From 25938ca10c374cb34cffea0ece3c33eddc10a20d Mon Sep 17 00:00:00 2001 From: Moritz Raabe Date: Tue, 28 Sep 2021 12:21:11 +0200 Subject: [PATCH] change to mandiant.com --- .../debugger-detection/check-for-debugger-via-api.yml | 2 +- .../debugger-detection/check-for-hardware-breakpoints.yml | 2 +- ...eck-for-kernel-debugger-via-shared-user-data-structure.yml | 2 +- .../debugger-detection/check-for-outputdebugstring-error.yml | 2 +- .../debugger-detection/check-for-peb-beingdebugged-flag.yml | 2 +- .../debugger-detection/check-for-peb-ntglobalflag-flag.yml | 2 +- .../check-for-protected-handle-exception.yml | 2 +- .../debugger-detection/check-for-software-breakpoints.yml | 2 +- .../check-for-time-delay-via-gettickcount.yml | 2 +- .../check-for-time-delay-via-queryperformancecounter.yml | 2 +- .../debugger-detection/check-for-trap-flag-exception.yml | 2 +- .../debugger-detection/check-for-unexpected-memory-writes.yml | 2 +- .../debugger-detection/check-process-job-object.yml | 2 +- .../debugger-detection/check-processdebugport.yml | 2 +- .../execute-anti-debugging-instructions.yml | 2 +- anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml | 2 +- .../anti-forensic/clear-logs/clear-the-windows-event-log.yml | 2 +- .../anti-forensic/crash-the-windows-event-logging-service.yml | 2 +- anti-analysis/anti-forensic/patch-process-command-line.yml | 2 +- anti-analysis/anti-forensic/self-deletion/self-delete.yml | 2 +- anti-analysis/anti-forensic/timestomp/timestomp-file.yml | 2 +- .../anti-vm/vm-detection/execute-anti-vm-instructions.yml | 2 +- .../reference-anti-vm-strings-targeting-parallels.yml | 2 +- .../vm-detection/reference-anti-vm-strings-targeting-qemu.yml | 2 +- .../reference-anti-vm-strings-targeting-virtualbox.yml | 2 +- .../reference-anti-vm-strings-targeting-virtualpc.yml | 2 +- .../reference-anti-vm-strings-targeting-vmware.yml | 2 +- .../vm-detection/reference-anti-vm-strings-targeting-xen.yml | 2 +- .../anti-vm/vm-detection/reference-anti-vm-strings.yml | 2 +- .../string/stackstring/contain-obfuscated-stackstrings.yml | 2 +- anti-analysis/packer/amber/packed-with-amber.yml | 2 +- anti-analysis/packer/aspack/packed-with-aspack.yml | 2 +- anti-analysis/packer/confuser/packed-with-confuser.yml | 2 +- anti-analysis/packer/generic/packed-with-generic-packer.yml | 2 +- anti-analysis/packer/gopacker/packed-with-gopacker.yml | 2 +- anti-analysis/packer/pecompact/packed-with-pecompact.yml | 2 +- anti-analysis/packer/upx/packed-with-upx.yml | 2 +- anti-analysis/packer/vmprotect/packed-with-vmprotect.yml | 2 +- anti-analysis/reference-analysis-tools-strings.yml | 2 +- c2/file-transfer/download-and-write-a-file.yml | 2 +- c2/file-transfer/write-and-execute-a-file.yml | 2 +- c2/shell/create-reverse-shell.yml | 2 +- c2/shell/execute-shell-command-and-capture-output.yml | 2 +- .../acquire-credentials-from-windows-credential-manager.yml | 2 +- collection/database/sql/reference-sql-statements.yml | 2 +- collection/database/wmi/reference-wmi-statements.yml | 2 +- collection/keylog/log-keystrokes-via-application-hook.yml | 2 +- collection/keylog/log-keystrokes-via-polling.yml | 2 +- collection/keylog/log-keystrokes.yml | 2 +- collection/network/get-mac-address-on-windows.yml | 2 +- collection/screenshot/capture-screenshot.yml | 4 ++-- communication/ftp/send/send-file-using-ftp-via-wininet.yml | 2 +- communication/http/client/connect-to-http-server.yml | 2 +- communication/http/client/connect-to-url.yml | 2 +- communication/http/client/create-http-request.yml | 2 +- .../decompress-http-response-via-iencodingfilterfactory.yml | 2 +- communication/http/client/download-url-to-file.yml | 2 +- communication/http/client/extract-http-body.yml | 2 +- .../http/client/get-http-document-via-iwebbrowser2.yml | 2 +- .../http/client/get-http-response-content-encoding.yml | 2 +- communication/http/client/prepare-http-request.yml | 2 +- communication/http/client/read-data-from-internet.yml | 2 +- communication/http/client/receive-http-response.yml | 2 +- communication/http/client/send-file-via-http.yml | 2 +- communication/http/client/send-http-request.yml | 2 +- communication/http/initialize-iwebbrowser2.yml | 2 +- communication/http/initialize-winhttp-library.yml | 2 +- communication/http/read-http-header.yml | 2 +- communication/http/server/receive-http-request.yml | 2 +- communication/http/server/send-http-response.yml | 2 +- communication/http/server/start-http-server.yml | 2 +- communication/http/set-http-header.yml | 2 +- communication/icmp/send-icmp-echo-request.yml | 2 +- communication/named-pipe/connect/connect-pipe.yml | 4 ++-- communication/named-pipe/create/create-pipe.yml | 2 +- .../named-pipe/create/create-two-anonymous-pipes.yml | 2 +- communication/named-pipe/read/read-pipe.yml | 4 ++-- communication/named-pipe/write/write-pipe.yml | 4 ++-- communication/receive-data.yml | 2 +- communication/send-data.yml | 2 +- communication/socket/get-socket-status.yml | 2 +- communication/socket/initialize-winsock-library.yml | 2 +- communication/socket/receive/receive-data-on-socket.yml | 2 +- communication/socket/send/send-data-on-socket.yml | 2 +- communication/socket/set-socket-configuration.yml | 2 +- communication/socket/tcp/connect-tcp-socket.yml | 2 +- communication/socket/tcp/create-tcp-socket.yml | 2 +- communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml | 2 +- communication/socket/udp/send/create-udp-socket.yml | 2 +- communication/tcp/client/act-as-tcp-client.yml | 2 +- communication/tcp/serve/start-tcp-server.yml | 2 +- compiler/autoit/compiled-with-autoit.yml | 2 +- compiler/delphi/compiled-with-borland-delphi.yml | 2 +- compiler/go/compiled-with-go.yml | 2 +- compiler/mingw/compiled-with-mingw-for-windows.yml | 2 +- compiler/nim/compiled-with-nim.yml | 2 +- .../checksum/adler32/compute-adler32-checksum.yml | 2 +- data-manipulation/checksum/crc32/hash-data-with-crc32.yml | 2 +- data-manipulation/compression/compress-data-via-winapi.yml | 2 +- data-manipulation/compression/decompress-data-using-aplib.yml | 2 +- .../decompress-data-via-iencodingfilterfactory.yml | 2 +- .../decode-data-using-base64-via-dword-translation-table.yml | 2 +- .../encoding/base64/decode-data-using-base64-via-winapi.yml | 2 +- .../encoding/base64/encode-data-using-base64-via-winapi.yml | 2 +- .../encoding/base64/encode-data-using-base64.yml | 2 +- data-manipulation/encoding/base64/reference-base64-string.yml | 2 +- data-manipulation/encoding/xor/encode-data-using-xor.yml | 2 +- .../aes/decrypt-data-using-aes-via-x86-extensions.yml | 2 +- .../encryption/aes/encrypt-data-using-aes-via-net.yml | 2 +- .../encryption/aes/encrypt-data-using-aes-via-winapi.yml | 2 +- .../encryption/create-new-key-via-cryptacquirecontext.yml | 2 +- .../encryption/dpapi/encrypt-data-using-dpapi.yml | 2 +- .../elliptic-curve/encrypt-data-using-curve25519.yml | 2 +- .../encryption/encrypt-or-decrypt-via-wincrypt.yml | 2 +- .../get-outbound-credentials-handle-via-credssp.yml | 2 +- data-manipulation/encryption/import-public-key.yml | 2 +- .../encryption/rc4/encrypt-data-using-rc4-ksa.yml | 2 +- .../encryption/rc4/encrypt-data-using-rc4-prga.yml | 2 +- .../encryption/rc4/encrypt-data-using-rc4-via-winapi.yml | 2 +- data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml | 2 +- data-manipulation/encryption/rsa/reference-public-rsa-key.yml | 2 +- data-manipulation/hashing/fnv/hash-data-using-fnv.yml | 4 ++-- data-manipulation/hashing/hash-data-via-wincrypt.yml | 2 +- data-manipulation/hashing/md5/hash-data-with-md5.yml | 2 +- data-manipulation/hashing/murmur/hash-data-using-murmur3.yml | 2 +- data-manipulation/hashing/sha1/hash-data-using-sha1.yml | 2 +- data-manipulation/hashing/sha224/hash-data-using-sha224.yml | 2 +- data-manipulation/hashing/sha256/hash-data-using-sha256.yml | 2 +- data-manipulation/hmac/authenticate-hmac.yml | 2 +- data-manipulation/prng/generate-random-numbers-via-winapi.yml | 2 +- .../generate-random-numbers-using-a-mersenne-twister.yml | 2 +- executable/pe/pdb/contains-pdb-path.yml | 2 +- .../pe/section/rsrc/contain-a-resource-rsrc-section.yml | 2 +- .../tls/contain-a-thread-local-storage-tls-section.yml | 2 +- .../resource/extract-resource-via-kernel32-functions.yml | 2 +- executable/subfile/pe/contain-an-embedded-pe-file.yml | 2 +- host-interaction/bootloader/disable-code-signing.yml | 2 +- host-interaction/bootloader/manipulate-boot-configuration.yml | 2 +- host-interaction/cli/accept-command-line-arguments.yml | 2 +- host-interaction/clipboard/open-clipboard.yml | 2 +- host-interaction/clipboard/read-clipboard-data.yml | 2 +- host-interaction/clipboard/replace-clipboard-data.yml | 2 +- host-interaction/clipboard/write-clipboard-data.yml | 2 +- host-interaction/console/manipulate-console.yml | 2 +- host-interaction/driver/disable-driver-code-integrity.yml | 2 +- host-interaction/driver/install-driver.yml | 2 +- .../driver/interact-with-driver-via-control-codes.yml | 2 +- .../environment-variable/get-comspec-environment-variable.yml | 2 +- .../environment-variable/query-environment-variable.yml | 2 +- .../environment-variable/set-environment-variable.yml | 2 +- host-interaction/file-system/bypass-mark-of-the-web.yml | 2 +- host-interaction/file-system/copy/copy-file.yml | 2 +- host-interaction/file-system/create/create-directory.yml | 2 +- host-interaction/file-system/delete/delete-directory.yml | 2 +- host-interaction/file-system/delete/delete-file.yml | 2 +- host-interaction/file-system/exists/check-if-file-exists.yml | 2 +- .../file-system/files/list/enumerate-files-on-linux.yml | 2 +- .../files/list/enumerate-files-via-kernel32-functions.yml | 2 +- .../files/list/enumerate-files-via-ntdll-functions.yml | 2 +- host-interaction/file-system/get-common-file-path.yml | 2 +- .../file-system/get-file-system-object-information.yml | 2 +- host-interaction/file-system/get-program-files-directory.yml | 2 +- host-interaction/file-system/meta/get-file-attributes.yml | 2 +- host-interaction/file-system/meta/get-file-size.yml | 2 +- host-interaction/file-system/meta/get-file-version-info.yml | 2 +- host-interaction/file-system/meta/set-file-attributes.yml | 4 ++-- host-interaction/file-system/move/move-file.yml | 2 +- host-interaction/file-system/read/read-file-on-windows.yml | 2 +- host-interaction/file-system/read/read-file-via-mapping.yml | 2 +- host-interaction/file-system/read/read-ini-file.yml | 2 +- .../bypass-windows-file-protection.yml | 2 +- host-interaction/file-system/write/write-file-on-windows.yml | 2 +- host-interaction/filter/register-minifilter-driver.yml | 2 +- host-interaction/filter/start-minifilter-driver.yml | 2 +- .../modify/access-firewall-settings-via-inetfwmgr.yml | 2 +- host-interaction/gui/console/set-console-window-title.yml | 2 +- host-interaction/gui/session/lock/lock-the-desktop.yml | 2 +- host-interaction/gui/set-application-hook.yml | 2 +- host-interaction/gui/taskbar/find/find-taskbar.yml | 2 +- .../gui/taskbar/hide/hide-the-windows-taskbar.yml | 2 +- host-interaction/gui/window/find/find-graphical-window.yml | 2 +- .../gui/window/get-text/get-graphical-window-text.yml | 2 +- host-interaction/gui/window/hide/hide-graphical-window.yml | 2 +- host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml | 2 +- host-interaction/hardware/cpu/get-cpu-information.yml | 2 +- .../hardware/cpu/get-number-of-processor-cores.yml | 2 +- host-interaction/hardware/cpu/get-number-of-processors.yml | 2 +- .../hardware/keyboard/layout/get-keyboard-layout.yml | 2 +- host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml | 2 +- host-interaction/hardware/memory/get-memory-capacity.yml | 2 +- host-interaction/hardware/mouse/swap-mouse-buttons.yml | 2 +- .../hardware/storage/enumerate-disk-properties.yml | 2 +- host-interaction/hardware/storage/get-disk-information.yml | 2 +- host-interaction/hardware/storage/get-disk-size.yml | 2 +- .../log/debug/write-event/print-debug-messages.yml | 2 +- .../log/winevt/access/access-the-windows-event-log.yml | 2 +- host-interaction/mutex/check-mutex-and-exit.yml | 2 +- host-interaction/mutex/check-mutex.yml | 2 +- host-interaction/mutex/create-mutex.yml | 2 +- host-interaction/network/address/get-local-ipv4-addresses.yml | 2 +- .../connectivity/check-internet-connectivity-via-wininet.yml | 4 ++-- host-interaction/network/dns/resolve/resolve-dns.yml | 2 +- .../network/interface/get-networking-interfaces.yml | 2 +- .../network/traffic/copy/copy-network-traffic.yml | 2 +- .../traffic/filter/register-network-filter-via-wfp-api.yml | 2 +- host-interaction/os/hostname/get-hostname.yml | 2 +- .../os/info/get-system-information-on-windows.yml | 2 +- host-interaction/os/shutdown-system.yml | 2 +- host-interaction/os/version/check-os-version.yml | 2 +- host-interaction/process/allocate-thread-local-storage.yml | 2 +- .../create-a-process-with-modified-io-handles-and-window.yml | 2 +- host-interaction/process/create/create-process-on-windows.yml | 2 +- host-interaction/process/create/create-process-suspended.yml | 2 +- .../process/dump/create-process-memory-minidump.yml | 2 +- host-interaction/process/get-process-heap-flags.yml | 2 +- host-interaction/process/get-process-heap-force-flags.yml | 2 +- host-interaction/process/inject/allocate-rwx-memory.yml | 2 +- .../process/inject/allocate-user-process-rwx-memory.yml | 2 +- .../process/inject/attach-user-process-memory.yml | 2 +- host-interaction/process/inject/free-user-process-memory.yml | 2 +- host-interaction/process/inject/inject-apc.yml | 2 +- host-interaction/process/inject/inject-thread.yml | 2 +- host-interaction/process/inject/use-process-doppelgänging.yml | 2 +- host-interaction/process/inject/use-process-replacement.yml | 2 +- .../enumerate-processes-on-remote-desktop-session-host.yml | 2 +- host-interaction/process/list/enumerate-processes.yml | 2 +- host-interaction/process/list/find-process-by-pid.yml | 2 +- host-interaction/process/list/get-explorer-pid.yml | 2 +- host-interaction/process/modify/acquire-debug-privileges.yml | 2 +- host-interaction/process/modify/modify-access-privileges.yml | 2 +- .../process/modules/list/enumerate-process-modules.yml | 2 +- host-interaction/process/set-thread-local-storage-value.yml | 2 +- host-interaction/process/terminate/terminate-process.yml | 2 +- host-interaction/registry/create-or-open-registry-key.yml | 2 +- host-interaction/registry/create/set-registry-value.yml | 4 ++-- host-interaction/registry/delete/delete-registry-key.yml | 4 ++-- host-interaction/registry/delete/delete-registry-value.yml | 2 +- host-interaction/registry/query-or-enumerate-registry-key.yml | 2 +- .../registry/query-or-enumerate-registry-value.yml | 4 ++-- host-interaction/service/create/create-service.yml | 2 +- host-interaction/service/delete/delete-service.yml | 2 +- host-interaction/service/list/enumerate-services.yml | 2 +- host-interaction/service/modify/modify-service.yml | 2 +- host-interaction/service/query-service-status.yml | 2 +- host-interaction/service/run-as-service.yml | 4 ++-- host-interaction/service/start/start-service.yml | 2 +- host-interaction/service/stop/stop-service.yml | 2 +- host-interaction/session/get-session-integrity-level.yml | 2 +- host-interaction/session/get-session-user-name.yml | 2 +- host-interaction/session/get-token-membership.yml | 2 +- host-interaction/session/get-user-security-identifier.yml | 2 +- host-interaction/thread/create/create-thread.yml | 4 ++-- host-interaction/thread/list/enumerate-threads.yml | 2 +- host-interaction/thread/terminate/terminate-thread.yml | 4 ++-- host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml | 2 +- host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml | 2 +- .../uac/bypass/bypass-uac-via-token-manipulation.yml | 2 +- .../wmi/connect-to-wmi-namespace-via-wbemlocator.yml | 2 +- .../inhibit-system-recovery/delete-volume-shadow-copies.yml | 2 +- .../wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml | 2 +- internal/limitation/file/internal-autoit-file-limitation.yml | 2 +- internal/limitation/file/internal-dotnet-file-limitation.yml | 2 +- .../limitation/file/internal-installer-file-limitation.yml | 2 +- internal/limitation/file/internal-packer-file-limitation.yml | 2 +- lib/calculate-modulo-256-via-x86-assembly.yml | 2 +- lib/contain-loop.yml | 2 +- lib/contain-pusha-popa-sequence.yml | 2 +- lib/create-or-open-file.yml | 2 +- lib/delay-execution.yml | 2 +- lib/get-service-handle.yml | 2 +- lib/peb-access.yml | 2 +- lib/write-process-memory.yml | 2 +- linking/runtime-linking/access-peb-ldr_data.yml | 2 +- linking/runtime-linking/get-kernel32-base-address.yml | 2 +- linking/runtime-linking/get-ntdll-base-address.yml | 2 +- .../runtime-linking/link-function-at-runtime-on-windows.yml | 2 +- linking/runtime-linking/link-many-functions-at-runtime.yml | 2 +- linking/static/cryptopp/linked-against-crypto.yml | 2 +- linking/static/libcurl/linked-against-libcurl.yml | 2 +- linking/static/msdetours/linked-against-microsoft-detours.yml | 2 +- linking/static/openssl/linked-against-openssl.yml | 4 ++-- linking/static/polarssl/linked-against-polarsslmbed-tls.yml | 2 +- linking/static/zlib/linked-against-zlib.yml | 2 +- load-code/pe/access-pe-header.yml | 2 +- load-code/pe/parse-pe-header.yml | 2 +- load-code/shellcode/spawn-thread-to-rwx-shellcode.yml | 2 +- nursery/add-file-to-cabinet-file.yml | 2 +- nursery/add-user-account-group.yml | 2 +- nursery/add-user-account-to-group.yml | 2 +- nursery/add-user-account.yml | 2 +- nursery/build-docker-image.yml | 2 +- .../bypass-uac-via-scheduled-task-environment-variable.yml | 2 +- nursery/change-user-account-password.yml | 2 +- nursery/check-for-process-debug-object.yml | 2 +- nursery/check-license-value.yml | 2 +- nursery/check-processdebugflags.yml | 2 +- nursery/check-systemkerneldebuggerinformation.yml | 2 +- nursery/check-thread-yield-allowed.yml | 2 +- nursery/compare-security-identifiers.yml | 2 +- nursery/compiled-from-epl.yml | 2 +- nursery/connect-network-resource.yml | 2 +- nursery/create-container.yml | 2 +- nursery/create-restart-manager-session.yml | 2 +- nursery/create-shortcut-via-ishelllink.yml | 2 +- nursery/debug-build.yml | 2 +- nursery/decrypt-data-via-sspi.yml | 2 +- nursery/delete-internet-cache.yml | 2 +- nursery/delete-user-account-from-group.yml | 2 +- nursery/delete-user-account-group.yml | 2 +- nursery/delete-user-account.yml | 2 +- nursery/empty-recycle-bin-quietly.yml | 2 +- nursery/empty-the-recycle-bin.yml | 2 +- nursery/encrypt-data-using-aes-via-x86-extensions.yml | 2 +- nursery/encrypt-data-using-fakem-cipher.yml | 2 +- nursery/encrypt-data-using-salsa20-or-chacha.yml | 2 +- nursery/encrypt-data-via-sspi.yml | 2 +- nursery/encrypt-or-decrypt-data-via-bcrypt.yml | 2 +- nursery/enumerate-browser-history.yml | 2 +- nursery/enumerate-disk-volumes.yml | 2 +- nursery/enumerate-internet-cache.yml | 2 +- nursery/enumerate-network-shares.yml | 2 +- nursery/enumerate-system-firmware-tables.yml | 2 +- .../execute-shell-command-via-windows-remote-management.yml | 2 +- nursery/flush-cabinet-file.yml | 2 +- nursery/generate-random-numbers-using-the-delphi-lcg.yml | 2 +- nursery/get-client-handle-via-schannel.yml | 2 +- nursery/get-inbound-credentials-handle-via-credssp.yml | 2 +- nursery/get-installed-programs.yml | 2 +- nursery/get-networking-parameters.yml | 2 +- nursery/get-proxy.yml | 2 +- nursery/get-remote-cert-context-via-schannel.yml | 2 +- nursery/get-routing-table.yml | 2 +- nursery/get-session-information.yml | 2 +- nursery/get-socket-information.yml | 2 +- nursery/get-storage-device-properties.yml | 2 +- nursery/get-system-firmware-table.yml | 2 +- nursery/get-thread-local-storage-value.yml | 2 +- nursery/get-token-privileges.yml | 2 +- nursery/hash-data-using-crc32b.yml | 2 +- nursery/hash-data-using-md4.yml | 2 +- nursery/hash-data-using-murmur2.yml | 2 +- nursery/hash-data-using-sha1-via-wincrypt.yml | 2 +- nursery/hash-data-via-bcrypt.yml | 2 +- nursery/hide-thread-from-debugger.yml | 2 +- nursery/hook-routines-via-microsoft-detours.yml | 2 +- nursery/hooked-by-api-override.yml | 2 +- nursery/impersonate-user.yml | 2 +- nursery/initialize-hashing-via-wincrypt.yml | 2 +- nursery/inspect-load-icon-resource.yml | 2 +- nursery/linked-against-cpp-regex-library.yml | 2 +- nursery/linked-against-xzip.yml | 2 +- nursery/list-containers.yml | 2 +- nursery/list-domain-servers.yml | 2 +- nursery/list-drag-and-drop-files.yml | 2 +- nursery/list-groups-for-user-account.yml | 2 +- nursery/list-tcp-connections-and-listeners.yml | 2 +- nursery/list-udp-connections-and-listeners.yml | 2 +- nursery/list-user-account-groups.yml | 2 +- nursery/list-user-accounts-for-group.yml | 2 +- nursery/list-user-accounts.yml | 2 +- nursery/listen-for-remote-procedure-calls.yml | 2 +- nursery/load-windows-common-language-runtime.yml | 2 +- nursery/log-keystrokes-via-raw-input-data.yml | 2 +- nursery/make-an-http-request-with-a-cookie.yml | 2 +- nursery/migrate-process-to-active-window-station.yml | 2 +- nursery/mine-cryptocurrency.yml | 2 +- nursery/monitor-clipboard-content.yml | 2 +- nursery/monitor-local-ipv4-address-changes.yml | 2 +- nursery/open-cabinet-file.yml | 2 +- nursery/packaged-as-a-createinstall-installer.yml | 2 +- nursery/packaged-as-a-nsis-installer.yml | 2 +- nursery/packaged-as-a-pintool.yml | 2 +- nursery/packaged-as-a-winzip-self-extracting-archive.yml | 2 +- nursery/packaged-as-a-wise-installer.yml | 2 +- nursery/packaged-as-an-installshield-installer.yml | 2 +- nursery/packed-with-ccg.yml | 2 +- nursery/packed-with-crunch.yml | 2 +- nursery/packed-with-dragon-armor.yml | 2 +- nursery/packed-with-enigma.yml | 2 +- nursery/packed-with-epack.yml | 2 +- nursery/packed-with-maskpe.yml | 2 +- nursery/packed-with-mew.yml | 2 +- nursery/packed-with-mpress.yml | 2 +- nursery/packed-with-neolite.yml | 2 +- nursery/packed-with-pepack.yml | 2 +- nursery/packed-with-perplex.yml | 2 +- nursery/packed-with-procrypt.yml | 2 +- nursery/packed-with-rpcrypt.yml | 2 +- nursery/packed-with-seausfx.yml | 2 +- nursery/packed-with-shrinker.yml | 2 +- nursery/packed-with-simple-pack.yml | 2 +- nursery/packed-with-starforce.yml | 2 +- nursery/packed-with-svkp.yml | 2 +- nursery/packed-with-themida.yml | 2 +- nursery/packed-with-tsuloader.yml | 2 +- nursery/packed-with-vprotect.yml | 2 +- nursery/packed-with-wwpack.yml | 2 +- nursery/parse-url.yml | 2 +- nursery/prompt-user-for-credentials.yml | 2 +- nursery/query-remote-server-for-available-data.yml | 2 +- nursery/read-and-send-data-from-client-to-server.yml | 2 +- nursery/read-process-memory.yml | 2 +- nursery/read-raw-disk-data.yml | 2 +- nursery/rebuilt-by-imprec.yml | 2 +- nursery/receive-and-write-data-from-server-to-client.yml | 2 +- nursery/reference-114dns-dns-server.yml | 2 +- nursery/reference-aes-constants.yml | 2 +- nursery/reference-alidns-dns-server.yml | 2 +- nursery/reference-cloudflare-dns-server.yml | 2 +- nursery/reference-comodo-secure-dns-server.yml | 2 +- nursery/reference-google-public-dns-server.yml | 2 +- nursery/reference-hurricane-electric-dns-server.yml | 2 +- nursery/reference-kornet-dns-server.yml | 2 +- nursery/reference-l3-dns-server.yml | 2 +- nursery/reference-opendns-dns-server.yml | 2 +- nursery/reference-processor-manufacturer-constants.yml | 2 +- nursery/reference-quad9-dns-server.yml | 2 +- nursery/reference-screen-saver-executable.yml | 2 +- nursery/reference-startup-folder.yml | 2 +- nursery/reference-the-vmware-io-port.yml | 2 +- nursery/reference-verisign-dns-server.yml | 2 +- nursery/register-http-server-url.yml | 2 +- nursery/register-raw-input-devices.yml | 2 +- nursery/resize-volume-shadow-copy-storage.yml | 2 +- nursery/resolve-function-by-hash.yml | 2 +- nursery/run-in-container.yml | 2 +- nursery/run-powershell-expression.yml | 2 +- nursery/schedule-task-via-itaskservice.yml | 2 +- nursery/search-for-credit-card-data.yml | 2 +- nursery/send-http-request-with-host-header.yml | 2 +- nursery/set-global-application-hook.yml | 2 +- nursery/spoof-parent-pid.yml | 2 +- nursery/terminate-process-by-name.yml | 2 +- .../registry/persist-via-active-setup-registry-key.yml | 2 +- persistence/registry/run/persist-via-run-registry-key.yml | 2 +- .../scheduled-tasks/schedule-task-via-itaskscheduler.yml | 2 +- persistence/service/persist-via-windows-service.yml | 2 +- persistence/startup-folder/get-startup-folder.yml | 2 +- persistence/startup-folder/write-file-to-startup-folder.yml | 2 +- runtime/dotnet/compiled-to-the-net-platform.yml | 2 +- .../diebold-nixdorf/load-diebold-nixdorf-atm-library.yml | 2 +- .../diebold-nixdorf/reference-diebold-atm-routines.yml | 2 +- .../identify-atm-dispenser-service-provider.yml | 2 +- .../automated-teller-machine/ncr/load-ncr-atm-library.yml | 2 +- .../ncr/reference-ncr-atm-library-routines.yml | 2 +- 445 files changed, 459 insertions(+), 459 deletions(-) diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml index 05a03963..6ef949ea 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml @@ -2,7 +2,7 @@ rule: meta: name: check for debugger via API namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::CheckRemoteDebuggerPresent [B0001.002] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml index 2115f51a..0ca2668a 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml @@ -2,7 +2,7 @@ rule: meta: name: check for hardware breakpoints namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::Hardware Breakpoints [B0001.005] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml index 1d4037ed..583c5f61 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml @@ -2,7 +2,7 @@ rule: meta: name: check for kernel debugger via shared user data structure namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml index 60c8e4eb..589afa2c 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml @@ -2,7 +2,7 @@ rule: meta: name: check for OutputDebugString error namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection::OutputDebugString [B0001.016] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml index 23a70dfe..7fb2aa8d 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml @@ -2,7 +2,7 @@ rule: meta: name: check for PEB BeingDebugged flag namespace: anti-analysis/anti-debugging/debugger-detection - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection::Process Environment Block BeingDebugged [B0001.035] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml index 5ca8b04d..400c9f5b 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml @@ -2,7 +2,7 @@ rule: meta: name: check for PEB NtGlobalFlag flag namespace: anti-analysis/anti-debugging/debugger-detection - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml index 1b7949a9..1c83c4bd 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml @@ -2,7 +2,7 @@ rule: meta: name: check for protected handle exception namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::SetHandleInformation [B0001.024] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml index 61deb898..f3295602 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml @@ -2,7 +2,7 @@ rule: meta: name: check for software breakpoints namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints [B0001.025] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml index 0bfcc8b9..6a57f429 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml @@ -2,7 +2,7 @@ rule: meta: name: check for time delay via GetTickCount namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount [B0001.032] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml index 54c2d608..9116db66 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml @@ -2,7 +2,7 @@ rule: meta: name: check for time delay via QueryPerformanceCounter namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check QueryPerformanceCounter [B0001.033] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml index 77d2506d..e2e14a71 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml @@ -2,7 +2,7 @@ rule: meta: name: check for trap flag exception namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml index 40ffbda6..694025c2 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml @@ -2,7 +2,7 @@ rule: meta: name: check for unexpected memory writes namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection::Memory Write Watching [B0001.010] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml b/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml index 41a3da90..32d86e71 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml @@ -2,7 +2,7 @@ rule: meta: name: check process job object namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml b/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml index 1cc3ac15..0f970e51 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml @@ -2,7 +2,7 @@ rule: meta: name: check ProcessDebugPort namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection diff --git a/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml b/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml index 468af5d3..4013c6b7 100644 --- a/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml +++ b/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml @@ -2,7 +2,7 @@ rule: meta: name: execute anti-debugging instructions namespace: anti-analysis/anti-debugging/debugger-detection - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection::Anti-debugging Instructions [B0001.034] diff --git a/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml b/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml index 234ce154..8b3d18b7 100644 --- a/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml +++ b/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml @@ -2,7 +2,7 @@ rule: meta: name: contain anti-disasm techniques namespace: anti-analysis/anti-disasm - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file mbc: - Anti-Static Analysis::Disassembler Evasion [B0012] diff --git a/anti-analysis/anti-forensic/clear-logs/clear-the-windows-event-log.yml b/anti-analysis/anti-forensic/clear-logs/clear-the-windows-event-log.yml index f3edf876..1528a0e9 100644 --- a/anti-analysis/anti-forensic/clear-logs/clear-the-windows-event-log.yml +++ b/anti-analysis/anti-forensic/clear-logs/clear-the-windows-event-log.yml @@ -2,7 +2,7 @@ rule: meta: name: clear the Windows event log namespace: anti-analysis/anti-forensic/clear-logs - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Indicator Removal on Host::Clear Windows Event Logs [T1070.001] diff --git a/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml b/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml index e2757101..d7955fc1 100644 --- a/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml +++ b/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml @@ -2,7 +2,7 @@ rule: meta: name: crash the Windows event logging service namespace: anti-analysis/anti-forensic - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Defense Evasion::Impair Defenses::Disable Windows Event Logging [T1562.002] diff --git a/anti-analysis/anti-forensic/patch-process-command-line.yml b/anti-analysis/anti-forensic/patch-process-command-line.yml index e0a4457f..2909f676 100644 --- a/anti-analysis/anti-forensic/patch-process-command-line.yml +++ b/anti-analysis/anti-forensic/patch-process-command-line.yml @@ -3,7 +3,7 @@ rule: name: patch process command line namespace: anti-analysis/anti-forensic author: - - william.ballenthin@fireeye.com + - william.ballenthin@mandiant.com - "@_re_fox" scope: function references: diff --git a/anti-analysis/anti-forensic/self-deletion/self-delete.yml b/anti-analysis/anti-forensic/self-deletion/self-delete.yml index e1f44394..9b897fbf 100644 --- a/anti-analysis/anti-forensic/self-deletion/self-delete.yml +++ b/anti-analysis/anti-forensic/self-deletion/self-delete.yml @@ -2,7 +2,7 @@ rule: meta: name: self delete namespace: anti-analysis/anti-forensic/self-deletion - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Indicator Removal on Host::File Deletion [T1070.004] diff --git a/anti-analysis/anti-forensic/timestomp/timestomp-file.yml b/anti-analysis/anti-forensic/timestomp/timestomp-file.yml index 5aaa3139..47a7947f 100644 --- a/anti-analysis/anti-forensic/timestomp/timestomp-file.yml +++ b/anti-analysis/anti-forensic/timestomp/timestomp-file.yml @@ -2,7 +2,7 @@ rule: meta: name: timestomp file namespace: anti-analysis/anti-forensic/timestomp - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Indicator Removal on Host::Timestomp [T1070.006] diff --git a/anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml b/anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml index ef098b50..8fa962f9 100644 --- a/anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml +++ b/anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml @@ -2,7 +2,7 @@ rule: meta: name: execute anti-VM instructions namespace: anti-analysis/anti-vm/vm-detection - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml index 1ea12dfb..82c9629d 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings targeting Parallels namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml index 96f64edb..3a0d083b 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings targeting Qemu namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml index 0b895de8..f11fd670 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings targeting VirtualBox namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml index 8d2f312c..306325eb 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings targeting VirtualPC namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml index 6f6e38b9..c3c5b9a6 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings targeting VMWare namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml index 17d2c69c..d185c49a 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings targeting Xen namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml index 2a801327..4aea6884 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml @@ -2,7 +2,7 @@ rule: meta: name: reference anti-VM strings namespace: anti-analysis/anti-vm/vm-detection - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml b/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml index 15abdea5..8ebba246 100644 --- a/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml +++ b/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml @@ -2,7 +2,7 @@ rule: meta: name: contain obfuscated stackstrings namespace: anti-analysis/obfuscation/string/stackstring - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] diff --git a/anti-analysis/packer/amber/packed-with-amber.yml b/anti-analysis/packer/amber/packed-with-amber.yml index dac9d48a..685b8442 100644 --- a/anti-analysis/packer/amber/packed-with-amber.yml +++ b/anti-analysis/packer/amber/packed-with-amber.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with amber namespace: anti-analysis/packer/amber - author: "john.gorman@fireeye.com" + author: "john.gorman@mandiant.com" scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/packer/aspack/packed-with-aspack.yml b/anti-analysis/packer/aspack/packed-with-aspack.yml index 2dfdf847..5127df23 100644 --- a/anti-analysis/packer/aspack/packed-with-aspack.yml +++ b/anti-analysis/packer/aspack/packed-with-aspack.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with ASPack namespace: anti-analysis/packer/aspack - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/packer/confuser/packed-with-confuser.yml b/anti-analysis/packer/confuser/packed-with-confuser.yml index fd053cb6..9f75be92 100644 --- a/anti-analysis/packer/confuser/packed-with-confuser.yml +++ b/anti-analysis/packer/confuser/packed-with-confuser.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Confuser namespace: anti-analysis/packer/confuser - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/packer/generic/packed-with-generic-packer.yml b/anti-analysis/packer/generic/packed-with-generic-packer.yml index ceab7835..f679ab52 100644 --- a/anti-analysis/packer/generic/packed-with-generic-packer.yml +++ b/anti-analysis/packer/generic/packed-with-generic-packer.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with generic packer namespace: anti-analysis/packer/generic - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/packer/gopacker/packed-with-gopacker.yml b/anti-analysis/packer/gopacker/packed-with-gopacker.yml index d163c4dd..d25a7752 100644 --- a/anti-analysis/packer/gopacker/packed-with-gopacker.yml +++ b/anti-analysis/packer/gopacker/packed-with-gopacker.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with GoPacker namespace: anti-analysis/packer/gopacker - author: jared.wilson@fireeye.com + author: jared.wilson@mandiant.com description: The sample appears to be packed with GoPacker. scope: file att&ck: diff --git a/anti-analysis/packer/pecompact/packed-with-pecompact.yml b/anti-analysis/packer/pecompact/packed-with-pecompact.yml index 2dd41769..683bb8e1 100644 --- a/anti-analysis/packer/pecompact/packed-with-pecompact.yml +++ b/anti-analysis/packer/pecompact/packed-with-pecompact.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with PECompact namespace: anti-analysis/packer/pecompact - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/packer/upx/packed-with-upx.yml b/anti-analysis/packer/upx/packed-with-upx.yml index cbe49f12..a54936f6 100644 --- a/anti-analysis/packer/upx/packed-with-upx.yml +++ b/anti-analysis/packer/upx/packed-with-upx.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with UPX namespace: anti-analysis/packer/upx - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml b/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml index ab81eb6f..c8385ebe 100644 --- a/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml +++ b/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with VMProtect namespace: anti-analysis/packer/vmprotect - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/anti-analysis/reference-analysis-tools-strings.yml b/anti-analysis/reference-analysis-tools-strings.yml index 70dd3d4f..399789d5 100644 --- a/anti-analysis/reference-analysis-tools-strings.yml +++ b/anti-analysis/reference-analysis-tools-strings.yml @@ -2,7 +2,7 @@ rule: meta: name: reference analysis tools strings namespace: anti-analysis - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file mbc: - Discovery::Analysis Tool Discovery::Process Detection [B0013.001] diff --git a/c2/file-transfer/download-and-write-a-file.yml b/c2/file-transfer/download-and-write-a-file.yml index 573b24cd..91e5dda5 100644 --- a/c2/file-transfer/download-and-write-a-file.yml +++ b/c2/file-transfer/download-and-write-a-file.yml @@ -3,7 +3,7 @@ rule: name: download and write a file namespace: c2/file-transfer maec/malware-category: downloader - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Command and Control::Ingress Tool Transfer [T1105] diff --git a/c2/file-transfer/write-and-execute-a-file.yml b/c2/file-transfer/write-and-execute-a-file.yml index 36ea7cd9..2b87de83 100644 --- a/c2/file-transfer/write-and-execute-a-file.yml +++ b/c2/file-transfer/write-and-execute-a-file.yml @@ -3,7 +3,7 @@ rule: name: write and execute a file namespace: c2/file-transfer maec/malware-category: launcher - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Execution::Install Additional Program [B0023] diff --git a/c2/shell/create-reverse-shell.yml b/c2/shell/create-reverse-shell.yml index f781caf3..8e566ba9 100644 --- a/c2/shell/create-reverse-shell.yml +++ b/c2/shell/create-reverse-shell.yml @@ -2,7 +2,7 @@ rule: meta: name: create reverse shell namespace: c2/shell - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Execution::Command and Scripting Interpreter::Windows Command Shell [T1059.003] diff --git a/c2/shell/execute-shell-command-and-capture-output.yml b/c2/shell/execute-shell-command-and-capture-output.yml index 2767143d..a7a48fba 100644 --- a/c2/shell/execute-shell-command-and-capture-output.yml +++ b/c2/shell/execute-shell-command-and-capture-output.yml @@ -2,7 +2,7 @@ rule: meta: name: execute shell command and capture output namespace: c2/shell - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function att&ck: - Execution::Command and Scripting Interpreter::Windows Command Shell [T1059.003] diff --git a/collection/acquire-credentials-from-windows-credential-manager.yml b/collection/acquire-credentials-from-windows-credential-manager.yml index 7f72d17d..17bdb084 100644 --- a/collection/acquire-credentials-from-windows-credential-manager.yml +++ b/collection/acquire-credentials-from-windows-credential-manager.yml @@ -3,7 +3,7 @@ rule: meta: name: acquire credentials from Windows Credential Manager namespace: collection - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Credential Access::Credentials from Password Stores::Windows Credential Manager [T1555.004] diff --git a/collection/database/sql/reference-sql-statements.yml b/collection/database/sql/reference-sql-statements.yml index 34386d17..45cb0f82 100644 --- a/collection/database/sql/reference-sql-statements.yml +++ b/collection/database/sql/reference-sql-statements.yml @@ -2,7 +2,7 @@ rule: meta: name: reference SQL statements namespace: collection/database/sql - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Collection::Data from Information Repositories [T1213] diff --git a/collection/database/wmi/reference-wmi-statements.yml b/collection/database/wmi/reference-wmi-statements.yml index e33d6e12..d6d01bbf 100644 --- a/collection/database/wmi/reference-wmi-statements.yml +++ b/collection/database/wmi/reference-wmi-statements.yml @@ -2,7 +2,7 @@ rule: meta: name: reference WMI statements namespace: collection/database/wmi - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Data from Information Repositories [T1213] diff --git a/collection/keylog/log-keystrokes-via-application-hook.yml b/collection/keylog/log-keystrokes-via-application-hook.yml index d427cd92..00628e0c 100644 --- a/collection/keylog/log-keystrokes-via-application-hook.yml +++ b/collection/keylog/log-keystrokes-via-application-hook.yml @@ -2,7 +2,7 @@ rule: meta: name: log keystrokes via application hook namespace: collection/keylog - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Input Capture::Keylogging [T1056.001] diff --git a/collection/keylog/log-keystrokes-via-polling.yml b/collection/keylog/log-keystrokes-via-polling.yml index d1d683cf..612a2f1a 100644 --- a/collection/keylog/log-keystrokes-via-polling.yml +++ b/collection/keylog/log-keystrokes-via-polling.yml @@ -2,7 +2,7 @@ rule: meta: name: log keystrokes via polling namespace: collection/keylog - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Input Capture::Keylogging [T1056.001] diff --git a/collection/keylog/log-keystrokes.yml b/collection/keylog/log-keystrokes.yml index 3380b23a..11783f4a 100644 --- a/collection/keylog/log-keystrokes.yml +++ b/collection/keylog/log-keystrokes.yml @@ -2,7 +2,7 @@ rule: meta: name: log keystrokes namespace: collection/keylog - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Collection::Input Capture::Keylogging [T1056.001] diff --git a/collection/network/get-mac-address-on-windows.yml b/collection/network/get-mac-address-on-windows.yml index 681c7be2..f3fc5d32 100644 --- a/collection/network/get-mac-address-on-windows.yml +++ b/collection/network/get-mac-address-on-windows.yml @@ -3,7 +3,7 @@ rule: name: get MAC address on Windows namespace: collection/network author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/collection/screenshot/capture-screenshot.yml b/collection/screenshot/capture-screenshot.yml index 5c563d54..2578b34d 100644 --- a/collection/screenshot/capture-screenshot.yml +++ b/collection/screenshot/capture-screenshot.yml @@ -3,9 +3,9 @@ rule: name: capture screenshot namespace: collection/screenshot author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - "@_re_fox" - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Screen Capture [T1113] diff --git a/communication/ftp/send/send-file-using-ftp-via-wininet.yml b/communication/ftp/send/send-file-using-ftp-via-wininet.yml index e8f2e831..b56cf67a 100644 --- a/communication/ftp/send/send-file-using-ftp-via-wininet.yml +++ b/communication/ftp/send/send-file-using-ftp-via-wininet.yml @@ -2,7 +2,7 @@ rule: meta: name: send file using FTP via wininet namespace: communication/ftp/send - author: michael.hunhof@fireeye.com + author: michael.hunhof@mandiant.com scope: function mbc: - Communication::FTP Communication::Send File [C0004.001] diff --git a/communication/http/client/connect-to-http-server.yml b/communication/http/client/connect-to-http-server.yml index 2a5b4c3c..912777f4 100644 --- a/communication/http/client/connect-to-http-server.yml +++ b/communication/http/client/connect-to-http-server.yml @@ -2,7 +2,7 @@ rule: meta: name: connect to HTTP server namespace: communication/http/client - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Connect to Server [C0002.009] diff --git a/communication/http/client/connect-to-url.yml b/communication/http/client/connect-to-url.yml index 98957f41..cf27924d 100644 --- a/communication/http/client/connect-to-url.yml +++ b/communication/http/client/connect-to-url.yml @@ -2,7 +2,7 @@ rule: meta: name: connect to URL namespace: communication/http/client - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Open URL [C0002.004] diff --git a/communication/http/client/create-http-request.yml b/communication/http/client/create-http-request.yml index acaa317c..d178f236 100644 --- a/communication/http/client/create-http-request.yml +++ b/communication/http/client/create-http-request.yml @@ -2,7 +2,7 @@ rule: meta: name: create HTTP request namespace: communication/http/client - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Create Request [C0002.012] diff --git a/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml b/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml index e8c2a4e6..22ad455b 100644 --- a/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml +++ b/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml @@ -2,7 +2,7 @@ rule: meta: name: decompress HTTP response via IEncodingFilterFactory namespace: communication/http/client - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Communication::HTTP Communication::Get Response [C0002.017] diff --git a/communication/http/client/download-url-to-file.yml