / android rules ( #907 )
...
* adding / updating linux / android rules
* update statement
* apply review feedback
* add additional android rules
* fix feedback
2024-06-11 12:10:57 -06:00
Mike Hunhoff
ded2744733
adding new and updating linux / android rules ( #903 )
...
* adding new and updating linux / android rules
* fix lints
2024-05-31 13:24:19 -04:00
mr-tz
f344af3327
add android OS where applicable
2024-04-23 13:49:05 +02:00
mr-tz
e18704545a
fix call/thread scopes manually
2023-11-24 11:35:00 +01:00
mr-tz
784c9dca53
upgrade rules using updated script
2023-11-24 11:34:28 +01:00
Anushka Virgaonkar
1fbee15a3c
Add dotnet rules having property features ( #601 )
2022-10-03 09:28:05 -06:00
Moritz
e88db21de4
fix: rule logic ( #592 )
...
* fix: rule logic
* fix: rule logic
2022-07-12 18:09:51 +02:00
Willi Ballenthin
57e1732f5c
Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
...
This reverts commit d43a6ee544 .
2022-06-28 15:23:20 -06:00
William Ballenthin
2d66aace99
*: add APIs used by .NET samples for basic interactions
2022-06-08 11:18:23 -06:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
William Ballenthin
d43a6ee544
Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
...
This reverts commit bc28847dd9 , reversing
changes made to 82308c4109 .
2022-04-27 06:23:36 -06:00
Willi Ballenthin
904bf3ef00
*: remove /x32 and /x64 flavors and use instruction scope
2022-04-05 12:25:14 -06:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
William Ballenthin
c0fa8a2318
linux: add examples
2021-08-26 17:48:20 -06:00
William Ballenthin
ea3ea14c22
minor reorg linux rules and logic
...
ref #442
2021-08-25 15:31:51 -06:00
Willi Ballenthin
6f582bd395
Merge pull request #442 from TcM1911/linux-rules
...
A set of rules for Linux ELFs
2021-08-25 14:33:25 -06:00
William Ballenthin
39e87e6cb4
execute-command: use better example
2021-08-18 14:45:48 -06:00
Joakim Kennedy
78fbf5f3c5
Fix linting errors
2021-08-05 15:35:27 +01:00
Joakim Kennedy
765e182553
A set of rules for Linux ELFs
2021-08-04 15:47:00 +01:00
Moritz Raabe
d81e757728
adding rules based on more PMA labs
2021-06-30 23:38:17 +02:00
William Ballenthin
913cebdb38
Merge branch 'master' into fix-1
2021-05-18 10:48:06 -06:00
William Ballenthin
6e501e8151
rules: convert inline comments to descriptions
...
closes #1
2021-05-18 10:45:41 -06:00
Moritz
c24ab23bc1
ATT&CK v9 updates ( #341 )
...
* update rules
* add example
* update namespace and move
* add rule
* remove HKCU
* update rules
* update rule
2021-05-06 20:06:24 +02:00
Moritz Raabe
77b737fcf0
rule tweaks based on PMA Lab 03-02.dll
...
see #296
2021-03-22 19:05:08 +01:00
Desiree Beck
c5d24c671a
added mbc mappings in the host-interaction namespace
2020-12-16 15:30:06 -05:00
William Ballenthin
54cfb05bd0
rules: address comments in #14
2020-06-26 17:45:56 -06:00
William Ballenthin
7b4f4d10fb
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9
rules: reorganize rule names, namespaces, and ATT&CK mappings
2020-06-21 17:25:43 -06:00