Willi Ballenthin
|
88c9c786ca
|
*: use meta.authors everywhere
|
2022-05-26 11:56:31 -06:00 |
|
Moritz Raabe
|
25938ca10c
|
change to mandiant.com
|
2021-09-28 12:21:11 +02:00 |
|
William Ballenthin
|
a5721b1698
|
graduate "encode data using Base64 via WinAPI"
|
2021-06-04 12:21:34 -06:00 |
|
William Ballenthin
|
d32aa59842
|
graduate "decode data using Base64 via WinAPI"
|
2021-06-04 12:18:30 -06:00 |
|
drfuzzer
|
612cc74841
|
Added rule for Base64 decoding per 9efa86b43b4367bcdc1591aee59bda25 (#397)
* Added rule for Base64 decoding per 9efa86b43b4367bcdc1591aee59bda25
* Update data-manipulation/encoding/base64/decode-data-using-base64.yml
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
* Update data-manipulation/encoding/base64/decode-data-using-base64.yml
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
* updated file name
Co-authored-by: Gil Elliot <gilbert.elliot@10-h14cjg5m-33o.fireeye.com>
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2021-05-26 09:31:11 +02:00 |
|
William Ballenthin
|
6e501e8151
|
rules: convert inline comments to descriptions
closes #1
|
2021-05-18 10:45:41 -06:00 |
|
William Ballenthin
|
f1b450edf0
|
update ATT&CK and MBC mappings
thanks to Regina Elwell @ FireEye and @evandrix
closes #316
|
2021-04-13 09:37:10 -06:00 |
|
Michael Hunhoff
|
20e1b8fd4c
|
enforce string formatting with double quotes + escaped special characters
|
2021-03-24 14:14:38 -06:00 |
|
Desiree Beck
|
33817fdd83
|
update micro objective name: data manipulation to data
|
2020-12-12 12:18:47 -05:00 |
|
Desiree Beck
|
a0f10b4cf2
|
add mappings
|
2020-10-19 14:04:15 -04:00 |
|
William Ballenthin
|
54cfb05bd0
|
rules: address comments in #14
|
2020-06-26 17:45:56 -06:00 |
|
William Ballenthin
|
7b4f4d10fb
|
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
|
2020-06-21 17:54:01 -06:00 |
|
William Ballenthin
|
5f57dbdbc9
|
rules: reorganize rule names, namespaces, and ATT&CK mappings
|
2020-06-21 17:25:43 -06:00 |
|