b/communication/http/client/download-url-to-file.yml index 8c147c90..8322a9a9 100644 --- a/communication/http/client/download-url-to-file.yml +++ b/communication/http/client/download-url-to-file.yml @@ -2,7 +2,7 @@ rule: meta: name: download URL to file namespace: communication/http/client - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Communication::HTTP Communication::Download URL [C0002.006] diff --git a/communication/http/client/extract-http-body.yml b/communication/http/client/extract-http-body.yml index f5fcdf4f..9f00732f 100644 --- a/communication/http/client/extract-http-body.yml +++ b/communication/http/client/extract-http-body.yml @@ -2,7 +2,7 @@ rule: meta: name: extract HTTP body namespace: communication/http/client - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Communication::HTTP Communication::Extract Body [C0002.011] diff --git a/communication/http/client/get-http-document-via-iwebbrowser2.yml b/communication/http/client/get-http-document-via-iwebbrowser2.yml index 4886fa58..02d36017 100644 --- a/communication/http/client/get-http-document-via-iwebbrowser2.yml +++ b/communication/http/client/get-http-document-via-iwebbrowser2.yml @@ -2,7 +2,7 @@ rule: meta: name: get HTTP document via IWebBrowser2 namespace: communication/http/client - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Communication::HTTP Communication::Get Response [C0002.017] diff --git a/communication/http/client/get-http-response-content-encoding.yml b/communication/http/client/get-http-response-content-encoding.yml index 4aa7db09..de1fd72f 100644 --- a/communication/http/client/get-http-response-content-encoding.yml +++ b/communication/http/client/get-http-response-content-encoding.yml @@ -2,7 +2,7 @@ rule: meta: name: get HTTP response content encoding namespace: communication/http/client - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block mbc: - Communication::HTTP Communication::Get Response [C0002.017] diff --git a/communication/http/client/prepare-http-request.yml b/communication/http/client/prepare-http-request.yml index ed3af1b9..fa6a29d5 100644 --- a/communication/http/client/prepare-http-request.yml +++ b/communication/http/client/prepare-http-request.yml @@ -2,7 +2,7 @@ rule: meta: name: prepare HTTP request namespace: communication/http/client - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Create Request [C0002.012] diff --git a/communication/http/client/read-data-from-internet.yml b/communication/http/client/read-data-from-internet.yml index 9182c93b..35ff17dd 100644 --- a/communication/http/client/read-data-from-internet.yml +++ b/communication/http/client/read-data-from-internet.yml @@ -2,7 +2,7 @@ rule: meta: name: read data from Internet namespace: communication/http/client - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Get Response [C0002.017] diff --git a/communication/http/client/receive-http-response.yml b/communication/http/client/receive-http-response.yml index 6104b134..6cf5927b 100644 --- a/communication/http/client/receive-http-response.yml +++ b/communication/http/client/receive-http-response.yml @@ -2,7 +2,7 @@ rule: meta: name: receive HTTP response namespace: communication/http/client - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Get Response [C0002.017] diff --git a/communication/http/client/send-file-via-http.yml b/communication/http/client/send-file-via-http.yml index c59842b3..fc222a68 100644 --- a/communication/http/client/send-file-via-http.yml +++ b/communication/http/client/send-file-via-http.yml @@ -2,7 +2,7 @@ rule: meta: name: send file via HTTP namespace: communication/http/client - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block mbc: - Communication::HTTP Communication::Send Data [C0002.005] diff --git a/communication/http/client/send-http-request.yml b/communication/http/client/send-http-request.yml index d43380f4..3dd41261 100644 --- a/communication/http/client/send-http-request.yml +++ b/communication/http/client/send-http-request.yml @@ -2,7 +2,7 @@ rule: meta: name: send HTTP request namespace: communication/http/client - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Communication::HTTP Communication::Send Request [C0002.003] diff --git a/communication/http/initialize-iwebbrowser2.yml b/communication/http/initialize-iwebbrowser2.yml index f5aec04d..8aaac3c4 100644 --- a/communication/http/initialize-iwebbrowser2.yml +++ b/communication/http/initialize-iwebbrowser2.yml @@ -2,7 +2,7 @@ rule: meta: name: initialize IWebBrowser2 namespace: communication/http - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block mbc: - Communication::HTTP Communication::IWebBrowser [C0002.010] diff --git a/communication/http/initialize-winhttp-library.yml b/communication/http/initialize-winhttp-library.yml index b8b8fcdb..702f6870 100644 --- a/communication/http/initialize-winhttp-library.yml +++ b/communication/http/initialize-winhttp-library.yml @@ -2,7 +2,7 @@ rule: meta: name: initialize WinHTTP library namespace: communication/http - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::WinHTTP [C0002.008] diff --git a/communication/http/read-http-header.yml b/communication/http/read-http-header.yml index b5b9069a..755aeaa2 100644 --- a/communication/http/read-http-header.yml +++ b/communication/http/read-http-header.yml @@ -2,7 +2,7 @@ rule: meta: name: read HTTP header namespace: communication/http - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Read Header [C0002.014] diff --git a/communication/http/server/receive-http-request.yml b/communication/http/server/receive-http-request.yml index 486ad031..4ad27279 100644 --- a/communication/http/server/receive-http-request.yml +++ b/communication/http/server/receive-http-request.yml @@ -2,7 +2,7 @@ rule: meta: name: receive HTTP request namespace: communication/http/server - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Receive Request [C0002.015] diff --git a/communication/http/server/send-http-response.yml b/communication/http/server/send-http-response.yml index cdf8a195..a6615894 100644 --- a/communication/http/server/send-http-response.yml +++ b/communication/http/server/send-http-response.yml @@ -2,7 +2,7 @@ rule: meta: name: send HTTP response namespace: communication/http/server - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Send Response [C0002.016] diff --git a/communication/http/server/start-http-server.yml b/communication/http/server/start-http-server.yml index 91f2973f..bd796cd4 100644 --- a/communication/http/server/start-http-server.yml +++ b/communication/http/server/start-http-server.yml @@ -2,7 +2,7 @@ rule: meta: name: start HTTP server namespace: communication/http/server - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Start Server [C0002.018] diff --git a/communication/http/set-http-header.yml b/communication/http/set-http-header.yml index f75f35f2..32eddb3a 100644 --- a/communication/http/set-http-header.yml +++ b/communication/http/set-http-header.yml @@ -2,7 +2,7 @@ rule: meta: name: set HTTP header namespace: communication/http - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::HTTP Communication::Set Header [C0002.013] diff --git a/communication/icmp/send-icmp-echo-request.yml b/communication/icmp/send-icmp-echo-request.yml index 7e5b5d7e..83c1247c 100644 --- a/communication/icmp/send-icmp-echo-request.yml +++ b/communication/icmp/send-icmp-echo-request.yml @@ -2,7 +2,7 @@ rule: meta: name: send ICMP echo request namespace: communication/icmp - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::ICMP Communication::Echo Request [C0014.002] diff --git a/communication/named-pipe/connect/connect-pipe.yml b/communication/named-pipe/connect/connect-pipe.yml index d70fe5c6..18a65bc3 100644 --- a/communication/named-pipe/connect/connect-pipe.yml +++ b/communication/named-pipe/connect/connect-pipe.yml @@ -3,8 +3,8 @@ rule: name: connect pipe namespace: communication/named-pipe/connect author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com scope: function mbc: - Communication::Interprocess Communication::Connect Pipe [C0003.002] diff --git a/communication/named-pipe/create/create-pipe.yml b/communication/named-pipe/create/create-pipe.yml index f5fbd0cd..1395ecc6 100644 --- a/communication/named-pipe/create/create-pipe.yml +++ b/communication/named-pipe/create/create-pipe.yml @@ -2,7 +2,7 @@ rule: meta: name: create pipe namespace: communication/named-pipe/create - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Communication::Interprocess Communication::Create Pipe [C0003.001] diff --git a/communication/named-pipe/create/create-two-anonymous-pipes.yml b/communication/named-pipe/create/create-two-anonymous-pipes.yml index 34adec3d..8e7030ab 100644 --- a/communication/named-pipe/create/create-two-anonymous-pipes.yml +++ b/communication/named-pipe/create/create-two-anonymous-pipes.yml @@ -2,7 +2,7 @@ rule: meta: name: create two anonymous pipes namespace: communication/named-pipe/create - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Communication::Interprocess Communication::Create Pipe [C0003.001] diff --git a/communication/named-pipe/read/read-pipe.yml b/communication/named-pipe/read/read-pipe.yml index 8069a7f3..03aa7c7c 100644 --- a/communication/named-pipe/read/read-pipe.yml +++ b/communication/named-pipe/read/read-pipe.yml @@ -3,8 +3,8 @@ rule: name: read pipe namespace: communication/named-pipe/read author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com description: PeekNamedPipe isn't required to read from a pipe; however, pipes are often utilized to capture the output of a cmd.exe process. In a multi-thread instance, a new thread is created that calls PeekNamedPipe and ReadFile to obtain the command output. scope: function mbc: diff --git a/communication/named-pipe/write/write-pipe.yml b/communication/named-pipe/write/write-pipe.yml index 46e7b84f..6823479f 100644 --- a/communication/named-pipe/write/write-pipe.yml +++ b/communication/named-pipe/write/write-pipe.yml @@ -3,8 +3,8 @@ rule: name: write pipe namespace: communication/named-pipe/write author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com scope: function mbc: - Communication::Interprocess Communication::Write Pipe [C0003.004] diff --git a/communication/receive-data.yml b/communication/receive-data.yml index 096a90ec..c8225397 100644 --- a/communication/receive-data.yml +++ b/communication/receive-data.yml @@ -2,7 +2,7 @@ rule: meta: name: receive data namespace: communication - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com description: all known techniques for receiving data from a potential C2 server scope: function mbc: diff --git a/communication/send-data.yml b/communication/send-data.yml index edf899c5..a2841e55 100644 --- a/communication/send-data.yml +++ b/communication/send-data.yml @@ -3,7 +3,7 @@ rule: name: send data namespace: communication author: - - william.ballenthin@fireeye.com + - william.ballenthin@mandiant.com - joakim@intezer.com description: all known techniques for sending data to a potential C2 server scope: function diff --git a/communication/socket/get-socket-status.yml b/communication/socket/get-socket-status.yml index 7156d00a..69a497e1 100644 --- a/communication/socket/get-socket-status.yml +++ b/communication/socket/get-socket-status.yml @@ -2,7 +2,7 @@ rule: meta: name: get socket status namespace: communication/socket - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Network Configuration Discovery [T1016] diff --git a/communication/socket/initialize-winsock-library.yml b/communication/socket/initialize-winsock-library.yml index b7538e0e..169a702e 100644 --- a/communication/socket/initialize-winsock-library.yml +++ b/communication/socket/initialize-winsock-library.yml @@ -2,7 +2,7 @@ rule: meta: name: initialize Winsock library namespace: communication/socket - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::Socket Communication::Initialize Winsock Library [C0001.009] diff --git a/communication/socket/receive/receive-data-on-socket.yml b/communication/socket/receive/receive-data-on-socket.yml index 61479959..82e51077 100644 --- a/communication/socket/receive/receive-data-on-socket.yml +++ b/communication/socket/receive/receive-data-on-socket.yml @@ -3,7 +3,7 @@ rule: name: receive data on socket namespace: communication/socket/receive author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function mbc: diff --git a/communication/socket/send/send-data-on-socket.yml b/communication/socket/send/send-data-on-socket.yml index db1e27a5..079d9f6e 100644 --- a/communication/socket/send/send-data-on-socket.yml +++ b/communication/socket/send/send-data-on-socket.yml @@ -3,7 +3,7 @@ rule: name: send data on socket namespace: communication/socket/send author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function mbc: diff --git a/communication/socket/set-socket-configuration.yml b/communication/socket/set-socket-configuration.yml index e2b33e99..b7d7d053 100644 --- a/communication/socket/set-socket-configuration.yml +++ b/communication/socket/set-socket-configuration.yml @@ -2,7 +2,7 @@ rule: meta: name: set socket configuration namespace: communication/socket - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::Socket Communication::Set Socket Config [C0001.001] diff --git a/communication/socket/tcp/connect-tcp-socket.yml b/communication/socket/tcp/connect-tcp-socket.yml index 25d8ac39..53c87f74 100644 --- a/communication/socket/tcp/connect-tcp-socket.yml +++ b/communication/socket/tcp/connect-tcp-socket.yml @@ -3,7 +3,7 @@ rule: name: connect TCP socket namespace: communication/socket/tcp author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function mbc: diff --git a/communication/socket/tcp/create-tcp-socket.yml b/communication/socket/tcp/create-tcp-socket.yml index 7b172c9e..11957e03 100644 --- a/communication/socket/tcp/create-tcp-socket.yml +++ b/communication/socket/tcp/create-tcp-socket.yml @@ -3,7 +3,7 @@ rule: name: create TCP socket namespace: communication/socket/tcp author: - - william.ballenthin@fireeye.com + - william.ballenthin@mandiant.com - joakim@intezer.com scope: basic block mbc: diff --git a/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml b/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml index 8d7d1478..a109a3db 100644 --- a/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml +++ b/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml @@ -2,7 +2,7 @@ rule: meta: name: send TCP data via WFP API namespace: communication/socket/tcp/send - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Communication::Socket Communication::Send TCP Data [C0001.014] diff --git a/communication/socket/udp/send/create-udp-socket.yml b/communication/socket/udp/send/create-udp-socket.yml index f24ff64d..7bfa08ae 100644 --- a/communication/socket/udp/send/create-udp-socket.yml +++ b/communication/socket/udp/send/create-udp-socket.yml @@ -3,7 +3,7 @@ rule: name: create UDP socket namespace: communication/socket/udp/send author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: basic block mbc: diff --git a/communication/tcp/client/act-as-tcp-client.yml b/communication/tcp/client/act-as-tcp-client.yml index d23987ef..3d3f6622 100644 --- a/communication/tcp/client/act-as-tcp-client.yml +++ b/communication/tcp/client/act-as-tcp-client.yml @@ -2,7 +2,7 @@ rule: meta: name: act as TCP client namespace: communication/tcp/client - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function mbc: - Communication::Socket Communication::TCP Client [C0001.008] diff --git a/communication/tcp/serve/start-tcp-server.yml b/communication/tcp/serve/start-tcp-server.yml index 805b1b18..ed00b251 100644 --- a/communication/tcp/serve/start-tcp-server.yml +++ b/communication/tcp/serve/start-tcp-server.yml @@ -2,7 +2,7 @@ rule: meta: name: start TCP server namespace: communication/tcp/serve - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function mbc: - Communication::Socket Communication::Start TCP Server [C0001.005] diff --git a/compiler/autoit/compiled-with-autoit.yml b/compiler/autoit/compiled-with-autoit.yml index f8271b5a..ed8f3379 100644 --- a/compiler/autoit/compiled-with-autoit.yml +++ b/compiler/autoit/compiled-with-autoit.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled with AutoIt namespace: compiler/autoit - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Execution::Command and Scripting Interpreter [T1059] diff --git a/compiler/delphi/compiled-with-borland-delphi.yml b/compiler/delphi/compiled-with-borland-delphi.yml index 4553c11b..67aeb281 100644 --- a/compiler/delphi/compiled-with-borland-delphi.yml +++ b/compiler/delphi/compiled-with-borland-delphi.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled with Borland Delphi namespace: compiler/delphi - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file examples: - 4BDD67FF852C221112337FECD0681EAC diff --git a/compiler/go/compiled-with-go.yml b/compiler/go/compiled-with-go.yml index 86ccc479..df9bd9aa 100644 --- a/compiler/go/compiled-with-go.yml +++ b/compiler/go/compiled-with-go.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled with Go namespace: compiler/go - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file examples: - 49a34cfbeed733c24392c9217ef46bb6 diff --git a/compiler/mingw/compiled-with-mingw-for-windows.yml b/compiler/mingw/compiled-with-mingw-for-windows.yml index d17edf38..326d3cd6 100644 --- a/compiler/mingw/compiled-with-mingw-for-windows.yml +++ b/compiler/mingw/compiled-with-mingw-for-windows.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled with MinGW for Windows namespace: compiler/mingw - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file examples: - 5b3968b47eb16a1cb88525e3b565eab1 diff --git a/compiler/nim/compiled-with-nim.yml b/compiler/nim/compiled-with-nim.yml index c5dd0f7d..cb13d49b 100644 --- a/compiler/nim/compiled-with-nim.yml +++ b/compiler/nim/compiled-with-nim.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled with Nim namespace: compiler/nim - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file examples: - 580c37831fe98a254eb6c61c692c70d8.exe_ diff --git a/data-manipulation/checksum/adler32/compute-adler32-checksum.yml b/data-manipulation/checksum/adler32/compute-adler32-checksum.yml index 4c02a01b..574a137c 100644 --- a/data-manipulation/checksum/adler32/compute-adler32-checksum.yml +++ b/data-manipulation/checksum/adler32/compute-adler32-checksum.yml @@ -2,7 +2,7 @@ rule: meta: name: compute adler32 checksum namespace: data-manipulation/checksum/adler32 - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Data::Checksum::Adler [C0032.005] diff --git a/data-manipulation/checksum/crc32/hash-data-with-crc32.yml b/data-manipulation/checksum/crc32/hash-data-with-crc32.yml index 7982fbe2..64c8fe95 100644 --- a/data-manipulation/checksum/crc32/hash-data-with-crc32.yml +++ b/data-manipulation/checksum/crc32/hash-data-with-crc32.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data with CRC32 namespace: data-manipulation/checksum/crc32 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Data::Checksum::CRC32 [C0032.001] diff --git a/data-manipulation/compression/compress-data-via-winapi.yml b/data-manipulation/compression/compress-data-via-winapi.yml index 079f0868..00644fd2 100644 --- a/data-manipulation/compression/compress-data-via-winapi.yml +++ b/data-manipulation/compression/compress-data-via-winapi.yml @@ -2,7 +2,7 @@ rule: meta: name: compress data via WinAPI namespace: data-manipulation/compression - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Collection::Archive Collected Data::Archive via Library [T1560.002] diff --git a/data-manipulation/compression/decompress-data-using-aplib.yml b/data-manipulation/compression/decompress-data-using-aplib.yml index 2633eb2e..ed0f7561 100644 --- a/data-manipulation/compression/decompress-data-using-aplib.yml +++ b/data-manipulation/compression/decompress-data-using-aplib.yml @@ -4,7 +4,7 @@ rule: namespace: data-manipulation/compression author: - "@r3c0nst (Frank Boldewin)" - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com description: detects decompression function of library aPLib scope: function references: diff --git a/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml b/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml index 16012ea3..02a03c83 100644 --- a/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml +++ b/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml @@ -2,7 +2,7 @@ rule: meta: name: decompress data via IEncodingFilterFactory namespace: data-manipulation/compression - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Data::Decompress Data::IEncodingFilterFactory [C0025.002] diff --git a/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml b/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml index 072b37ac..9dbd0cf6 100644 --- a/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml +++ b/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml @@ -2,7 +2,7 @@ rule: meta: name: decode data using Base64 via dword translation table namespace: data-manipulation/encoding/base64 - author: gilbert.elliot@fireeye.com + author: gilbert.elliot@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml b/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml index 15a4450a..40841c5d 100644 --- a/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml +++ b/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml @@ -2,7 +2,7 @@ rule: meta: name: decode data using Base64 via WinAPI namespace: data-manipulation/encoding/base64 - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] diff --git a/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml b/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml index 0e62a2ed..503d2abf 100644 --- a/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml +++ b/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml @@ -2,7 +2,7 @@ rule: meta: name: encode data using Base64 via WinAPI namespace: data-manipulation/encoding/base64 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encoding/base64/encode-data-using-base64.yml b/data-manipulation/encoding/base64/encode-data-using-base64.yml index 5ab6ca07..c65ca6c9 100644 --- a/data-manipulation/encoding/base64/encode-data-using-base64.yml +++ b/data-manipulation/encoding/base64/encode-data-using-base64.yml @@ -2,7 +2,7 @@ rule: meta: name: encode data using Base64 namespace: data-manipulation/encoding/base64 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encoding/base64/reference-base64-string.yml b/data-manipulation/encoding/base64/reference-base64-string.yml index 0adabca7..f9d31b61 100644 --- a/data-manipulation/encoding/base64/reference-base64-string.yml +++ b/data-manipulation/encoding/base64/reference-base64-string.