Willi Ballenthin
9cb8848b03
Merge branch 'master' into dynamic-syntax
2023-10-17 10:29:30 +00:00
Mike Hunhoff
2a37df98f5
adding new rules based on private Linux sample(s) ( #821 )
...
* adding new rules based on private Linux sample(s)
---------
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
2023-10-09 18:27:33 +02:00
Yacine Elhamer
5b73ddcd24
manual pass
2023-08-22 09:40:13 +02:00
Yacine Elhamer
0aea484e04
updated rules
2023-08-21 19:14:45 +02:00
Yacine Elhamer
c4cdd9bae7
fix improper scope for rules containing a subscope in and
2023-08-21 14:27:45 +02:00
Yacine Elhamer
a55d769da8
fix author quoting
2023-08-21 09:10:33 +02:00
Yacine Elhamer
8d851f3343
updated rules
2023-08-20 15:39:29 +02:00
Yacine Elhamer
850909bd82
update
2023-08-17 11:07:02 +02:00
Yacine Elhamer
e937af1ee6
initial commit
2023-08-17 10:41:11 +02:00
Anushka Virgaonkar
1fbee15a3c
Add dotnet rules having property features ( #601 )
2022-10-03 09:28:05 -06:00
Anushka Virgaonkar
dcc2e74c84
Update with dotnet capabilities ( #590 )
2022-07-07 15:22:39 -06:00
Anushka Virgaonkar
95dc5eb27f
Add new dotnet rules that capture capabilites typically found in backdoors. ( #579 )
2022-07-07 13:39:51 -06:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
William Ballenthin
f5c3bfaba7
consolidate host-interaction/sid to host-interaction-session
2021-06-08 11:17:38 -06:00
William Ballenthin
a4a08c6921
graduate "get token membership"
2021-06-08 11:17:25 -06:00
Andrew
fbafd732e7
Update rule metadata for rules written by @recvfrom
...
Mostly just changes @recvfrom to awillia2@cisco.com , but
also updates the descriptions in a few places to be
more precise (I don't think I initially realized that
`api` has function scope and is for API calls whereas
`import` has file level scope and is just for the import)
2021-06-06 23:30:34 -04:00
Andrew
8a513b280b
Add rules from Egregor ransomware DLL
2021-04-26 11:56:25 -04:00
Michael Hunhoff
40c64c8f27
fixes #248
2021-02-16 16:49:25 -07:00
William Ballenthin
f8a3de9367
update attack mappings
2021-01-02 11:46:20 -07:00
Michael Hunhoff
9320b70185
adding new rules for sample with MD5 hash 03B236B23B1EC37C663527C1F53AF3FE
2020-07-30 17:33:13 -06:00
William Ballenthin
54cfb05bd0
rules: address comments in #14
2020-06-26 17:45:56 -06:00
William Ballenthin
7b4f4d10fb
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9
rules: reorganize rule names, namespaces, and ATT&CK mappings
2020-06-21 17:25:43 -06:00