* new rules and updates
* fix issues with ci
* rename for accurate macro
* update description and logic
* new wbadmin rule and fix pwsh dataset
* more updates for the weekend
* update network rules filters
* downgrade versions
* Update windows_file_transfer_protocol_in_non_common_process_path.yml
* add missing DS for some rules
* update nirsoft lookup and add new rules
* update more nirsoft stuff
* update snort message
* Update cisco_secure_firewall_filetype_lookup.yml
* new analytic and updates / incl. fix#3730
* Update detect_new_local_admin_account.yml
* add lnx dataset and fix wildcards
Adds new detections and story for ZDI-CAN-25373 Windows shortcut zero-day vulnerability:
- Windows SSH ProxyCommand abuse detection
- Windows Explorer LNK exploit with padding detection
- Windows Explorer spawning PowerShell/CMD detection
- Analytic story covering APT campaigns exploiting this vulnerability
Thank you to AJ and Hunter (Community) for the assist!