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Base64 string namespace: data-manipulation/encoding/base64 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encoding/xor/encode-data-using-xor.yml b/data-manipulation/encoding/xor/encode-data-using-xor.yml index 3ef671ce..6945cb95 100644 --- a/data-manipulation/encoding/xor/encode-data-using-xor.yml +++ b/data-manipulation/encoding/xor/encode-data-using-xor.yml @@ -2,7 +2,7 @@ rule: meta: name: encode data using XOR namespace: data-manipulation/encoding/xor - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml b/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml index a12fbaea..60264f8d 100644 --- a/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml +++ b/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml @@ -2,7 +2,7 @@ rule: meta: name: decrypt data using AES via x86 extensions namespace: data-manipulation/encryption/aes - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] diff --git a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-net.yml b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-net.yml index 7ec4471f..95869601 100644 --- a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-net.yml +++ b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-net.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using AES via .NET namespace: data-manipulation/encryption/aes - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml index 6c7c3d2c..2f0d4667 100644 --- a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml +++ b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using AES via WinAPI namespace: data-manipulation/encryption/aes - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml b/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml index 10f9378c..a18d5d5f 100644 --- a/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml +++ b/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml @@ -2,7 +2,7 @@ rule: meta: name: create new key via CryptAcquireContext namespace: data-manipulation/encryption - author: chuong.dong@fireeye.com + author: chuong.dong@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml b/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml index 3a30484a..b1727923 100644 --- a/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml +++ b/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using DPAPI namespace: data-manipulation/encryption/dpapi - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml b/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml index 6fc18cdd..bc24b8e3 100644 --- a/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml +++ b/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using Curve25519 namespace: data-manipulation/encryption/elliptic-curve - author: dimiter.andonov@fireeye.com + author: dimiter.andonov@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml b/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml index c521a7a2..e24cb9c9 100644 --- a/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml +++ b/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt or decrypt via WinCrypt namespace: data-manipulation/encryption - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml b/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml index ffd7671e..5cb3d28a 100644 --- a/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml +++ b/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml @@ -2,7 +2,7 @@ rule: meta: name: get outbound credentials handle via CredSSP namespace: data-manipulation/encryption - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/import-public-key.yml b/data-manipulation/encryption/import-public-key.yml index 7efe4443..244ebf83 100644 --- a/data-manipulation/encryption/import-public-key.yml +++ b/data-manipulation/encryption/import-public-key.yml @@ -2,7 +2,7 @@ rule: meta: name: import public key namespace: data-manipulation/encryption - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function mbc: - Cryptography::Encryption Key::Import Public Key [C0028.001] diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml index 0cd9f0ba..606d172d 100644 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using RC4 KSA namespace: data-manipulation/encryption/rc4 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml index 90e2877a..c1b465de 100644 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using RC4 PRGA namespace: data-manipulation/encryption/rc4 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml index 8ae483a5..0e2fead5 100644 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using RC4 via WinAPI namespace: data-manipulation/encryption/rc4 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml b/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml index f565dad1..661b1054 100644 --- a/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml +++ b/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using RC6 namespace: data-manipulation/encryption/rc6 - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/data-manipulation/encryption/rsa/reference-public-rsa-key.yml b/data-manipulation/encryption/rsa/reference-public-rsa-key.yml index f9f01ddf..be91f0ef 100644 --- a/data-manipulation/encryption/rsa/reference-public-rsa-key.yml +++ b/data-manipulation/encryption/rsa/reference-public-rsa-key.yml @@ -2,7 +2,7 @@ rule: meta: name: reference public RSA key namespace: data-manipulation/encryption/rsa - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Cryptography::Encryption Key [C0028] diff --git a/data-manipulation/hashing/fnv/hash-data-using-fnv.yml b/data-manipulation/hashing/fnv/hash-data-using-fnv.yml index 0a79c384..eb8d7030 100644 --- a/data-manipulation/hashing/fnv/hash-data-using-fnv.yml +++ b/data-manipulation/hashing/fnv/hash-data-using-fnv.yml @@ -3,9 +3,9 @@ rule: name: hash data using fnv namespace: data-manipulation/hashing/fnv author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - "@_re_fox" - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com description: can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1, FNV-1a, FNV-0 scope: function mbc: diff --git a/data-manipulation/hashing/hash-data-via-wincrypt.yml b/data-manipulation/hashing/hash-data-via-wincrypt.yml index 840854f2..c41b9cc8 100644 --- a/data-manipulation/hashing/hash-data-via-wincrypt.yml +++ b/data-manipulation/hashing/hash-data-via-wincrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data via WinCrypt namespace: data-manipulation/hashing - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Cryptography::Cryptographic Hash [C0029] diff --git a/data-manipulation/hashing/md5/hash-data-with-md5.yml b/data-manipulation/hashing/md5/hash-data-with-md5.yml index d937f769..3d6b208a 100644 --- a/data-manipulation/hashing/md5/hash-data-with-md5.yml +++ b/data-manipulation/hashing/md5/hash-data-with-md5.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data with MD5 namespace: data-manipulation/hashing/md5 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function references: - https://github.com/rwfpl/rewolf-x86-virtualizer/blob/master/src/test_app/main.cpp diff --git a/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml b/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml index 8dd811ba..de4fb82e 100644 --- a/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml +++ b/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using murmur3 namespace: data-manipulation/hashing/murmur - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function mbc: - Data::Non-Cryptographic Hash::MurmurHash [C0030.001] diff --git a/data-manipulation/hashing/sha1/hash-data-using-sha1.yml b/data-manipulation/hashing/sha1/hash-data-using-sha1.yml index 64bf7d43..ee498fb5 100644 --- a/data-manipulation/hashing/sha1/hash-data-using-sha1.yml +++ b/data-manipulation/hashing/sha1/hash-data-using-sha1.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using SHA1 namespace: data-manipulation/hashing/sha1 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Cryptography::Cryptographic Hash::SHA1 [C0029.002] diff --git a/data-manipulation/hashing/sha224/hash-data-using-sha224.yml b/data-manipulation/hashing/sha224/hash-data-using-sha224.yml index cfb30966..c7b487b9 100644 --- a/data-manipulation/hashing/sha224/hash-data-using-sha224.yml +++ b/data-manipulation/hashing/sha224/hash-data-using-sha224.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using SHA224 namespace: data-manipulation/hashing/sha224 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Cryptography::Cryptographic Hash::SHA224 [C0029.004] diff --git a/data-manipulation/hashing/sha256/hash-data-using-sha256.yml b/data-manipulation/hashing/sha256/hash-data-using-sha256.yml index 892d9c53..7547e7dd 100644 --- a/data-manipulation/hashing/sha256/hash-data-using-sha256.yml +++ b/data-manipulation/hashing/sha256/hash-data-using-sha256.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using SHA256 namespace: data-manipulation/hashing/sha256 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Cryptography::Cryptographic Hash::SHA256 [C0029.003] diff --git a/data-manipulation/hmac/authenticate-hmac.yml b/data-manipulation/hmac/authenticate-hmac.yml index 1de4f249..fb794939 100644 --- a/data-manipulation/hmac/authenticate-hmac.yml +++ b/data-manipulation/hmac/authenticate-hmac.yml @@ -2,7 +2,7 @@ rule: meta: name: authenticate HMAC namespace: data-manipulation/hmac - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function references: - https://tools.ietf.org/html/rfc2104 diff --git a/data-manipulation/prng/generate-random-numbers-via-winapi.yml b/data-manipulation/prng/generate-random-numbers-via-winapi.yml index 64253fce..cb6e7e8c 100644 --- a/data-manipulation/prng/generate-random-numbers-via-winapi.yml +++ b/data-manipulation/prng/generate-random-numbers-via-winapi.yml @@ -3,7 +3,7 @@ rule: name: generate random numbers via WinAPI namespace: data-manipulation/prng author: - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com - johnk3r scope: function mbc: diff --git a/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml b/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml index fb19b07d..59832f4e 100644 --- a/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml +++ b/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml @@ -2,7 +2,7 @@ rule: meta: name: generate random numbers using a Mersenne Twister namespace: data-manipulation/prng/mersenne - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Cryptography::Generate Pseudo-random Sequence::Mersenne Twister [C0021.005] diff --git a/executable/pe/pdb/contains-pdb-path.yml b/executable/pe/pdb/contains-pdb-path.yml index 4d004727..f97baebf 100644 --- a/executable/pe/pdb/contains-pdb-path.yml +++ b/executable/pe/pdb/contains-pdb-path.yml @@ -2,7 +2,7 @@ rule: meta: name: contains PDB path namespace: executable/pe/pdb - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file examples: - 464EF2CA59782CE697BC329713698CCC # level32.exe diff --git a/executable/pe/section/rsrc/contain-a-resource-rsrc-section.yml b/executable/pe/section/rsrc/contain-a-resource-rsrc-section.yml index 3ad91e2b..dbc4cb64 100644 --- a/executable/pe/section/rsrc/contain-a-resource-rsrc-section.yml +++ b/executable/pe/section/rsrc/contain-a-resource-rsrc-section.yml @@ -2,7 +2,7 @@ rule: meta: name: contain a resource (.rsrc) section namespace: executable/pe/section/rsrc - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file examples: - A933A1A402775CFA94B6BEE0963F4B46:0x41fd25 diff --git a/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml b/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml index 9fab1655..cc7430e8 100644 --- a/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml +++ b/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml @@ -2,7 +2,7 @@ rule: meta: name: contain a thread local storage (.tls) section namespace: executable/pe/section/tls - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: file examples: - Practical Malware Analysis Lab 16-02.exe_ diff --git a/executable/resource/extract-resource-via-kernel32-functions.yml b/executable/resource/extract-resource-via-kernel32-functions.yml index 661f0bba..48ab15ff 100644 --- a/executable/resource/extract-resource-via-kernel32-functions.yml +++ b/executable/resource/extract-resource-via-kernel32-functions.yml @@ -2,7 +2,7 @@ rule: meta: name: extract resource via kernel32 functions namespace: executable/resource - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function examples: - BF88E1BD4A3BDE10B419A622278F1FF7:0x401000 diff --git a/executable/subfile/pe/contain-an-embedded-pe-file.yml b/executable/subfile/pe/contain-an-embedded-pe-file.yml index 8106abc3..d6f88b54 100644 --- a/executable/subfile/pe/contain-an-embedded-pe-file.yml +++ b/executable/subfile/pe/contain-an-embedded-pe-file.yml @@ -2,7 +2,7 @@ rule: meta: name: contain an embedded PE file namespace: executable/subfile/pe - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file mbc: - Execution::Install Additional Program [B0023] diff --git a/host-interaction/bootloader/disable-code-signing.yml b/host-interaction/bootloader/disable-code-signing.yml index 6a2d9f39..3532379e 100644 --- a/host-interaction/bootloader/disable-code-signing.yml +++ b/host-interaction/bootloader/disable-code-signing.yml @@ -2,7 +2,7 @@ rule: meta: name: disable code signing namespace: host-interaction/bootloader - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Subvert Trust Controls::Code Signing Policy Modification [T1553.006] diff --git a/host-interaction/bootloader/manipulate-boot-configuration.yml b/host-interaction/bootloader/manipulate-boot-configuration.yml index 3d2c37d1..ccbd67ae 100644 --- a/host-interaction/bootloader/manipulate-boot-configuration.yml +++ b/host-interaction/bootloader/manipulate-boot-configuration.yml @@ -2,7 +2,7 @@ rule: meta: name: manipulate boot configuration namespace: host-interaction/bootloader - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/bcdedit-command-line-options diff --git a/host-interaction/cli/accept-command-line-arguments.yml b/host-interaction/cli/accept-command-line-arguments.yml index 739754ec..9001a6c1 100644 --- a/host-interaction/cli/accept-command-line-arguments.yml +++ b/host-interaction/cli/accept-command-line-arguments.yml @@ -2,7 +2,7 @@ rule: meta: name: accept command line arguments namespace: host-interaction/cli - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Execution::Command and Scripting Interpreter [T1059] diff --git a/host-interaction/clipboard/open-clipboard.yml b/host-interaction/clipboard/open-clipboard.yml index 97d1fba7..6b3517bf 100644 --- a/host-interaction/clipboard/open-clipboard.yml +++ b/host-interaction/clipboard/open-clipboard.yml @@ -2,7 +2,7 @@ rule: meta: name: open clipboard namespace: host-interaction/clipboard - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Clipboard Data [T1115] diff --git a/host-interaction/clipboard/read-clipboard-data.yml b/host-interaction/clipboard/read-clipboard-data.yml index deca8a39..9aff144d 100644 --- a/host-interaction/clipboard/read-clipboard-data.yml +++ b/host-interaction/clipboard/read-clipboard-data.yml @@ -2,7 +2,7 @@ rule: meta: name: read clipboard data namespace: host-interaction/clipboard - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Clipboard Data [T1115] diff --git a/host-interaction/clipboard/replace-clipboard-data.yml b/host-interaction/clipboard/replace-clipboard-data.yml index 7485927e..6368434f 100644 --- a/host-interaction/clipboard/replace-clipboard-data.yml +++ b/host-interaction/clipboard/replace-clipboard-data.yml @@ -2,7 +2,7 @@ rule: meta: name: replace clipboard data namespace: host-interaction/clipboard - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Impact::Clipboard Modification [E1510] diff --git a/host-interaction/clipboard/write-clipboard-data.yml b/host-interaction/clipboard/write-clipboard-data.yml index 43168e5a..c20b483e 100644 --- a/host-interaction/clipboard/write-clipboard-data.yml +++ b/host-interaction/clipboard/write-clipboard-data.yml @@ -2,7 +2,7 @@ rule: meta: name: write clipboard data namespace: host-interaction/clipboard - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Impact::Clipboard Modification [E1510] diff --git a/host-interaction/console/manipulate-console.yml b/host-interaction/console/manipulate-console.yml index 3b20e86f..8e21328f 100644 --- a/host-interaction/console/manipulate-console.yml +++ b/host-interaction/console/manipulate-console.yml @@ -2,7 +2,7 @@ rule: meta: name: manipulate console namespace: host-interaction/console - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function mbc: - Operating System::Console [C0033] diff --git a/host-interaction/driver/disable-driver-code-integrity.yml b/host-interaction/driver/disable-driver-code-integrity.yml index 90208946..da86aab7 100644 --- a/host-interaction/driver/disable-driver-code-integrity.yml +++ b/host-interaction/driver/disable-driver-code-integrity.yml @@ -2,7 +2,7 @@ rule: meta: name: disable driver code integrity namespace: host-interaction/driver - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.fuzzysecurity.com/tutorials/28.html diff --git a/host-interaction/driver/install-driver.yml b/host-interaction/driver/install-driver.yml index 66325f17..2c4d1f4f 100644 --- a/host-interaction/driver/install-driver.yml +++ b/host-interaction/driver/install-driver.yml @@ -2,7 +2,7 @@ rule: meta: name: install driver namespace: host-interaction/driver - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/host-interaction/driver/interact-with-driver-via-control-codes.yml b/host-interaction/driver/interact-with-driver-via-control-codes.yml index bd67329d..0deceb3a 100644 --- a/host-interaction/driver/interact-with-driver-via-control-codes.yml +++ b/host-interaction/driver/interact-with-driver-via-control-codes.yml @@ -2,7 +2,7 @@ rule: meta: name: interact with driver via control codes namespace: host-interaction/driver - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Execution::System Services::Service Execution [T1569.002] diff --git a/host-interaction/environment-variable/get-comspec-environment-variable.yml b/host-interaction/environment-variable/get-comspec-environment-variable.yml index e30e58dc..57df8c56 100644 --- a/host-interaction/environment-variable/get-comspec-environment-variable.yml +++ b/host-interaction/environment-variable/get-comspec-environment-variable.yml @@ -2,7 +2,7 @@ rule: meta: name: get COMSPEC environment variable namespace: host-interaction/environment-variable - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function examples: - Practical Malware Analysis Lab 14-02.exe_:0x401880 diff --git a/host-interaction/environment-variable/query-environment-variable.yml b/host-interaction/environment-variable/query-environment-variable.yml index 96d1594a..46797de2 100644 --- a/host-interaction/environment-variable/query-environment-variable.yml +++ b/host-interaction/environment-variable/query-environment-variable.yml @@ -3,7 +3,7 @@ rule: name: query environment variable namespace: host-interaction/environment-variable author: - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com - "@_re_fox" scope: function att&ck: diff --git a/host-interaction/environment-variable/set-environment-variable.yml b/host-interaction/environment-variable/set-environment-variable.yml index b3597e74..99544c09 100644 --- a/host-interaction/environment-variable/set-environment-variable.yml +++ b/host-interaction/environment-variable/set-environment-variable.yml @@ -2,7 +2,7 @@ rule: meta: name: set environment variable namespace: host-interaction/environment-variable - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Operating System::Environment Variable::Set Variable [C0034.001] diff --git a/host-interaction/file-system/bypass-mark-of-the-web.yml b/host-interaction/file-system/bypass-mark-of-the-web.yml index 853a0d7c..9ab18aa2 100644 --- a/host-interaction/file-system/bypass-mark-of-the-web.yml +++ b/host-interaction/file-system/bypass-mark-of-the-web.yml @@ -2,7 +2,7 @@ rule: meta: name: bypass Mark of the Web namespace: host-interaction/file-system - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Subvert Trust Controls::Mark-of-the-Web Bypass [T1553.005] diff --git a/host-interaction/file-system/copy/copy-file.yml b/host-interaction/file-system/copy/copy-file.yml index 98062809..ed06fd26 100644 --- a/host-interaction/file-system/copy/copy-file.yml +++ b/host-interaction/file-system/copy/copy-file.yml @@ -2,7 +2,7 @@ rule: meta: name: copy file namespace: host-interaction/file-system/copy - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - File System::Copy File [C0045] diff --git a/host-interaction/file-system/create/create-directory.yml b/host-interaction/file-system/create/create-directory.yml index 1fafe7be..08cb9f8f 100644 --- a/host-interaction/file-system/create/create-directory.yml +++ b/host-interaction/file-system/create/create-directory.yml @@ -2,7 +2,7 @@ rule: meta: name: create directory namespace: host-interaction/file-system/create - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - File System::Create Directory [C0046] diff --git a/host-interaction/file-system/delete/delete-directory.yml b/host-interaction/file-system/delete/delete-directory.yml index 37857268..f5f75f64 100644 --- a/host-interaction/file-system/delete/delete-directory.yml +++ b/host-interaction/file-system/delete/delete-directory.yml @@ -2,7 +2,7 @@ rule: meta: name: delete directory namespace: host-interaction/file-system/delete - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - File System::Delete Directory [C0048] diff --git a/host-interaction/file-system/delete/delete-file.yml b/host-interaction/file-system/delete/delete-file.yml index 6250a7e8..6d7e5793 100644 --- a/host-interaction/file-system/delete/delete-file.yml +++ b/host-interaction/file-system/delete/delete-file.yml @@ -2,7 +2,7 @@ rule: meta: name: delete file namespace: host-interaction/file-system/delete - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - File System::Delete File [C0047] diff --git a/host-interaction/file-system/exists/check-if-file-exists.yml b/host-interaction/file-system/exists/check-if-file-exists.yml index 22923a0f..416e765f 100644 --- a/host-interaction/file-system/exists/check-if-file-exists.yml +++ b/host-interaction/file-system/exists/check-if-file-exists.yml @@ -2,7 +2,7 @@ rule: meta: name: check if file exists namespace: host-interaction/file-system/exists - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/files/list/enumerate-files-on-linux.yml b/host-interaction/file-system/files/list/enumerate-files-on-linux.yml index 8f31f8c6..42087468 100644 --- a/host-interaction/file-system/files/list/enumerate-files-on-linux.yml +++ b/host-interaction/file-system/files/list/enumerate-files-on-linux.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate files on Linux namespace: host-interaction/file-system/files/list - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/files/list/enumerate-files-via-kernel32-functions.yml b/host-interaction/file-system/files/list/enumerate-files-via-kernel32-functions.yml index 876660aa..d09ffb27 100644 --- a/host-interaction/file-system/files/list/enumerate-files-via-kernel32-functions.yml +++ b/host-interaction/file-system/files/list/enumerate-files-via-kernel32-functions.