Willi Ballenthin
|
c1d20764ad
|
use "span of calls" scope (#973)
* use sequence scope instead of thread scope for "static: function" rules
* use sequence scope instead of thread scope for "static: basic block" rules
* make runtime linking rules more concise
* doc: describe sequence scope
* rename "sequence" scope to "span of calls" scope
* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/get-geographical-location.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/file-managers/gather-classicftp-information.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/database/wmi/reference-wmi-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/database/sql/reference-sql-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
---------
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
|
2025-01-29 10:27:13 +01:00 |
|
mr-tz
|
8a36231025
|
fix scopes for rules with subscopes 2
|
2023-11-24 11:35:03 +01:00 |
|
mr-tz
|
784c9dca53
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
Anushka Virgaonkar
|
1fbee15a3c
|
Add dotnet rules having property features (#601)
|
2022-10-03 09:28:05 -06:00 |
|
Willi Ballenthin
|
88c9c786ca
|
*: use meta.authors everywhere
|
2022-05-26 11:56:31 -06:00 |
|
Moritz Raabe
|
25938ca10c
|
change to mandiant.com
|
2021-09-28 12:21:11 +02:00 |
|
Moritz Raabe
|
d81e757728
|
adding rules based on more PMA labs
|
2021-06-30 23:38:17 +02:00 |
|
William Ballenthin
|
7b4f4d10fb
|
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
|
2020-06-21 17:54:01 -06:00 |
|
William Ballenthin
|
5f57dbdbc9
|
rules: reorganize rule names, namespaces, and ATT&CK mappings
|
2020-06-21 17:25:43 -06:00 |
|