Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
William Ballenthin
d43a6ee544
Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
...
This reverts commit bc28847dd9 , reversing
changes made to 82308c4109 .
2022-04-27 06:23:36 -06:00
Willi Ballenthin
904bf3ef00
*: remove /x32 and /x64 flavors and use instruction scope
2022-04-05 12:25:14 -06:00
jtothej
80c6804ec1
Add linked-against-wolfssl.yml and linked-against-wolfcrypt.yml
2021-12-03 15:44:58 +08:00
Ryan Xu
5b3c56ae44
Update linking/runtime-linking/resolve-function-by-fin8-fasthash.yml
...
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
2021-11-24 11:52:41 -05:00
Ryan Xu
607a06e184
Adding changes suggested by Mandiant
2021-11-23 09:01:53 -05:00
Desiree Beck
e190179ffd
Merge pull request #1 from MBCProject/ryan-patches1
...
Update patch-process-command-line.yml
2021-11-22 11:27:15 -05:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
Ryan Xu
0114138ae4
More detailed mappings
2021-08-31 11:34:09 -05:00
William Ballenthin
ea3ea14c22
minor reorg linux rules and logic
...
ref #442
2021-08-25 15:31:51 -06:00
Willi Ballenthin
6f582bd395
Merge pull request #442 from TcM1911/linux-rules
...
A set of rules for Linux ELFs
2021-08-25 14:33:25 -06:00
William Ballenthin
0ef69c4fbd
*: use substring features rather than unreadable regexes
...
closes #450
2021-08-24 12:47:26 -06:00
Ryan Xu
b4e040dc50
preliminary mapping
2021-08-23 14:11:00 -05:00
Joakim Kennedy
78fbf5f3c5
Fix linting errors
2021-08-05 15:35:27 +01:00
Joakim Kennedy
765e182553
A set of rules for Linux ELFs
2021-08-04 15:47:00 +01:00
Michael Hunhoff
64c8746098
adding additional detection strings to linked-against-openssl.yml
2021-07-28 15:00:29 -06:00
William Ballenthin
6e501e8151
rules: convert inline comments to descriptions
...
closes #1
2021-05-18 10:45:41 -06:00
Moritz Raabe
aedf47d971
remove unneeded or, fix offset
2021-04-09 11:24:48 +02:00
Moritz Raabe
30db0cddb8
add rules from fboldewin
...
Co-authored-by: Frank Boldewin <frank.boldewin@gmx.de >
2021-04-09 11:24:47 +02:00
Michael Hunhoff
20e1b8fd4c
enforce string formatting with double quotes + escaped special characters
2021-03-24 14:14:38 -06:00
Moritz Raabe
387334a603
reformated using capafmt
2021-01-27 15:30:59 +01:00
Desiree Beck
5c11fe70b2
mappings for linking namespace
2021-01-21 15:27:42 -05:00
Moritz Raabe
15911402d8
comms and shellcode technique rules
2020-12-15 21:49:18 +01:00
mike-hunhoff
bcfbebc567
Merge pull request #100 from fireeye/init-al-khaser-rules
2020-08-27 10:07:58 -06:00
Willi Ballenthin
c59913b22a
Merge pull request #104 from fireeye/rules-8-27
...
add new rules
2020-08-27 07:52:15 -06:00
Moritz Raabe
e995189224
add new rules
2020-08-27 10:38:59 +02:00
Michael Hunhoff
a7c9192cc5
Merge branch 'master' into init-al-khaser-rules
2020-08-26 13:55:46 -06:00
0ssigeno
1ea6c4c38e
number doesn't have inline comment
2020-08-20 10:34:16 +02:00
0ssigeno
8dd3821274
fixed key, and added x32 and x64 flavours
2020-08-20 10:22:00 +02:00
Michael Hunhoff
6ccc9a736f
fresh rules from al-khaser project
2020-08-13 09:39:42 -06:00
Ana María Martínez Gómez
25f1157db0
Change characteristic syntax in rules
...
Get rid of `true` in characteristic as it is implicit.
The changes are the result of executing the following commands:
```
find . -type f -exec sed -i.bak "s/\(.*\)characteristic(\(.*\)): true/\1characteristic: \2/g" {} \;
find . -name "*.bak" -type f -delete
```
2020-07-01 19:19:49 +02:00
William Ballenthin
0d77564785
merge
2020-06-26 17:47:37 -06:00
William Ballenthin
54cfb05bd0
rules: address comments in #14
2020-06-26 17:45:56 -06:00
William Ballenthin
7b4f4d10fb
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9
rules: reorganize rule names, namespaces, and ATT&CK mappings
2020-06-21 17:25:43 -06:00