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate files via kernel32 functions namespace: host-interaction/file-system/files/list - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/files/list/enumerate-files-via-ntdll-functions.yml b/host-interaction/file-system/files/list/enumerate-files-via-ntdll-functions.yml index ef16afb7..5bed5a8d 100644 --- a/host-interaction/file-system/files/list/enumerate-files-via-ntdll-functions.yml +++ b/host-interaction/file-system/files/list/enumerate-files-via-ntdll-functions.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate files via ntdll functions namespace: host-interaction/file-system/files/list - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/get-common-file-path.yml b/host-interaction/file-system/get-common-file-path.yml index c76c6341..77513fdd 100644 --- a/host-interaction/file-system/get-common-file-path.yml +++ b/host-interaction/file-system/get-common-file-path.yml @@ -2,7 +2,7 @@ rule: meta: name: get common file path namespace: host-interaction/file-system - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/get-file-system-object-information.yml b/host-interaction/file-system/get-file-system-object-information.yml index a3300d89..d9008663 100644 --- a/host-interaction/file-system/get-file-system-object-information.yml +++ b/host-interaction/file-system/get-file-system-object-information.yml @@ -2,7 +2,7 @@ rule: meta: name: get file system object information namespace: host-interaction/file-system - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/get-program-files-directory.yml b/host-interaction/file-system/get-program-files-directory.yml index 9f6a33b5..107a71d6 100644 --- a/host-interaction/file-system/get-program-files-directory.yml +++ b/host-interaction/file-system/get-program-files-directory.yml @@ -2,7 +2,7 @@ rule: meta: name: get Program Files directory namespace: host-interaction/file-system - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/meta/get-file-attributes.yml b/host-interaction/file-system/meta/get-file-attributes.yml index 441e7739..514f8ff5 100644 --- a/host-interaction/file-system/meta/get-file-attributes.yml +++ b/host-interaction/file-system/meta/get-file-attributes.yml @@ -2,7 +2,7 @@ rule: meta: name: get file attributes namespace: host-interaction/file-system/meta - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - File System::Get File Attributes [C0049] diff --git a/host-interaction/file-system/meta/get-file-size.yml b/host-interaction/file-system/meta/get-file-size.yml index 3eb6c9bd..2b18305c 100644 --- a/host-interaction/file-system/meta/get-file-size.yml +++ b/host-interaction/file-system/meta/get-file-size.yml @@ -2,7 +2,7 @@ rule: meta: name: get file size namespace: host-interaction/file-system/meta - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/meta/get-file-version-info.yml b/host-interaction/file-system/meta/get-file-version-info.yml index 2f30fe6d..ed208d6b 100644 --- a/host-interaction/file-system/meta/get-file-version-info.yml +++ b/host-interaction/file-system/meta/get-file-version-info.yml @@ -2,7 +2,7 @@ rule: meta: name: get file version info namespace: host-interaction/file-system/meta - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::File and Directory Discovery [T1083] diff --git a/host-interaction/file-system/meta/set-file-attributes.yml b/host-interaction/file-system/meta/set-file-attributes.yml index 0c214612..c8f646c1 100644 --- a/host-interaction/file-system/meta/set-file-attributes.yml +++ b/host-interaction/file-system/meta/set-file-attributes.yml @@ -3,8 +3,8 @@ rule: name: set file attributes namespace: host-interaction/file-system/meta author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com scope: basic block att&ck: - Defense Evasion::File and Directory Permissions Modification [T1222] diff --git a/host-interaction/file-system/move/move-file.yml b/host-interaction/file-system/move/move-file.yml index fbf6b46b..1212f479 100644 --- a/host-interaction/file-system/move/move-file.yml +++ b/host-interaction/file-system/move/move-file.yml @@ -2,7 +2,7 @@ rule: meta: name: move file namespace: host-interaction/file-system/move - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function examples: - Practical Malware Analysis Lab 01-04.exe_:0x401350 diff --git a/host-interaction/file-system/read/read-file-on-windows.yml b/host-interaction/file-system/read/read-file-on-windows.yml index 923d09ad..6992c1ce 100644 --- a/host-interaction/file-system/read/read-file-on-windows.yml +++ b/host-interaction/file-system/read/read-file-on-windows.yml @@ -3,7 +3,7 @@ rule: name: read file on Windows namespace: host-interaction/file-system/read author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com scope: function mbc: - File System::Read File [C0051] diff --git a/host-interaction/file-system/read/read-file-via-mapping.yml b/host-interaction/file-system/read/read-file-via-mapping.yml index 3969f4d9..9d65b09e 100644 --- a/host-interaction/file-system/read/read-file-via-mapping.yml +++ b/host-interaction/file-system/read/read-file-via-mapping.yml @@ -2,7 +2,7 @@ rule: meta: name: read file via mapping namespace: host-interaction/file-system/read - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function examples: - Practical Malware Analysis Lab 01-01.exe_:0x401440 diff --git a/host-interaction/file-system/read/read-ini-file.yml b/host-interaction/file-system/read/read-ini-file.yml index bf9a6a2b..c1f71910 100644 --- a/host-interaction/file-system/read/read-ini-file.yml +++ b/host-interaction/file-system/read/read-ini-file.yml @@ -4,7 +4,7 @@ rule: namespace: host-interaction/file-system/read author: - "@_re_fox" - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com scope: function mbc: - File System::Read File [C0051] diff --git a/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml b/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml index 3a86d08b..8716d315 100644 --- a/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml +++ b/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml @@ -2,7 +2,7 @@ rule: meta: name: bypass Windows File Protection namespace: host-interaction/file-system/windows-file-protection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Defense Evasion::Disable or Evade Security Tools::Bypass Windows File Protection [F0004.007] diff --git a/host-interaction/file-system/write/write-file-on-windows.yml b/host-interaction/file-system/write/write-file-on-windows.yml index be4cc69e..50941d17 100644 --- a/host-interaction/file-system/write/write-file-on-windows.yml +++ b/host-interaction/file-system/write/write-file-on-windows.yml @@ -3,7 +3,7 @@ rule: name: write file on Windows namespace: host-interaction/file-system/write author: - - william.ballenthin@fireeye.com + - william.ballenthin@mandiant.com scope: function mbc: - File System::Writes File [C0052] diff --git a/host-interaction/filter/register-minifilter-driver.yml b/host-interaction/filter/register-minifilter-driver.yml index 43f35b20..07c6bd12 100644 --- a/host-interaction/filter/register-minifilter-driver.yml +++ b/host-interaction/filter/register-minifilter-driver.yml @@ -2,7 +2,7 @@ rule: meta: name: register minifilter driver namespace: host-interaction/filter - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block references: - https://docs.microsoft.com/en-us/windows-hardware/drivers/ifs/filter-manager-concepts diff --git a/host-interaction/filter/start-minifilter-driver.yml b/host-interaction/filter/start-minifilter-driver.yml index d1b16fd9..91a01be9 100644 --- a/host-interaction/filter/start-minifilter-driver.yml +++ b/host-interaction/filter/start-minifilter-driver.yml @@ -2,7 +2,7 @@ rule: meta: name: start minifilter driver namespace: host-interaction/filter - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block references: - https://docs.microsoft.com/en-us/windows-hardware/drivers/ifs/filter-manager-concepts diff --git a/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml b/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml index e5005375..b4bf72a5 100644 --- a/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml +++ b/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml @@ -2,7 +2,7 @@ rule: meta: name: access firewall settings via INetFwMgr namespace: host-interaction/firewall/modify - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::Software Discovery::Security Software Discovery [T1518.001] diff --git a/host-interaction/gui/console/set-console-window-title.yml b/host-interaction/gui/console/set-console-window-title.yml index 3c305a02..045d3999 100644 --- a/host-interaction/gui/console/set-console-window-title.yml +++ b/host-interaction/gui/console/set-console-window-title.yml @@ -2,7 +2,7 @@ rule: meta: name: set console window title namespace: host-interaction/gui/console - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function examples: - mimikatz.exe_:0x44570F diff --git a/host-interaction/gui/session/lock/lock-the-desktop.yml b/host-interaction/gui/session/lock/lock-the-desktop.yml index 5d2ce073..d7a8f5db 100644 --- a/host-interaction/gui/session/lock/lock-the-desktop.yml +++ b/host-interaction/gui/session/lock/lock-the-desktop.yml @@ -2,7 +2,7 @@ rule: meta: name: lock the desktop namespace: host-interaction/gui/session/lock - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Impact::Endpoint Denial of Service [T1499] diff --git a/host-interaction/gui/set-application-hook.yml b/host-interaction/gui/set-application-hook.yml index 43f41e6e..75a53150 100644 --- a/host-interaction/gui/set-application-hook.yml +++ b/host-interaction/gui/set-application-hook.yml @@ -2,7 +2,7 @@ rule: meta: name: set application hook namespace: host-interaction/gui - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function examples: - Practical Malware Analysis Lab 12-03.exe_:0x401000 diff --git a/host-interaction/gui/taskbar/find/find-taskbar.yml b/host-interaction/gui/taskbar/find/find-taskbar.yml index dcc7ae9c..0c6d451c 100644 --- a/host-interaction/gui/taskbar/find/find-taskbar.yml +++ b/host-interaction/gui/taskbar/find/find-taskbar.yml @@ -2,7 +2,7 @@ rule: meta: name: find taskbar namespace: host-interaction/gui/taskbar/find - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Discovery::Taskbar Discovery [B0043] diff --git a/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml b/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml index 15528b14..afce5b75 100644 --- a/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml +++ b/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml @@ -2,7 +2,7 @@ rule: meta: name: hide the Windows taskbar namespace: host-interaction/gui/taskbar/hide - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Hide Artifacts [T1564] diff --git a/host-interaction/gui/window/find/find-graphical-window.yml b/host-interaction/gui/window/find/find-graphical-window.yml index 0750fc6a..4d410f46 100644 --- a/host-interaction/gui/window/find/find-graphical-window.yml +++ b/host-interaction/gui/window/find/find-graphical-window.yml @@ -2,7 +2,7 @@ rule: meta: name: find graphical window namespace: host-interaction/gui/window/find - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::Application Window Discovery [T1010] diff --git a/host-interaction/gui/window/get-text/get-graphical-window-text.yml b/host-interaction/gui/window/get-text/get-graphical-window-text.yml index 4f8b9a4f..527bfc3c 100644 --- a/host-interaction/gui/window/get-text/get-graphical-window-text.yml +++ b/host-interaction/gui/window/get-text/get-graphical-window-text.yml @@ -2,7 +2,7 @@ rule: meta: name: get graphical window text namespace: host-interaction/gui/window/get-text - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Discovery::Application Window Discovery::Window Text [E1010.m01] diff --git a/host-interaction/gui/window/hide/hide-graphical-window.yml b/host-interaction/gui/window/hide/hide-graphical-window.yml index 5eec824c..90c36a23 100644 --- a/host-interaction/gui/window/hide/hide-graphical-window.yml +++ b/host-interaction/gui/window/hide/hide-graphical-window.yml @@ -2,7 +2,7 @@ rule: meta: name: hide graphical window namespace: host-interaction/gui/window/hide - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Defense Evasion::Hide Artifacts::Hidden Window [T1564.003] diff --git a/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml b/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml index f966e802..0d990716 100644 --- a/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml +++ b/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml @@ -2,7 +2,7 @@ rule: meta: name: manipulate CD-ROM drive namespace: host-interaction/hardware/cdrom - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Impact::Modify Hardware::CDROM [B0042.001] diff --git a/host-interaction/hardware/cpu/get-cpu-information.yml b/host-interaction/hardware/cpu/get-cpu-information.yml index 8482675b..d2d7205b 100644 --- a/host-interaction/hardware/cpu/get-cpu-information.yml +++ b/host-interaction/hardware/cpu/get-cpu-information.yml @@ -3,7 +3,7 @@ rule: name: get CPU information namespace: host-interaction/hardware/cpu author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function att&ck: diff --git a/host-interaction/hardware/cpu/get-number-of-processor-cores.yml b/host-interaction/hardware/cpu/get-number-of-processor-cores.yml index 93798194..2e72d3a3 100644 --- a/host-interaction/hardware/cpu/get-number-of-processor-cores.yml +++ b/host-interaction/hardware/cpu/get-number-of-processor-cores.yml @@ -2,7 +2,7 @@ rule: meta: name: get number of processor cores namespace: host-interaction/hardware/cpu - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/hardware/cpu/get-number-of-processors.yml b/host-interaction/hardware/cpu/get-number-of-processors.yml index 8db5e6d5..4b3895fd 100644 --- a/host-interaction/hardware/cpu/get-number-of-processors.yml +++ b/host-interaction/hardware/cpu/get-number-of-processors.yml @@ -2,7 +2,7 @@ rule: meta: name: get number of processors namespace: host-interaction/hardware/cpu - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/hardware/keyboard/layout/get-keyboard-layout.yml b/host-interaction/hardware/keyboard/layout/get-keyboard-layout.yml index c3d43b17..49ba7e25 100644 --- a/host-interaction/hardware/keyboard/layout/get-keyboard-layout.yml +++ b/host-interaction/hardware/keyboard/layout/get-keyboard-layout.yml @@ -2,7 +2,7 @@ rule: meta: name: get keyboard layout namespace: host-interaction/hardware/keyboard/layout - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml b/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml index ae288ecb..9aedf1c4 100644 --- a/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml +++ b/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml @@ -3,7 +3,7 @@ rule: name: simulate CTRL ALT DEL namespace: host-interaction/hardware/keyboard author: - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com - johnk3r scope: function mbc: diff --git a/host-interaction/hardware/memory/get-memory-capacity.yml b/host-interaction/hardware/memory/get-memory-capacity.yml index 83d52020..1df3f5b6 100644 --- a/host-interaction/hardware/memory/get-memory-capacity.yml +++ b/host-interaction/hardware/memory/get-memory-capacity.yml @@ -2,7 +2,7 @@ rule: meta: name: get memory capacity namespace: host-interaction/hardware/memory - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/hardware/mouse/swap-mouse-buttons.yml b/host-interaction/hardware/mouse/swap-mouse-buttons.yml index 69e22c58..666d7abb 100644 --- a/host-interaction/hardware/mouse/swap-mouse-buttons.yml +++ b/host-interaction/hardware/mouse/swap-mouse-buttons.yml @@ -2,7 +2,7 @@ rule: meta: name: swap mouse buttons namespace: host-interaction/hardware/mouse - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Impact::Modify Hardware::Mouse [B0042.002] diff --git a/host-interaction/hardware/storage/enumerate-disk-properties.yml b/host-interaction/hardware/storage/enumerate-disk-properties.yml index 9b164607..4d7b9783 100644 --- a/host-interaction/hardware/storage/enumerate-disk-properties.yml +++ b/host-interaction/hardware/storage/enumerate-disk-properties.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate disk properties namespace: host-interaction/hardware/storage - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/hardware/storage/get-disk-information.yml b/host-interaction/hardware/storage/get-disk-information.yml index c2ce8030..e174a6a9 100644 --- a/host-interaction/hardware/storage/get-disk-information.yml +++ b/host-interaction/hardware/storage/get-disk-information.yml @@ -2,7 +2,7 @@ rule: meta: name: get disk information namespace: host-interaction/hardware/storage - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/hardware/storage/get-disk-size.yml b/host-interaction/hardware/storage/get-disk-size.yml index 04587f2d..958c84e1 100644 --- a/host-interaction/hardware/storage/get-disk-size.yml +++ b/host-interaction/hardware/storage/get-disk-size.yml @@ -2,7 +2,7 @@ rule: meta: name: get disk size namespace: host-interaction/hardware/storage - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/host-interaction/log/debug/write-event/print-debug-messages.yml b/host-interaction/log/debug/write-event/print-debug-messages.yml index 5a58da4e..102b5263 100644 --- a/host-interaction/log/debug/write-event/print-debug-messages.yml +++ b/host-interaction/log/debug/write-event/print-debug-messages.yml @@ -2,7 +2,7 @@ rule: meta: name: print debug messages namespace: host-interaction/log/debug/write-event - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function examples: - 493167E85E45363D09495D0841C30648:0x401000 diff --git a/host-interaction/log/winevt/access/access-the-windows-event-log.yml b/host-interaction/log/winevt/access/access-the-windows-event-log.yml index 8719cc0b..edfc8712 100644 --- a/host-interaction/log/winevt/access/access-the-windows-event-log.yml +++ b/host-interaction/log/winevt/access/access-the-windows-event-log.yml @@ -2,7 +2,7 @@ rule: meta: name: access the Windows event log namespace: host-interaction/log/winevt/access - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Discovery::File and Directory Discovery::Log File [E1083.m01] diff --git a/host-interaction/mutex/check-mutex-and-exit.yml b/host-interaction/mutex/check-mutex-and-exit.yml index 8d410ac8..907b3d39 100644 --- a/host-interaction/mutex/check-mutex-and-exit.yml +++ b/host-interaction/mutex/check-mutex-and-exit.yml @@ -4,7 +4,7 @@ rule: namespace: host-interaction/mutex author: - "@_re_fox" - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com scope: function mbc: - Process::Check Mutex [C0043] diff --git a/host-interaction/mutex/check-mutex.yml b/host-interaction/mutex/check-mutex.yml index 7ff482e4..5a2c4e67 100644 --- a/host-interaction/mutex/check-mutex.yml +++ b/host-interaction/mutex/check-mutex.yml @@ -2,7 +2,7 @@ rule: meta: name: check mutex namespace: host-interaction/mutex - author: moritz.raabem@fireeye.com + author: moritz.raabem@mandiant.com scope: basic block mbc: - Process::Check Mutex [C0043] diff --git a/host-interaction/mutex/create-mutex.yml b/host-interaction/mutex/create-mutex.yml index 62146087..14aa8269 100644 --- a/host-interaction/mutex/create-mutex.yml +++ b/host-interaction/mutex/create-mutex.yml @@ -2,7 +2,7 @@ rule: meta: name: create mutex namespace: host-interaction/mutex - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Process::Create Mutex [C0042] diff --git a/host-interaction/network/address/get-local-ipv4-addresses.yml b/host-interaction/network/address/get-local-ipv4-addresses.yml index 642a3ca8..3147acbb 100644 --- a/host-interaction/network/address/get-local-ipv4-addresses.yml +++ b/host-interaction/network/address/get-local-ipv4-addresses.yml @@ -3,7 +3,7 @@ rule: name: get local IPv4 addresses namespace: host-interaction/network/address author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function att&ck: diff --git a/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml b/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml index e63640d6..140c45b8 100644 --- a/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml +++ b/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml @@ -3,8 +3,8 @@ rule: name: check Internet connectivity via WinINet namespace: host-interaction/network/connectivity author: - - matthew.williams@fireeye.com - - michael.hunhoff@fireeye.com + - matthew.williams@mandiant.com + - michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::System Network Configuration Discovery::Internet Connection Discovery [T1016.001] diff --git a/host-interaction/network/dns/resolve/resolve-dns.yml b/host-interaction/network/dns/resolve/resolve-dns.yml index 08f0c336..659b575a 100644 --- a/host-interaction/network/dns/resolve/resolve-dns.yml +++ b/host-interaction/network/dns/resolve/resolve-dns.yml @@ -3,7 +3,7 @@ rule: name: resolve DNS namespace: host-interaction/network/dns/resolve author: - - william.ballenthin@fireeye.com + - william.ballenthin@mandiant.com - johnk3r - joakim@intezer.com scope: function diff --git a/host-interaction/network/interface/get-networking-interfaces.yml b/host-interaction/network/interface/get-networking-interfaces.yml index 000e3f8f..86637564 100644 --- a/host-interaction/network/interface/get-networking-interfaces.yml +++ b/host-interaction/network/interface/get-networking-interfaces.yml @@ -3,7 +3,7 @@ rule: name: get networking interfaces namespace: host-interaction/network/interface author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function att&ck: diff --git a/host-interaction/network/traffic/copy/copy-network-traffic.yml b/host-interaction/network/traffic/copy/copy-network-traffic.yml index 6698b3fb..d84735a4 100644 --- a/host-interaction/network/traffic/copy/copy-network-traffic.yml +++ b/host-interaction/network/traffic/copy/copy-network-traffic.yml @@ -2,7 +2,7 @@ rule: meta: name: copy network traffic namespace: host-interaction/network/traffic/copy - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Network Sniffing [T1040] diff --git a/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml b/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml index 75276d8f..71255f8b 100644 --- a/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml +++ b/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml @@ -2,7 +2,7 @@ rule: meta: name: register network filter via WFP API namespace: host-interaction/network/traffic/filter - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Impact::Data Manipulation::Transmitted Data Manipulation [T1565.002] diff --git a/host-interaction/os/hostname/get-hostname.yml b/host-interaction/os/hostname/get-hostname.yml index 64cf1653..430ab8e9 100644 --- a/host-interaction/os/hostname/get-hostname.yml +++ b/host-interaction/os/hostname/get-hostname.yml @@ -3,7 +3,7 @@ rule: name: get hostname namespace: host-interaction/os/hostname author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function att&ck: diff --git a/host-interaction/os/info/get-system-information-on-windows.yml b/host-interaction/os/info/get-system-information-on-windows.yml index 13075920..fb1858d2 