Commit Graph

53 Commits

Author SHA1 Message Date
Willi Ballenthin 9cb8848b03 Merge branch 'master' into dynamic-syntax 2023-10-17 10:29:30 +00:00
ryan 6fbf5187e5 Update Mappings for MBC (part 11) 2023-09-27 15:01:03 -04:00
Yacine Elhamer d20a7e0a48 add elaborative comment 2023-08-29 21:32:37 +02:00
Yacine Elhamer d5f05f4e88 initial commit 2023-08-29 21:23:55 +02:00
Yacine Elhamer 5b73ddcd24 manual pass 2023-08-22 09:40:13 +02:00
Yacine Elhamer 0aea484e04 updated rules 2023-08-21 19:14:45 +02:00
Yacine Elhamer 3a42318eae fix improper scope for rules containing a subscope in and 2023-08-21 14:33:12 +02:00
Yacine Elhamer c4cdd9bae7 fix improper scope for rules containing a subscope in and 2023-08-21 14:27:45 +02:00
Yacine Elhamer a55d769da8 fix author quoting 2023-08-21 09:10:33 +02:00
Yacine Elhamer 8d851f3343 updated rules 2023-08-20 15:39:29 +02:00
Still / Azaka 037ca83cb3 Improve browser stealer & add SQLite lib detection (#757)
* Improve regex for existing browser data gathering detection

- Fix erroneous regex capture
+ Add detections for cookies gathering
+ Add generic browser detection (some webkit browser for some reason uses the same chromium-based paths?)

Signed-off-by: Still Hsu <dev@stillu.cc>

* Add rudimentary sqlite db libs detection
- Typically used along with browser data collection

Signed-off-by: Still Hsu <dev@stillu.cc>

---------

Signed-off-by: Still Hsu <dev@stillu.cc>
2023-08-19 11:36:10 +02:00
Yacine Elhamer e937af1ee6 initial commit 2023-08-17 10:41:11 +02:00
JJ 82714cd7d0 Add resolve-function-by-brute-ratel-badger-hash.yml (#793)
* Add resolve-function-by-brute-ratel-badger-hash.yml
2023-07-12 12:12:42 +02:00
Still Hsu 80f1993388 Lint rule
Signed-off-by: Still Hsu <dev@stillu.cc>
2023-05-10 16:01:15 +08:00
Still Hsu 51a6a65f4a Add aPLib linking detection
Signed-off-by: Still Hsu <dev@stillu.cc>
2023-05-10 15:55:14 +08:00
Mike Hunhoff e5ae505682 update .NET detections (#703) 2023-02-21 14:38:03 -07:00
Moritz 106123eb61 Rules for the week (#671)
* add rules

* avoid FPs via mnemonics to ignore

* correct number logic

* add --onefile option strings
2023-01-27 09:56:12 +01:00
Willi Ballenthin 57e1732f5c Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
This reverts commit d43a6ee544.
2022-06-28 15:23:20 -06:00
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
William Ballenthin d43a6ee544 Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
This reverts commit bc28847dd9, reversing
changes made to 82308c4109.
2022-04-27 06:23:36 -06:00
Willi Ballenthin 904bf3ef00 *: remove /x32 and /x64 flavors and use instruction scope 2022-04-05 12:25:14 -06:00
jtothej 80c6804ec1 Add linked-against-wolfssl.yml and linked-against-wolfcrypt.yml 2021-12-03 15:44:58 +08:00
Ryan Xu 5b3c56ae44 Update linking/runtime-linking/resolve-function-by-fin8-fasthash.yml
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2021-11-24 11:52:41 -05:00
Ryan Xu 607a06e184 Adding changes suggested by Mandiant 2021-11-23 09:01:53 -05:00
Desiree Beck e190179ffd Merge pull request #1 from MBCProject/ryan-patches1
Update patch-process-command-line.yml
2021-11-22 11:27:15 -05:00
Moritz Raabe 25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
Ryan Xu 0114138ae4 More detailed mappings 2021-08-31 11:34:09 -05:00
William Ballenthin ea3ea14c22 minor reorg linux rules and logic
ref #442
2021-08-25 15:31:51 -06:00
Willi Ballenthin 6f582bd395 Merge pull request #442 from TcM1911/linux-rules
A set of rules for Linux ELFs
2021-08-25 14:33:25 -06:00
William Ballenthin 0ef69c4fbd *: use substring features rather than unreadable regexes
closes #450
2021-08-24 12:47:26 -06:00
Ryan Xu b4e040dc50 preliminary mapping 2021-08-23 14:11:00 -05:00
Joakim Kennedy 78fbf5f3c5 Fix linting errors 2021-08-05 15:35:27 +01:00
Joakim Kennedy 765e182553 A set of rules for Linux ELFs 2021-08-04 15:47:00 +01:00
Michael Hunhoff 64c8746098 adding additional detection strings to linked-against-openssl.yml 2021-07-28 15:00:29 -06:00
William Ballenthin 6e501e8151 rules: convert inline comments to descriptions
closes #1
2021-05-18 10:45:41 -06:00
Moritz Raabe aedf47d971 remove unneeded or, fix offset 2021-04-09 11:24:48 +02:00
Moritz Raabe 30db0cddb8 add rules from fboldewin
Co-authored-by: Frank Boldewin <frank.boldewin@gmx.de>
2021-04-09 11:24:47 +02:00
Michael Hunhoff 20e1b8fd4c enforce string formatting with double quotes + escaped special characters 2021-03-24 14:14:38 -06:00
Moritz Raabe 387334a603 reformated using capafmt 2021-01-27 15:30:59 +01:00
Desiree Beck 5c11fe70b2 mappings for linking namespace 2021-01-21 15:27:42 -05:00
Moritz Raabe 15911402d8 comms and shellcode technique rules 2020-12-15 21:49:18 +01:00
mike-hunhoff bcfbebc567 Merge pull request #100 from fireeye/init-al-khaser-rules 2020-08-27 10:07:58 -06:00
Willi Ballenthin c59913b22a Merge pull request #104 from fireeye/rules-8-27
add new rules
2020-08-27 07:52:15 -06:00
Moritz Raabe e995189224 add new rules 2020-08-27 10:38:59 +02:00
Michael Hunhoff a7c9192cc5 Merge branch 'master' into init-al-khaser-rules 2020-08-26 13:55:46 -06:00
0ssigeno 1ea6c4c38e number doesn't have inline comment 2020-08-20 10:34:16 +02:00
0ssigeno 8dd3821274 fixed key, and added x32 and x64 flavours 2020-08-20 10:22:00 +02:00
Michael Hunhoff 6ccc9a736f fresh rules from al-khaser project 2020-08-13 09:39:42 -06:00
Ana María Martínez Gómez 25f1157db0 Change characteristic syntax in rules
Get rid of `true` in characteristic as it is implicit.

The changes are the result of executing the following commands:
```
find . -type f -exec sed -i.bak "s/\(.*\)characteristic(\(.*\)): true/\1characteristic: \2/g" {} \;
find . -name "*.bak" -type f -delete
```
2020-07-01 19:19:49 +02:00
William Ballenthin 0d77564785 merge 2020-06-26 17:47:37 -06:00