100644 --- a/host-interaction/os/info/get-system-information-on-windows.yml +++ b/host-interaction/os/info/get-system-information-on-windows.yml @@ -3,7 +3,7 @@ rule: name: get system information on Windows namespace: host-interaction/os/info author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function att&ck: diff --git a/host-interaction/os/shutdown-system.yml b/host-interaction/os/shutdown-system.yml index 43e5b2db..26c79203 100644 --- a/host-interaction/os/shutdown-system.yml +++ b/host-interaction/os/shutdown-system.yml @@ -2,7 +2,7 @@ rule: meta: name: shutdown system namespace: host-interaction/os - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Impact::System Shutdown/Reboot [T1529] diff --git a/host-interaction/os/version/check-os-version.yml b/host-interaction/os/version/check-os-version.yml index 3c6d15b0..d2c9f829 100644 --- a/host-interaction/os/version/check-os-version.yml +++ b/host-interaction/os/version/check-os-version.yml @@ -3,7 +3,7 @@ rule: name: check OS version namespace: host-interaction/os/version author: - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com - johnk3r scope: function att&ck: diff --git a/host-interaction/process/allocate-thread-local-storage.yml b/host-interaction/process/allocate-thread-local-storage.yml index 85cecc25..801a5f62 100644 --- a/host-interaction/process/allocate-thread-local-storage.yml +++ b/host-interaction/process/allocate-thread-local-storage.yml @@ -2,7 +2,7 @@ rule: meta: name: allocate thread local storage namespace: host-interaction/process - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Process::Allocate Thread Local Storage [C0040] diff --git a/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml b/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml index 8c5d9613..6fd47a1f 100644 --- a/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml +++ b/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml @@ -2,7 +2,7 @@ rule: meta: name: create a process with modified I/O handles and window namespace: host-interaction/process/create - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function mbc: - Process::Create Process [C0017] diff --git a/host-interaction/process/create/create-process-on-windows.yml b/host-interaction/process/create/create-process-on-windows.yml index 9df01126..af112731 100644 --- a/host-interaction/process/create/create-process-on-windows.yml +++ b/host-interaction/process/create/create-process-on-windows.yml @@ -3,7 +3,7 @@ rule: name: create process on Windows namespace: host-interaction/process/create author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com scope: basic block mbc: - Process::Create Process [C0017] diff --git a/host-interaction/process/create/create-process-suspended.yml b/host-interaction/process/create/create-process-suspended.yml index d800d896..a897ffd0 100644 --- a/host-interaction/process/create/create-process-suspended.yml +++ b/host-interaction/process/create/create-process-suspended.yml @@ -2,7 +2,7 @@ rule: meta: name: create process suspended namespace: host-interaction/process/create - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: basic block mbc: - Process::Create Process::Create Suspended Process [C0017.003] diff --git a/host-interaction/process/dump/create-process-memory-minidump.yml b/host-interaction/process/dump/create-process-memory-minidump.yml index 8ac595d0..091ca5e2 100644 --- a/host-interaction/process/dump/create-process-memory-minidump.yml +++ b/host-interaction/process/dump/create-process-memory-minidump.yml @@ -3,7 +3,7 @@ rule: meta: name: create process memory minidump namespace: host-interaction/process/dump - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block examples: - 91a12a4cf437589ba70b1687f5acad19:0x43E1C9 diff --git a/host-interaction/process/get-process-heap-flags.yml b/host-interaction/process/get-process-heap-flags.yml index 048107c9..1ecc43d6 100644 --- a/host-interaction/process/get-process-heap-flags.yml +++ b/host-interaction/process/get-process-heap-flags.yml @@ -2,7 +2,7 @@ rule: meta: name: get process heap flags namespace: host-interaction/process - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/get-process-heap-force-flags.yml b/host-interaction/process/get-process-heap-force-flags.yml index 918b5dae..7de5c80c 100644 --- a/host-interaction/process/get-process-heap-force-flags.yml +++ b/host-interaction/process/get-process-heap-force-flags.yml @@ -2,7 +2,7 @@ rule: meta: name: get process heap force flags namespace: host-interaction/process - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/inject/allocate-rwx-memory.yml b/host-interaction/process/inject/allocate-rwx-memory.yml index ef5da8ca..8e3d3d45 100644 --- a/host-interaction/process/inject/allocate-rwx-memory.yml +++ b/host-interaction/process/inject/allocate-rwx-memory.yml @@ -2,7 +2,7 @@ rule: meta: name: allocate RWX memory namespace: host-interaction/process/inject - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block mbc: - Memory::Allocate Memory [C0007] diff --git a/host-interaction/process/inject/allocate-user-process-rwx-memory.yml b/host-interaction/process/inject/allocate-user-process-rwx-memory.yml index b63925d5..3bbe1ce7 100644 --- a/host-interaction/process/inject/allocate-user-process-rwx-memory.yml +++ b/host-interaction/process/inject/allocate-user-process-rwx-memory.yml @@ -2,7 +2,7 @@ rule: meta: name: allocate user process RWX memory namespace: host-interaction/process/inject - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Process Injection [T1055] diff --git a/host-interaction/process/inject/attach-user-process-memory.yml b/host-interaction/process/inject/attach-user-process-memory.yml index 31d8f707..74cf5f3c 100644 --- a/host-interaction/process/inject/attach-user-process-memory.yml +++ b/host-interaction/process/inject/attach-user-process-memory.yml @@ -2,7 +2,7 @@ rule: meta: name: attach user process memory namespace: host-interaction/process/inject - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Process Injection [T1055] diff --git a/host-interaction/process/inject/free-user-process-memory.yml b/host-interaction/process/inject/free-user-process-memory.yml index a19d3704..ae321f17 100644 --- a/host-interaction/process/inject/free-user-process-memory.yml +++ b/host-interaction/process/inject/free-user-process-memory.yml @@ -2,7 +2,7 @@ rule: meta: name: free user process memory namespace: host-interaction/process/inject - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Process Injection [T1055] diff --git a/host-interaction/process/inject/inject-apc.yml b/host-interaction/process/inject/inject-apc.yml index 2ff25bf3..0eca6a06 100644 --- a/host-interaction/process/inject/inject-apc.yml +++ b/host-interaction/process/inject/inject-apc.yml @@ -2,7 +2,7 @@ rule: meta: name: inject APC namespace: host-interaction/process/inject - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Process Injection::Asynchronous Procedure Call [T1055.004] diff --git a/host-interaction/process/inject/inject-thread.yml b/host-interaction/process/inject/inject-thread.yml index 98dbf9df..3378643a 100644 --- a/host-interaction/process/inject/inject-thread.yml +++ b/host-interaction/process/inject/inject-thread.yml @@ -3,7 +3,7 @@ rule: name: inject thread namespace: host-interaction/process/inject author: - - anamaria.martinezgom@fireeye.com + - anamaria.martinezgom@mandiant.com - 0x534a@mailbox.org scope: function att&ck: diff --git a/host-interaction/process/inject/use-process-doppelgänging.yml b/host-interaction/process/inject/use-process-doppelgänging.yml index 6fd7d8fb..41d9017c 100644 --- a/host-interaction/process/inject/use-process-doppelgänging.yml +++ b/host-interaction/process/inject/use-process-doppelgänging.yml @@ -2,7 +2,7 @@ rule: meta: name: use process Doppelgänging namespace: host-interaction/process/inject - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file att&ck: - Defense Evasion::Process Injection::Process Doppelgänging [T1055.013] diff --git a/host-interaction/process/inject/use-process-replacement.yml b/host-interaction/process/inject/use-process-replacement.yml index 4d530ff8..ca8649d2 100644 --- a/host-interaction/process/inject/use-process-replacement.yml +++ b/host-interaction/process/inject/use-process-replacement.yml @@ -2,7 +2,7 @@ rule: meta: name: use process replacement namespace: host-interaction/process/inject - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Process Injection::Process Hollowing [T1055.012] diff --git a/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml b/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml index b725a21c..e39998f4 100644 --- a/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml +++ b/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate processes on remote desktop session host namespace: host-interaction/process/list - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/list/enumerate-processes.yml b/host-interaction/process/list/enumerate-processes.yml index b180c6fc..4191ed72 100644 --- a/host-interaction/process/list/enumerate-processes.yml +++ b/host-interaction/process/list/enumerate-processes.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate processes namespace: host-interaction/process/list - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/list/find-process-by-pid.yml b/host-interaction/process/list/find-process-by-pid.yml index 81281051..043b1150 100644 --- a/host-interaction/process/list/find-process-by-pid.yml +++ b/host-interaction/process/list/find-process-by-pid.yml @@ -2,7 +2,7 @@ rule: meta: name: find process by PID namespace: host-interaction/process/list - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/list/get-explorer-pid.yml b/host-interaction/process/list/get-explorer-pid.yml index 7eb0fd15..6cd63622 100644 --- a/host-interaction/process/list/get-explorer-pid.yml +++ b/host-interaction/process/list/get-explorer-pid.yml @@ -2,7 +2,7 @@ rule: meta: name: get Explorer PID namespace: host-interaction/process/list - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/modify/acquire-debug-privileges.yml b/host-interaction/process/modify/acquire-debug-privileges.yml index a2357cb7..f0719264 100644 --- a/host-interaction/process/modify/acquire-debug-privileges.yml +++ b/host-interaction/process/modify/acquire-debug-privileges.yml @@ -2,7 +2,7 @@ rule: meta: name: acquire debug privileges namespace: host-interaction/process/modify - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: basic block att&ck: - Privilege Escalation::Access Token Manipulation [T1134] diff --git a/host-interaction/process/modify/modify-access-privileges.yml b/host-interaction/process/modify/modify-access-privileges.yml index 8f91bd7c..adba3a28 100644 --- a/host-interaction/process/modify/modify-access-privileges.yml +++ b/host-interaction/process/modify/modify-access-privileges.yml @@ -2,7 +2,7 @@ rule: meta: name: modify access privileges namespace: host-interaction/process/modify - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Privilege Escalation::Access Token Manipulation [T1134] diff --git a/host-interaction/process/modules/list/enumerate-process-modules.yml b/host-interaction/process/modules/list/enumerate-process-modules.yml index 4ab1271a..d4179eec 100644 --- a/host-interaction/process/modules/list/enumerate-process-modules.yml +++ b/host-interaction/process/modules/list/enumerate-process-modules.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate process modules namespace: host-interaction/process/modules/list - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Process Discovery [T1057] diff --git a/host-interaction/process/set-thread-local-storage-value.yml b/host-interaction/process/set-thread-local-storage-value.yml index 72fccc1f..3f06c506 100644 --- a/host-interaction/process/set-thread-local-storage-value.yml +++ b/host-interaction/process/set-thread-local-storage-value.yml @@ -2,7 +2,7 @@ rule: meta: name: set thread local storage value namespace: host-interaction/process - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Process::Set Thread Local Storage Value [C0041] diff --git a/host-interaction/process/terminate/terminate-process.yml b/host-interaction/process/terminate/terminate-process.yml index 30a4cb97..7219ba09 100644 --- a/host-interaction/process/terminate/terminate-process.yml +++ b/host-interaction/process/terminate/terminate-process.yml @@ -2,7 +2,7 @@ rule: meta: name: terminate process namespace: host-interaction/process/terminate - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function mbc: - Process::Terminate Process [C0018] diff --git a/host-interaction/registry/create-or-open-registry-key.yml b/host-interaction/registry/create-or-open-registry-key.yml index 816b59db..e24a0972 100644 --- a/host-interaction/registry/create-or-open-registry-key.yml +++ b/host-interaction/registry/create-or-open-registry-key.yml @@ -2,7 +2,7 @@ rule: meta: name: create or open registry key namespace: host-interaction/registry - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Operating System::Registry::Create Registry Key [C0036.004] diff --git a/host-interaction/registry/create/set-registry-value.yml b/host-interaction/registry/create/set-registry-value.yml index 986c54a3..04cf0db4 100644 --- a/host-interaction/registry/create/set-registry-value.yml +++ b/host-interaction/registry/create/set-registry-value.yml @@ -3,8 +3,8 @@ rule: name: set registry value namespace: host-interaction/registry/create author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com scope: function mbc: - Operating System::Registry::Set Registry Key [C0036.001] diff --git a/host-interaction/registry/delete/delete-registry-key.yml b/host-interaction/registry/delete/delete-registry-key.yml index a58dea0f..46d266cc 100644 --- a/host-interaction/registry/delete/delete-registry-key.yml +++ b/host-interaction/registry/delete/delete-registry-key.yml @@ -3,8 +3,8 @@ rule: name: delete registry key namespace: host-interaction/registry/delete author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com - johnk3r scope: function att&ck: diff --git a/host-interaction/registry/delete/delete-registry-value.yml b/host-interaction/registry/delete/delete-registry-value.yml index be78292a..9b6f2ca9 100644 --- a/host-interaction/registry/delete/delete-registry-value.yml +++ b/host-interaction/registry/delete/delete-registry-value.yml @@ -2,7 +2,7 @@ rule: meta: name: delete registry value namespace: host-interaction/registry/delete - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Modify Registry [T1112] diff --git a/host-interaction/registry/query-or-enumerate-registry-key.yml b/host-interaction/registry/query-or-enumerate-registry-key.yml index 263fd1c4..f18d9bd2 100644 --- a/host-interaction/registry/query-or-enumerate-registry-key.yml +++ b/host-interaction/registry/query-or-enumerate-registry-key.yml @@ -2,7 +2,7 @@ rule: meta: name: query or enumerate registry key namespace: host-interaction/registry - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Query Registry [T1012] diff --git a/host-interaction/registry/query-or-enumerate-registry-value.yml b/host-interaction/registry/query-or-enumerate-registry-value.yml index 8201612c..03b6ee80 100644 --- a/host-interaction/registry/query-or-enumerate-registry-value.yml +++ b/host-interaction/registry/query-or-enumerate-registry-value.yml @@ -3,8 +3,8 @@ rule: name: query or enumerate registry value namespace: host-interaction/registry author: - - william.ballenthin@fireeye.com - - michael.hunhoff@fireeye.com + - william.ballenthin@mandiant.com + - michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Query Registry [T1012] diff --git a/host-interaction/service/create/create-service.yml b/host-interaction/service/create/create-service.yml index 0d3efd87..55af7e52 100644 --- a/host-interaction/service/create/create-service.yml +++ b/host-interaction/service/create/create-service.yml @@ -2,7 +2,7 @@ rule: meta: name: create service namespace: host-interaction/service/create - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/host-interaction/service/delete/delete-service.yml b/host-interaction/service/delete/delete-service.yml index 4f27943b..07b67aa1 100644 --- a/host-interaction/service/delete/delete-service.yml +++ b/host-interaction/service/delete/delete-service.yml @@ -2,7 +2,7 @@ rule: meta: name: delete service namespace: host-interaction/service/delete - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/host-interaction/service/list/enumerate-services.yml b/host-interaction/service/list/enumerate-services.yml index f8b9d24f..6bdb8955 100644 --- a/host-interaction/service/list/enumerate-services.yml +++ b/host-interaction/service/list/enumerate-services.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate services namespace: host-interaction/service/list - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::System Service Discovery [T1007] diff --git a/host-interaction/service/modify/modify-service.yml b/host-interaction/service/modify/modify-service.yml index 3df8839e..fe8d5ec1 100644 --- a/host-interaction/service/modify/modify-service.yml +++ b/host-interaction/service/modify/modify-service.yml @@ -2,7 +2,7 @@ rule: meta: name: modify service namespace: host-interaction/service/modify - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/host-interaction/service/query-service-status.yml b/host-interaction/service/query-service-status.yml index 58b1383f..50009fc8 100644 --- a/host-interaction/service/query-service-status.yml +++ b/host-interaction/service/query-service-status.yml @@ -2,7 +2,7 @@ rule: meta: name: query service status namespace: host-interaction/service - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Service Discovery [T1007] diff --git a/host-interaction/service/run-as-service.yml b/host-interaction/service/run-as-service.yml index 98247219..a5086a4e 100644 --- a/host-interaction/service/run-as-service.yml +++ b/host-interaction/service/run-as-service.yml @@ -3,8 +3,8 @@ rule: name: run as service namespace: host-interaction/service author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com scope: file mbc: - Anti-Behavioral Analysis::Execution Guardrails::Runs as Service [E1480.m07] diff --git a/host-interaction/service/start/start-service.yml b/host-interaction/service/start/start-service.yml index 50afe039..520e6e19 100644 --- a/host-interaction/service/start/start-service.yml +++ b/host-interaction/service/start/start-service.yml @@ -2,7 +2,7 @@ rule: meta: name: start service namespace: host-interaction/service/start - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/host-interaction/service/stop/stop-service.yml b/host-interaction/service/stop/stop-service.yml index c9a76138..78d46a5c 100644 --- a/host-interaction/service/stop/stop-service.yml +++ b/host-interaction/service/stop/stop-service.yml @@ -2,7 +2,7 @@ rule: meta: name: stop service namespace: host-interaction/service/stop - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/host-interaction/session/get-session-integrity-level.yml b/host-interaction/session/get-session-integrity-level.yml index 74080615..07f0b864 100644 --- a/host-interaction/session/get-session-integrity-level.yml +++ b/host-interaction/session/get-session-integrity-level.yml @@ -2,7 +2,7 @@ rule: meta: name: get session integrity level namespace: host-interaction/session - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Owner/User Discovery [T1033] diff --git a/host-interaction/session/get-session-user-name.yml b/host-interaction/session/get-session-user-name.yml index 8d9e68ec..ecd62834 100644 --- a/host-interaction/session/get-session-user-name.yml +++ b/host-interaction/session/get-session-user-name.yml @@ -2,7 +2,7 @@ rule: meta: name: get session user name namespace: host-interaction/session - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::System Owner/User Discovery [T1033] diff --git a/host-interaction/session/get-token-membership.yml b/host-interaction/session/get-token-membership.yml index 0dfdb19d..d1b70f3a 100644 --- a/host-interaction/session/get-token-membership.yml +++ b/host-interaction/session/get-token-membership.yml @@ -2,7 +2,7 @@ rule: meta: name: get token membership namespace: host-interaction/session - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Owner/User Discovery [T1033] diff --git a/host-interaction/session/get-user-security-identifier.yml b/host-interaction/session/get-user-security-identifier.yml index 3daf730d..d54df817 100644 --- a/host-interaction/session/get-user-security-identifier.yml +++ b/host-interaction/session/get-user-security-identifier.yml @@ -3,7 +3,7 @@ rule: meta: name: get user security identifier namespace: host-interaction/session - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::Account Discovery [T1087] diff --git a/host-interaction/thread/create/create-thread.yml b/host-interaction/thread/create/create-thread.yml index 1d762cf5..dd6c7859 100644 --- a/host-interaction/thread/create/create-thread.yml +++ b/host-interaction/thread/create/create-thread.yml @@ -3,8 +3,8 @@ rule: name: create thread namespace: host-interaction/thread/create author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com - joakim@intezer.com scope: basic block mbc: diff --git a/host-interaction/thread/list/enumerate-threads.yml b/host-interaction/thread/list/enumerate-threads.yml index 044e0da0..dd002789 100644 --- a/host-interaction/thread/list/enumerate-threads.yml +++ b/host-interaction/thread/list/enumerate-threads.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate threads namespace: host-interaction/thread/list - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function examples: - Practical Malware Analysis Lab 05-01.dll_:0x10006BD5 diff --git a/host-interaction/thread/terminate/terminate-thread.yml b/host-interaction/thread/terminate/terminate-thread.yml index e062b3a2..18e91bab 100644 --- a/host-interaction/thread/terminate/terminate-thread.yml +++ b/host-interaction/thread/terminate/terminate-thread.yml @@ -3,8 +3,8 @@ rule: name: terminate thread namespace: host-interaction/thread/terminate author: - - moritz.raabe@fireeye.com - - michael.hunhoff@fireeye.com + - moritz.raabe@mandiant.com + - michael.hunhoff@mandiant.com scope: basic block mbc: - Process::Terminate Thread [C0039] diff --git a/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml b/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml index c49e5b43..63f344ac 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml @@ -2,7 +2,7 @@ rule: meta: name: bypass UAC via AppInfo ALPC namespace: host-interaction/uac/bypass - author: richard.cole@fireeye.com + author: richard.cole@mandiant.com scope: function att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] diff --git a/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml b/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml index 11a02358..97469877 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml @@ -2,7 +2,7 @@ rule: meta: name: bypass UAC via ICMLuaUtil namespace: host-interaction/uac/bypass - author: anamaria.martinezgom@fireeye.com + author: anamaria.martinezgom@mandiant.com scope: function att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] diff --git a/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml b/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml index 31ad1454..58af20c9 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml @@ -2,7 +2,7 @@ rule: meta: name: bypass UAC via token manipulation namespace: host-interaction/uac/bypass - author: richard.cole@fireeye.com + author: richard.cole@mandiant.com scope: function att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] diff --git a/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml b/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml index 63ff218e..3d1a416f 100644 --- a/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml +++ b/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml @@ -3,7 +3,7 @@ rule: meta: name: connect to WMI namespace via WbemLocator namespace: host-interaction/wmi - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Execution::Windows Management Instrumentation [T1047] diff --git a/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml b/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml index a6177d85..ac326dff 100644 --- a/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml +++ b/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml @@ -2,7 +2,7 @@ rule: meta: name: delete volume shadow copies namespace: impact/inhibit-system-recovery - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Impact::Inhibit System Recovery [T1490] diff --git a/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml b/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml index 7833c621..eff78ba6 100644 --- a/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml +++ b/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml @@ -2,7 +2,7 @@ rule: meta: name: overwrite Master Boot Record (MBR) namespace: impact/wipe-disk/wipe-mbr - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Impact::Disk Wipe::Disk Structure Wipe [T1561.002] diff --git a/internal/limitation/file/internal-autoit-file-limitation.yml b/internal/limitation/file/internal-autoit-file-limitation.yml index 00a6e18a..c7f426e2 100644 --- a/internal/limitation/file/internal-autoit-file-limitation.yml +++ b/internal/limitation/file/internal-autoit-file-limitation.yml @@ -5,7 +5,7 @@ rule: # but these are due to the AutoIt runtime, not the payload script. # so, don't confuse the user with FP matches - bail instead namespace: internal/limitation/file - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com description: | This sample appears to be compiled with AutoIt. diff --git a/internal/limitation/file/internal-dotnet-file-limitation.yml b/internal/limitation/file/internal-dotnet-file-limitation.yml index 10af2e85..ca648dfa 100644 --- a/internal/limitation/file/internal-dotnet-file-limitation.yml +++ b/internal/limitation/file/internal-dotnet-file-limitation.yml @@ -5,7 +5,7 @@ rule: # it might match some file-level things. # for consistency, bail on things that we don't support. namespace: internal/limitation/file - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com description: | This sample appears to be a .NET module. diff --git a/internal/limitation/file/internal-installer-file-limitation.yml b/internal/limitation/file/internal-installer-file-limitation.yml index 02596d0a..a3ada31a 100644 --- a/internal/limitation/file/internal-installer-file-limitation.yml +++ b/internal/limitation/file/internal-installer-file-limitation.yml @@ -4,7 +4,7 @@ rule: # capa will likely detect installer specific functionality. # this is probably not what the user wants. namespace: internal/limitation/file - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com description: | This sample appears to be an installer. diff --git a/internal/limitation/file/internal-packer-file-limitation.yml b/internal/limitation/file/internal-packer-file-limitation.yml index 0f34b36e..9418b0fb 100644 --- a/internal/limitation/file/internal-packer-file-limitation.yml +++ b/internal/limitation/file/internal-packer-file-limitation.yml @@ -2,7 +2,7 @@ rule: meta: name: (internal) packer file limitation namespace: internal/limitation/file - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com description: | This sample appears to be packed. diff --git a/lib/calculate-modulo-256-via-x86-assembly.yml b/lib/calculate-modulo-256-via-x86-assembly.yml index 6f8669ab..f46a471d 100644 --- a/lib/calculate-modulo-256-via-x86-assembly.yml +++ b/lib/calculate-modulo-256-via-x86-assembly.yml @@ -1,7 +1,7 @@ rule: meta: name: calculate modulo 256 via x86 assembly - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com lib: true scope: basic block mbc: diff --git a/lib/contain-loop.yml b/lib/contain-loop.yml index 86bb79df..17098c08 100644 --- a/lib/contain-loop.yml +++ b/lib/contain-loop.yml @@ -1,7 +1,7 @@ rule: meta: name: contain loop - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com lib: true scope: function examples: diff --git a/lib/contain-pusha-popa-sequence.yml b/lib/contain-pusha-popa-sequence.yml index 7e549425..1735ab76 100644 --- a/lib/contain-pusha-popa-sequence.yml +++ b/lib/contain-pusha-popa-sequence.yml @@ -1,7 +1,7 @@ rule: meta: name: contain pusha popa sequence - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com lib: true scope: function examples: diff --git a/lib/create-or-open-file.yml b/lib/create-or-open-file.yml index 935c0126..a8aee353 100644 --- a/lib/create-or-open-file.yml +++ b/lib/create-or-open-file.yml @@ -2,7 +2,7 @@ rule: meta: name: create or open file author: - - michael.hunhoff@fireeye.com + - michael.hunhoff@mandiant.com - joakim@intezer.com lib: true scope: basic block diff --git a/lib/delay-execution.yml b/lib/delay-execution.yml index f9990484..5f318f27 100644 --- a/lib/delay-execution.yml +++ b/lib/delay-execution.yml @@ -1,7 +1,7 @@ rule: meta: name: delay execution - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com lib: true scope: basic block mbc: diff --git a/lib/get-service-handle.yml b/lib/get-service-handle.yml index eb89fb56..65db2a4d 100644 --- a/lib/get-service-handle.yml +++ b/lib/get-service-handle.yml @@ -1,7 +1,7 @@ rule: meta: name: get service handle - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com lib: true scope: function examples: diff --git a/lib/peb-access.yml b/lib/peb-access.yml index 0e726220..05da2d0a 100644 --- a/lib/peb-access.yml +++ b/lib/peb-access.yml @@ -1,7 +1,7 @@ rule: meta: name: PEB access - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com lib: true scope: basic block mbc: diff --git a/lib/write-process-memory.yml b/lib/write-process-memory.yml index a0e474bf..cd61c5df 100644 --- a/lib/write-process-memory.yml +++ b/lib/write-process-memory.yml @@ -1,7 +1,7 @@ rule: meta: name: write process memory - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com lib: true scope: function att&ck: diff --git a/linking/runtime-linking/access-peb-ldr_data.yml b/linking/runtime-linking/access-peb-ldr_data.yml index 5880c93c..19ef6806 100644 --- a/linking/runtime-linking/access-peb-ldr_data.yml +++ b/linking/runtime-linking/access-peb-ldr_data.yml @@ -2,7 +2,7 @@ rule: meta: name: access PEB ldr_data namespace: linking/runtime-linking - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Execution::Shared Modules [T1129] diff --git a/linking/runtime-linking/get-kernel32-base-address.yml b/linking/runtime-linking/get-kernel32-base-address.yml index c29eac6c..85c3474c 100644 --- a/linking/runtime-linking/get-kernel32-base-address.yml +++ b/linking/runtime-linking/get-kernel32-base-address.yml @@ -2,7 +2,7 @@ rule: meta: name: get kernel32 base address namespace: linking/runtime-linking - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Execution::Shared Modules [T1129] diff --git a/linking/runtime-linking/get-ntdll-base-address.yml b/linking/runtime-linking/get-ntdll-base-address.yml index 4c1603f6..1379c69c 100644 --- a/linking/runtime-linking/get-ntdll-base-address.yml +++ b/linking/runtime-linking/get-ntdll-base-address.yml @@ -2,7 +2,7 @@ rule: meta: name: get ntdll base address namespace: linking/runtime-linking - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: basic block att&ck: - Execution::Shared Modules [T1129] diff --git a/linking/runtime-linking/link-function-at-runtime-on-windows.yml b/linking/runtime-linking/link-function-at-runtime-on-windows.yml index 07d69f70..8cbbb425 100644 --- a/linking/runtime-linking/link-function-at-runtime-on-windows.yml +++ b/linking/runtime-linking/link-function-at-runtime-on-windows.yml @@ -3,7 +3,7 @@ rule: name: link function at runtime on Windows namespace: linking/runtime-linking author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com scope: function att&ck: - Execution::Shared Modules [T1129] diff --git a/linking/runtime-linking/link-many-functions-at-runtime.yml b/linking/runtime-linking/link-many-functions-at-runtime.yml index 2dfe469c..01f52127 100644 --- a/linking/runtime-linking/link-many-functions-at-runtime.yml +++ b/linking/runtime-linking/link-many-functions-at-runtime.yml @@ -3,7 +3,7 @@ rule: name: link many functions at runtime namespace: linking/runtime-linking author: - - moritz.raabe@fireeye.com + - moritz.raabe@mandiant.com - joakim@intezer.com scope: function att&ck: diff --git a/linking/static/cryptopp/linked-against-crypto.yml b/linking/static/cryptopp/linked-against-crypto.yml index 21f0b016..8c874f8b 100644 --- a/linking/static/cryptopp/linked-against-crypto.yml +++ b/linking/static/cryptopp/linked-against-crypto.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against Crypto++ namespace: linking/static/cryptopp - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file mbc: - Cryptography::Crypto Library [C0059] diff --git a/linking/static/libcurl/linked-against-libcurl.yml b/linking/static/libcurl/linked-against-libcurl.yml index 09b31365..c8ef4940 100644 --- a/linking/static/libcurl/linked-against-libcurl.yml +++ b/linking/static/libcurl/linked-against-libcurl.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against libcurl namespace: linking/static/libcurl - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file examples: - A90E5B3454AA71D9700B2EA54615F44B diff --git a/linking/static/msdetours/linked-against-microsoft-detours.yml b/linking/static/msdetours/linked-against-microsoft-detours.yml index c0828de7..4619e46d 100644 --- a/linking/static/msdetours/linked-against-microsoft-detours.yml +++ b/linking/static/msdetours/linked-against-microsoft-detours.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against Microsoft Detours namespace: linking/static/msdetours - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file att&ck: - Defense Evasion::Hijack Execution Flow [T1574] diff --git a/linking/static/openssl/linked-against-openssl.yml b/linking/static/openssl/linked-against-openssl.yml index 3eec520a..0ef56cc1 100644 --- a/linking/static/openssl/linked-against-openssl.yml +++ b/linking/static/openssl/linked-against-openssl.yml @@ -3,8 +3,8 @@ rule: name: linked against OpenSSL namespace: linking/static/openssl author: - - william.ballenthin@fireeye.com - - michael.hunhoff@fireeye.com + - william.ballenthin@mandiant.com + - michael.hunhoff@mandiant.com scope: file mbc: - Cryptography::Crypto Library [C0059] diff --git a/linking/static/polarssl/linked-against-polarsslmbed-tls.yml b/linking/static/polarssl/linked-against-polarsslmbed-tls.yml index 9f227207..d0e5df3d 100644 --- a/linking/static/polarssl/linked-against-polarsslmbed-tls.yml +++ b/linking/static/polarssl/linked-against-polarsslmbed-tls.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against PolarSSL/mbed TLS namespace: linking/static/polarssl - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file mbc: - Cryptography::Crypto Library [C0059] diff --git a/linking/static/zlib/linked-against-zlib.yml b/linking/static/zlib/linked-against-zlib.yml index 790bc18c..ca121889 100644 --- a/linking/static/zlib/linked-against-zlib.yml +++ b/linking/static/zlib/linked-against-zlib.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against ZLIB namespace: linking/static/zlib - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file mbc: - Data::Compression Library [C0060] diff --git a/load-code/pe/access-pe-header.yml b/load-code/pe/access-pe-header.yml index cf52d8d2..f10dcb05 100644 --- a/load-code/pe/access-pe-header.yml +++ b/load-code/pe/access-pe-header.yml @@ -2,7 +2,7 @@ rule: meta: name: access PE header namespace: load-code/pe - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Execution::Shared Modules [T1129] diff --git a/load-code/pe/parse-pe-header.yml b/load-code/pe/parse-pe-header.yml index d214984f..d5a02357 100644 --- a/load-code/pe/parse-pe-header.yml +++ b/load-code/pe/parse-pe-header.yml @@ -2,7 +2,7 @@ rule: meta: name: parse PE header namespace: load-code/pe - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Execution::Shared Modules [T1129] diff --git a/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml b/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml index d09136a4..d5ee0458 100644 --- a/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml +++ b/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml @@ -2,7 +2,7 @@ rule: meta: name: spawn thread to RWX shellcode namespace: load-code/shellcode - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function examples: - Practical Malware Analysis Lab 19-02.exe_:0x401230 diff --git a/nursery/add-file-to-cabinet-file.yml b/nursery/add-file-to-cabinet-file.yml index 4ef48ce9..a8feb45c 100644 --- a/nursery/add-file-to-cabinet-file.yml +++ b/nursery/add-file-to-cabinet-file.yml @@ -2,7 +2,7 @@ rule: meta: name: add file to cabinet file namespace: host-interaction/file-system - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: https://docs.microsoft.com/en-us/windows/win32/msi/cabinet-files features: diff --git a/nursery/add-user-account-group.yml b/nursery/add-user-account-group.yml index b988a68c..d809ee18 100644 --- a/nursery/add-user-account-group.yml +++ b/nursery/add-user-account-group.yml @@ -3,7 +3,7 @@ rule: meta: name: add user account group namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Persistence::Account Manipulation [T1098] diff --git a/nursery/add-user-account-to-group.yml b/nursery/add-user-account-to-group.yml index ab6ee008..daba65b0 100644 --- a/nursery/add-user-account-to-group.yml +++ b/nursery/add-user-account-to-group.yml @@ -3,7 +3,7 @@ rule: meta: name: add user account to group namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Persistence::Account Manipulation [T1098] diff --git a/nursery/add-user-account.yml b/nursery/add-user-account.yml index 764bc639..79b95057 100644 --- a/nursery/add-user-account.yml +++ b/nursery/add-user-account.yml @@ -3,7 +3,7 @@ rule: meta: name: add user account namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Persistence::Create Account [T1136] diff --git a/nursery/build-docker-image.yml b/nursery/build-docker-image.yml index 7598ae00..40a376ac 100644 --- a/nursery/build-docker-image.yml +++ b/nursery/build-docker-image.yml @@ -2,7 +2,7 @@ rule: meta: name: build Docker image namespace: host-interaction/container/docker - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Build Image on Host [T1612] diff --git a/nursery/bypass-uac-via-scheduled-task-environment-variable.yml b/nursery/bypass-uac-via-scheduled-task-environment-variable.yml index a8852860..786dc8e7 100644 --- a/nursery/bypass-uac-via-scheduled-task-environment-variable.yml +++ b/nursery/bypass-uac-via-scheduled-task-environment-variable.yml @@ -2,7 +2,7 @@ rule: meta: name: bypass UAC via scheduled task environment variable namespace: host-interaction/uac/bypass - author: anamaria.martinezgom@fireeye.com + author: anamaria.martinezgom@mandiant.com scope: function att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] diff --git a/nursery/change-user-account-password.yml b/nursery/change-user-account-password.yml index e4c7a011..9927c130 100644 --- a/nursery/change-user-account-password.yml +++ b/nursery/change-user-account-password.yml @@ -3,7 +3,7 @@ rule: meta: name: change user account password namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Persistence::Account Manipulation [T1098] diff --git a/nursery/check-for-process-debug-object.yml b/nursery/check-for-process-debug-object.yml index 064cb74e..a2c9df8b 100644 --- a/nursery/check-for-process-debug-object.yml +++ b/nursery/check-for-process-debug-object.yml @@ -2,7 +2,7 @@ rule: meta: name: check for process debug object namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection diff --git a/nursery/check-license-value.yml b/nursery/check-license-value.yml index 01f32b35..6436ea35 100644 --- a/nursery/check-license-value.yml +++ b/nursery/check-license-value.yml @@ -2,7 +2,7 @@ rule: meta: name: check license value namespace: anti-analysis/anti-vm/vm-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/nursery/check-processdebugflags.yml b/nursery/check-processdebugflags.yml index 3126fdec..fe155e45 100644 --- a/nursery/check-processdebugflags.yml +++ b/nursery/check-processdebugflags.yml @@ -2,7 +2,7 @@ rule: meta: name: check ProcessDebugFlags namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection diff --git a/nursery/check-systemkerneldebuggerinformation.yml b/nursery/check-systemkerneldebuggerinformation.yml index 1cc9fbe8..de787203 100644 --- a/nursery/check-systemkerneldebuggerinformation.yml +++ b/nursery/check-systemkerneldebuggerinformation.yml @@ -2,7 +2,7 @@ rule: meta: name: check SystemKernelDebuggerInformation namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block mbc: - Anti-Behavioral Analysis::Debugger Detection diff --git a/nursery/check-thread-yield-allowed.yml b/nursery/check-thread-yield-allowed.yml index ef47a4a0..aa9bf632 100644 --- a/nursery/check-thread-yield-allowed.yml +++ b/nursery/check-thread-yield-allowed.yml @@ -2,7 +2,7 @@ rule: meta: name: check thread yield allowed namespace: anti-analysis/anti-debugging/debugger-detection - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function mbc: - Anti-Behavioral Analysis::Debugger Detection diff --git a/nursery/compare-security-identifiers.yml b/nursery/compare-security-identifiers.yml index 12333eac..a51b4ed9 100644 --- a/nursery/compare-security-identifiers.yml +++ b/nursery/compare-security-identifiers.yml @@ -3,7 +3,7 @@ rule: meta: name: compare security identifiers namespace: host-interaction/sid - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/compiled-from-epl.yml b/nursery/compiled-from-epl.yml index 70393489..4805b252 100644 --- a/nursery/compiled-from-epl.yml +++ b/nursery/compiled-from-epl.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled from EPL namespace: compiler/epl - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.hexacorn.com/blog/2019/02/13/pe-files-and-the-easy-programming-language-epl/ diff --git a/nursery/connect-network-resource.yml b/nursery/connect-network-resource.yml index 3d4e42a9..93883cd2 100644 --- a/nursery/connect-network-resource.yml +++ b/nursery/connect-network-resource.yml @@ -2,7 +2,7 @@ rule: meta: name: connect network resource namespace: communication/http - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com description: connect to disk or print resource scope: function features: diff --git a/nursery/create-container.yml b/nursery/create-container.yml index 0f91c334..c3fb97ce 100644 --- a/nursery/create-container.yml +++ b/nursery/create-container.yml @@ -2,7 +2,7 @@ rule: meta: name: create container namespace: host-interaction/container/docker - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Execution::Deploy Container [T1610] diff --git a/nursery/create-restart-manager-session.yml b/nursery/create-restart-manager-session.yml index 76a27e41..153bf149 100644 --- a/nursery/create-restart-manager-session.yml +++ b/nursery/create-restart-manager-session.yml @@ -2,7 +2,7 @@ rule: meta: name: create Restart Manager session namespace: host-interaction/process - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com description: Windows Restart Manager can be used to close/unlock specific files, often abused by Ransomware scope: function references: https://www.carbonblack.com/blog/tau-threat-discovery-conti-ransomware/ diff --git a/nursery/create-shortcut-via-ishelllink.yml b/nursery/create-shortcut-via-ishelllink.yml index 93c2282a..73597e7e 100644 --- a/nursery/create-shortcut-via-ishelllink.yml +++ b/nursery/create-shortcut-via-ishelllink.yml @@ -2,7 +2,7 @@ rule: meta: name: create shortcut via IShellLink namespace: host-interaction/file-system/write - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function references: - https://docs.microsoft.com/en-us/windows/win32/shell/links#creating-a-shortcut-and-a-folder-shortcut-to-a-file diff --git a/nursery/debug-build.yml b/nursery/debug-build.yml index 107d41b4..036e6db4 100644 --- a/nursery/debug-build.yml +++ b/nursery/debug-build.yml @@ -2,7 +2,7 @@ rule: meta: name: debug build namespace: executable/pe/debug - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file features: - or: diff --git a/nursery/decrypt-data-via-sspi.yml b/nursery/decrypt-data-via-sspi.yml index 39b30542..8827cc46 100644 --- a/nursery/decrypt-data-via-sspi.yml +++ b/nursery/decrypt-data-via-sspi.yml @@ -2,7 +2,7 @@ rule: meta: name: decrypt data via SSPI namespace: data-manipulation/encryption - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] diff --git a/nursery/delete-internet-cache.yml b/nursery/delete-internet-cache.yml index b154670c..be39c331 100644 --- a/nursery/delete-internet-cache.yml +++ b/nursery/delete-internet-cache.yml @@ -2,7 +2,7 @@ rule: meta: name: delete internet cache namespace: host-interaction/internet/cache - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/delete-user-account-from-group.yml b/nursery/delete-user-account-from-group.yml index 42dbf1b8..920a712e 100644 --- a/nursery/delete-user-account-from-group.yml +++ b/nursery/delete-user-account-from-group.yml @@ -3,7 +3,7 @@ rule: meta: name: delete user account from group namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Persistence::Account Manipulation [T1098] diff --git a/nursery/delete-user-account-group.yml b/nursery/delete-user-account-group.yml index 0f74962c..d0cb18a7 100644 --- a/nursery/delete-user-account-group.yml +++ b/nursery/delete-user-account-group.yml @@ -3,7 +3,7 @@ rule: meta: name: delete user account group namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Persistence::Account Manipulation [T1098] diff --git a/nursery/delete-user-account.yml b/nursery/delete-user-account.yml index 36268a51..56b3d8b0 100644 --- a/nursery/delete-user-account.yml +++ b/nursery/delete-user-account.yml @@ -3,7 +3,7 @@ rule: meta: name: delete user account namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Impact::Account Access Removal [T1531] diff --git a/nursery/empty-recycle-bin-quietly.yml b/nursery/empty-recycle-bin-quietly.yml index 76b1bbae..661e2e4b 100644 --- a/nursery/empty-recycle-bin-quietly.yml +++ b/nursery/empty-recycle-bin-quietly.yml @@ -2,7 +2,7 @@ rule: meta: name: empty recycle bin quietly namespace: host-interaction/recycle-bin - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block references: - https://docs.microsoft.com/en-us/windows/win32/api/shellapi/nf-shellapi-shemptyrecyclebina diff --git a/nursery/empty-the-recycle-bin.yml b/nursery/empty-the-recycle-bin.yml index f6a71851..f8e605db 100644 --- a/nursery/empty-the-recycle-bin.yml +++ b/nursery/empty-the-recycle-bin.yml @@ -2,7 +2,7 @@ rule: meta: name: empty the recycle bin namespace: host-interaction/recycle-bin - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function features: - or: diff --git a/nursery/encrypt-data-using-aes-via-x86-extensions.yml b/nursery/encrypt-data-using-aes-via-x86-extensions.yml index 47ac17eb..bad72f13 100644 --- a/nursery/encrypt-data-using-aes-via-x86-extensions.yml +++ b/nursery/encrypt-data-using-aes-via-x86-extensions.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using AES via x86 extensions namespace: data-manipulation/encryption/aes - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/encrypt-data-using-fakem-cipher.yml b/nursery/encrypt-data-using-fakem-cipher.yml index 838eb2a7..a98b204b 100644 --- a/nursery/encrypt-data-using-fakem-cipher.yml +++ b/nursery/encrypt-data-using-fakem-cipher.yml @@ -3,7 +3,7 @@ rule: meta: name: encrypt data using FAKEM cipher namespace: data-manipulation/encryption - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com description: Detect custom encryption cipher used by FAKEM malware family scope: basic block att&ck: diff --git a/nursery/encrypt-data-using-salsa20-or-chacha.yml b/nursery/encrypt-data-using-salsa20-or-chacha.yml index b9dceaee..5ba468b6 100644 --- a/nursery/encrypt-data-using-salsa20-or-chacha.yml +++ b/nursery/encrypt-data-using-salsa20-or-chacha.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data using Salsa20 or ChaCha namespace: data-manipulation/encryption/salsa20 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/encrypt-data-via-sspi.yml b/nursery/encrypt-data-via-sspi.yml index d33cb38c..c1c8b218 100644 --- a/nursery/encrypt-data-via-sspi.yml +++ b/nursery/encrypt-data-via-sspi.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt data via SSPI namespace: data-manipulation/encryption - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/encrypt-or-decrypt-data-via-bcrypt.yml b/nursery/encrypt-or-decrypt-data-via-bcrypt.yml index 28cd225f..8934c973 100644 --- a/nursery/encrypt-or-decrypt-data-via-bcrypt.yml +++ b/nursery/encrypt-or-decrypt-data-via-bcrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: encrypt or decrypt data via BCrypt namespace: data-manipulation/encryption - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/enumerate-browser-history.yml b/nursery/enumerate-browser-history.yml index e0e76eb2..d2dbb2fd 100644 --- a/nursery/enumerate-browser-history.yml +++ b/nursery/enumerate-browser-history.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate browser history namespace: host-interaction/browser/history/list - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/enumerate-disk-volumes.yml b/nursery/enumerate-disk-volumes.yml index abd56666..c4db1032 100644 --- a/nursery/enumerate-disk-volumes.yml +++ b/nursery/enumerate-disk-volumes.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate disk volumes namespace: host-interaction/hardware/storage - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Information Discovery [T1082] diff --git a/nursery/enumerate-internet-cache.yml b/nursery/enumerate-internet-cache.yml index a5a94962..b53a6127 100644 --- a/nursery/enumerate-internet-cache.yml +++ b/nursery/enumerate-internet-cache.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate internet cache namespace: host-interaction/internet/cache - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/enumerate-network-shares.yml b/nursery/enumerate-network-shares.yml index 18372279..5e30ac33 100644 --- a/nursery/enumerate-network-shares.yml +++ b/nursery/enumerate-network-shares.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate network shares namespace: host-interaction/network - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::Network Share Discovery [T1135] diff --git a/nursery/enumerate-system-firmware-tables.yml b/nursery/enumerate-system-firmware-tables.yml index 75e83e7c..f4378a53 100644 --- a/nursery/enumerate-system-firmware-tables.yml +++ b/nursery/enumerate-system-firmware-tables.yml @@ -2,7 +2,7 @@ rule: meta: name: enumerate system firmware tables namespace: host-interaction/hardware/firmware - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: - https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/Shared/Utils.cpp#L843 diff --git a/nursery/execute-shell-command-via-windows-remote-management.yml b/nursery/execute-shell-command-via-windows-remote-management.yml index 09d29ae8..af41aa55 100644 --- a/nursery/execute-shell-command-via-windows-remote-management.yml +++ b/nursery/execute-shell-command-via-windows-remote-management.yml @@ -3,7 +3,7 @@ rule: meta: name: execute shell command via Windows Remote Management namespace: host-interaction/process/create - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/flush-cabinet-file.yml b/nursery/flush-cabinet-file.yml index 87a6ba42..03353fe2 100644 --- a/nursery/flush-cabinet-file.yml +++ b/nursery/flush-cabinet-file.yml @@ -2,7 +2,7 @@ rule: meta: name: flush cabinet file namespace: host-interaction/file-system - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: https://docs.microsoft.com/en-us/windows/win32/msi/cabinet-files features: diff --git a/nursery/generate-random-numbers-using-the-delphi-lcg.yml b/nursery/generate-random-numbers-using-the-delphi-lcg.yml index 353181af..084be00b 100644 --- a/nursery/generate-random-numbers-using-the-delphi-lcg.yml +++ b/nursery/generate-random-numbers-using-the-delphi-lcg.yml @@ -2,7 +2,7 @@ rule: meta: name: generate random numbers using the Delphi LCG namespace: data-manipulation/prng/lcg - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: basic block mbc: - Cryptography::Generate Pseudo-random Sequence [C0021] diff --git a/nursery/get-client-handle-via-schannel.yml b/nursery/get-client-handle-via-schannel.yml index 1ceba697..02a03130 100644 --- a/nursery/get-client-handle-via-schannel.yml +++ b/nursery/get-client-handle-via-schannel.yml @@ -2,7 +2,7 @@ rule: meta: name: get client handle via SChannel namespace: data-manipulation/encryption - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/get-inbound-credentials-handle-via-credssp.yml b/nursery/get-inbound-credentials-handle-via-credssp.yml index e5df264c..f79bf491 100644 --- a/nursery/get-inbound-credentials-handle-via-credssp.yml +++ b/nursery/get-inbound-credentials-handle-via-credssp.yml @@ -2,7 +2,7 @@ rule: meta: name: get inbound credentials handle via CredSSP namespace: data-manipulation/encryption - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/get-installed-programs.yml b/nursery/get-installed-programs.yml index 0e84a422..a8d77641 100644 --- a/nursery/get-installed-programs.yml +++ b/nursery/get-installed-programs.yml @@ -2,7 +2,7 @@ rule: meta: name: get installed programs namespace: host-interaction/software - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::Software Discovery [T1518] diff --git a/nursery/get-networking-parameters.yml b/nursery/get-networking-parameters.yml index 057f5925..abfbf5a8 100644 --- a/nursery/get-networking-parameters.yml +++ b/nursery/get-networking-parameters.yml @@ -2,7 +2,7 @@ rule: meta: name: get networking parameters namespace: host-interaction/network - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Network Configuration Discovery [T1016] diff --git a/nursery/get-proxy.yml b/nursery/get-proxy.yml index 916b924b..37c9d08d 100644 --- a/nursery/get-proxy.yml +++ b/nursery/get-proxy.yml @@ -2,7 +2,7 @@ rule: meta: name: get proxy namespace: host-interaction/network/proxy - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Discovery::System Network Configuration Discovery [T1016] diff --git a/nursery/get-remote-cert-context-via-schannel.yml b/nursery/get-remote-cert-context-via-schannel.yml index f03b1e42..a20b44b7 100644 --- a/nursery/get-remote-cert-context-via-schannel.yml +++ b/nursery/get-remote-cert-context-via-schannel.yml @@ -2,7 +2,7 @@ rule: meta: name: get remote cert context via SChannel namespace: data-manipulation/encryption - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/get-routing-table.yml b/nursery/get-routing-table.yml index 18e3b24f..da5760ef 100644 --- a/nursery/get-routing-table.yml +++ b/nursery/get-routing-table.yml @@ -2,7 +2,7 @@ rule: meta: name: get routing table namespace: host-interaction/network/routing-table - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Network Configuration Discovery [T1016] diff --git a/nursery/get-session-information.yml b/nursery/get-session-information.yml index 1dee75fa..17721178 100644 --- a/nursery/get-session-information.yml +++ b/nursery/get-session-information.yml @@ -2,7 +2,7 @@ rule: meta: name: get session information namespace: host-interaction/session - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Owner/User Discovery [T1033] diff --git a/nursery/get-socket-information.yml b/nursery/get-socket-information.yml index 86709c72..05b621c4 100644 --- a/nursery/get-socket-information.yml +++ b/nursery/get-socket-information.yml @@ -2,7 +2,7 @@ rule: meta: name: get socket information namespace: communication/socket - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Discovery::System Network Configuration Discovery [T1016] diff --git a/nursery/get-storage-device-properties.yml b/nursery/get-storage-device-properties.yml index 52b4899e..c5f5ed8a 100644 --- a/nursery/get-storage-device-properties.yml +++ b/nursery/get-storage-device-properties.yml @@ -3,7 +3,7 @@ rule: meta: name: get storage device properties namespace: host-interaction/hardware/storage - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-winioctl-ioctl_storage_query_property features: diff --git a/nursery/get-system-firmware-table.yml b/nursery/get-system-firmware-table.yml index dd00221d..671d0e5c 100644 --- a/nursery/get-system-firmware-table.yml +++ b/nursery/get-system-firmware-table.yml @@ -2,7 +2,7 @@ rule: meta: name: get system firmware table namespace: host-interaction/hardware/firmware - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: - https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/Shared/Utils.cpp#L854 diff --git a/nursery/get-thread-local-storage-value.yml b/nursery/get-thread-local-storage-value.yml index bea36e11..bc9ef9bc 100644 --- a/nursery/get-thread-local-storage-value.yml +++ b/nursery/get-thread-local-storage-value.yml @@ -2,7 +2,7 @@ rule: meta: name: get thread local storage value namespace: host-interaction/process - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/get-token-privileges.yml b/nursery/get-token-privileges.yml index a27abadd..f44277b2 100644 --- a/nursery/get-token-privileges.yml +++ b/nursery/get-token-privileges.yml @@ -3,7 +3,7 @@ rule: meta: name: get token privileges namespace: host-interaction/session - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/hash-data-using-crc32b.yml b/nursery/hash-data-using-crc32b.yml index 6a17b21c..daf669b2 100644 --- a/nursery/hash-data-using-crc32b.yml +++ b/nursery/hash-data-using-crc32b.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using CRC32b namespace: data-manipulation/checksum/crc32 - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function features: - and: diff --git a/nursery/hash-data-using-md4.yml b/nursery/hash-data-using-md4.yml index c4b8524e..01640c3c 100644 --- a/nursery/hash-data-using-md4.yml +++ b/nursery/hash-data-using-md4.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using MD4 namespace: data-manipulation/hashing/md4 - author: anamaria.martinezgom@fireeye.com + author: anamaria.martinezgom@mandiant.com scope: basic block features: - and: diff --git a/nursery/hash-data-using-murmur2.yml b/nursery/hash-data-using-murmur2.yml index 7b06801d..68ac0a59 100644 --- a/nursery/hash-data-using-murmur2.yml +++ b/nursery/hash-data-using-murmur2.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using murmur2 namespace: data-manipulation/hashing/murmur - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://github.com/abrandoned/murmur2/blob/master/MurmurHash2.c diff --git a/nursery/hash-data-using-sha1-via-wincrypt.yml b/nursery/hash-data-using-sha1-via-wincrypt.yml index 158076b3..89cd2892 100644 --- a/nursery/hash-data-using-sha1-via-wincrypt.yml +++ b/nursery/hash-data-using-sha1-via-wincrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data using SHA1 via WinCrypt namespace: data-manipulation/hashing/sha1 - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - or: diff --git a/nursery/hash-data-via-bcrypt.yml b/nursery/hash-data-via-bcrypt.yml index e8e8e0ba..9b6d5bf8 100644 --- a/nursery/hash-data-via-bcrypt.yml +++ b/nursery/hash-data-via-bcrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: hash data via BCrypt namespace: data-manipulation/hashing - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/hide-thread-from-debugger.yml b/nursery/hide-thread-from-debugger.yml index cacd9db8..7843536a 100644 --- a/nursery/hide-thread-from-debugger.yml +++ b/nursery/hide-thread-from-debugger.yml @@ -2,7 +2,7 @@ rule: meta: name: hide thread from debugger namespace: anti-analysis/anti-debugging - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block references: - https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/AntiDebug/NtSetInformationThread_ThreadHideFromDebugger.cpp diff --git a/nursery/hook-routines-via-microsoft-detours.yml b/nursery/hook-routines-via-microsoft-detours.yml index 9ab0e1ba..82647fb4 100644 --- a/nursery/hook-routines-via-microsoft-detours.yml +++ b/nursery/hook-routines-via-microsoft-detours.yml @@ -2,7 +2,7 @@ rule: meta: name: hook routines via microsoft detours # namespace: linking/hooking - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.fireeye.com/content/dam/fireeye-www/global/en/blog/threat-research/Flare-On%202017/Challenge7.pdf diff --git a/nursery/hooked-by-api-override.yml b/nursery/hooked-by-api-override.yml index e584677d..b6ad18a3 100644 --- a/nursery/hooked-by-api-override.yml +++ b/nursery/hooked-by-api-override.yml @@ -2,7 +2,7 @@ rule: meta: name: hooked by API Override namespace: executable/hooked/api-override - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/ diff --git a/nursery/impersonate-user.yml b/nursery/impersonate-user.yml index 63a5f118..19b59638 100644 --- a/nursery/impersonate-user.yml +++ b/nursery/impersonate-user.yml @@ -2,7 +2,7 @@ rule: meta: name: impersonate user namespace: host-interaction/user - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Privilege Escalation::Access Token Manipulation::Token Impersonation/Theft [T1134.001] diff --git a/nursery/initialize-hashing-via-wincrypt.yml b/nursery/initialize-hashing-via-wincrypt.yml index d3097da3..c624683e 100644 --- a/nursery/initialize-hashing-via-wincrypt.yml +++ b/nursery/initialize-hashing-via-wincrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: initialize hashing via WinCrypt namespace: data-manipulation/hashing - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function features: - and: diff --git a/nursery/inspect-load-icon-resource.yml b/nursery/inspect-load-icon-resource.yml index c60050f2..3e4729e8 100644 --- a/nursery/inspect-load-icon-resource.yml +++ b/nursery/inspect-load-icon-resource.yml @@ -3,7 +3,7 @@ rule: meta: name: inspect load icon resource namespace: anti-analysis - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: # check if call to LoadIcon fails when first argument is NULL diff --git a/nursery/linked-against-cpp-regex-library.yml b/nursery/linked-against-cpp-regex-library.yml index bc4fadb3..5dd0e4f8 100644 --- a/nursery/linked-against-cpp-regex-library.yml +++ b/nursery/linked-against-cpp-regex-library.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against CPP regex library namespace: linking/static/cppregex - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - http://www.cplusplus.com/reference/regex/regex_error/ diff --git a/nursery/linked-against-xzip.yml b/nursery/linked-against-xzip.yml index 8d53ca43..69508420 100644 --- a/nursery/linked-against-xzip.yml +++ b/nursery/linked-against-xzip.yml @@ -2,7 +2,7 @@ rule: meta: name: linked against XZip namespace: linking/static/xzip - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file mbc: - Data::Compression Library [C0060] diff --git a/nursery/list-containers.yml b/nursery/list-containers.yml index 2044c6e5..e09da77d 100644 --- a/nursery/list-containers.yml +++ b/nursery/list-containers.yml @@ -2,7 +2,7 @@ rule: meta: name: list containers namespace: host-interaction/container/docker - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Discovery::Container and Resource Discovery [T1613] diff --git a/nursery/list-domain-servers.yml b/nursery/list-domain-servers.yml index b813a38d..0f7521f8 100644 --- a/nursery/list-domain-servers.yml +++ b/nursery/list-domain-servers.yml @@ -3,7 +3,7 @@ rule: meta: name: list domain servers namespace: host-interaction/domain - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::System Network Configuration Discovery [T1016.001] diff --git a/nursery/list-drag-and-drop-files.yml b/nursery/list-drag-and-drop-files.yml index 69d55cab..97b0aaa8 100644 --- a/nursery/list-drag-and-drop-files.yml +++ b/nursery/list-drag-and-drop-files.yml @@ -3,7 +3,7 @@ rule: meta: name: list drag and drop files namespace: host-interaction/clipboard - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Clipboard Data [T1115] diff --git a/nursery/list-groups-for-user-account.yml b/nursery/list-groups-for-user-account.yml index 6af7ed1f..f10f680a 100644 --- a/nursery/list-groups-for-user-account.yml +++ b/nursery/list-groups-for-user-account.yml @@ -3,7 +3,7 @@ rule: meta: name: list groups for user account namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com description: enumerates all the groups to which a user account belongs scope: basic block att&ck: diff --git a/nursery/list-tcp-connections-and-listeners.yml b/nursery/list-tcp-connections-and-listeners.yml index 58e2f3b0..05cbc67a 100644 --- a/nursery/list-tcp-connections-and-listeners.yml +++ b/nursery/list-tcp-connections-and-listeners.yml @@ -3,7 +3,7 @@ rule: meta: name: list TCP connections and listeners namespace: collection/network - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/list-udp-connections-and-listeners.yml b/nursery/list-udp-connections-and-listeners.yml index 17413158..01fc09ed 100644 --- a/nursery/list-udp-connections-and-listeners.yml +++ b/nursery/list-udp-connections-and-listeners.yml @@ -3,7 +3,7 @@ rule: meta: name: list UDP connections and listeners namespace: collection/network - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/list-user-account-groups.yml b/nursery/list-user-account-groups.yml index a3f4c8bd..45086da9 100644 --- a/nursery/list-user-account-groups.yml +++ b/nursery/list-user-account-groups.yml @@ -3,7 +3,7 @@ rule: meta: name: list user account groups namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com description: enumerates all the groups present on the system/domain scope: basic block att&ck: diff --git a/nursery/list-user-accounts-for-group.yml b/nursery/list-user-accounts-for-group.yml index 0ffbac89..ba894f13 100644 --- a/nursery/list-user-accounts-for-group.yml +++ b/nursery/list-user-accounts-for-group.yml @@ -3,7 +3,7 @@ rule: meta: name: list user accounts for group namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::Permission Groups Discovery [T1069] diff --git a/nursery/list-user-accounts.yml b/nursery/list-user-accounts.yml index bbf135a2..d72df066 100644 --- a/nursery/list-user-accounts.yml +++ b/nursery/list-user-accounts.yml @@ -3,7 +3,7 @@ rule: meta: name: list user accounts namespace: host-interaction/accounts - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discovery::Account Discovery [T1087] diff --git a/nursery/listen-for-remote-procedure-calls.yml b/nursery/listen-for-remote-procedure-calls.yml index 83cda8dc..70578ac7 100644 --- a/nursery/listen-for-remote-procedure-calls.yml +++ b/nursery/listen-for-remote-procedure-calls.yml @@ -3,7 +3,7 @@ rule: meta: name: listen for remote procedure calls namespace: communication/rpc/server - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/load-windows-common-language-runtime.yml b/nursery/load-windows-common-language-runtime.yml index 51e35a61..b685aa7c 100644 --- a/nursery/load-windows-common-language-runtime.yml +++ b/nursery/load-windows-common-language-runtime.yml @@ -3,7 +3,7 @@ rule: meta: name: load Windows Common Language Runtime namespace: load-code/dotnet - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/log-keystrokes-via-raw-input-data.yml b/nursery/log-keystrokes-via-raw-input-data.yml index b64ca0d4..451b75fe 100644 --- a/nursery/log-keystrokes-via-raw-input-data.yml +++ b/nursery/log-keystrokes-via-raw-input-data.yml @@ -3,7 +3,7 @@ rule: meta: name: log keystrokes via raw input data namespace: collection/keylog - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Collection::Input Capture::Keylogging [T1056.001] diff --git a/nursery/make-an-http-request-with-a-cookie.yml b/nursery/make-an-http-request-with-a-cookie.yml index f5ea54d2..0ade6592 100644 --- a/nursery/make-an-http-request-with-a-cookie.yml +++ b/nursery/make-an-http-request-with-a-cookie.yml @@ -2,7 +2,7 @@ rule: meta: name: make an HTTP request with a Cookie namespace: communication/http/client - author: anamaria.martinezgom@fireeye.com + author: anamaria.martinezgom@mandiant.com scope: function features: - and: diff --git a/nursery/migrate-process-to-active-window-station.yml b/nursery/migrate-process-to-active-window-station.yml index 414a031b..17510641 100644 --- a/nursery/migrate-process-to-active-window-station.yml +++ b/nursery/migrate-process-to-active-window-station.yml @@ -2,7 +2,7 @@ rule: meta: name: migrate process to active window station namespace: host-interaction/gui/window-station - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com description: set process to the active window station so it can receive GUI events. commonly seen in keyloggers. scope: function references: diff --git a/nursery/mine-cryptocurrency.yml b/nursery/mine-cryptocurrency.yml index a21cd71f..d11a3cec 100644 --- a/nursery/mine-cryptocurrency.yml +++ b/nursery/mine-cryptocurrency.yml @@ -2,7 +2,7 @@ rule: meta: name: mine cryptocurrency namespace: impact/cryptocurrency - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file att&ck: - Impact::Resource Hijacking [T1496] diff --git a/nursery/monitor-clipboard-content.yml b/nursery/monitor-clipboard-content.yml index 7b503b96..19ffeb0c 100644 --- a/nursery/monitor-clipboard-content.yml +++ b/nursery/monitor-clipboard-content.yml @@ -3,7 +3,7 @@ rule: meta: name: monitor clipboard content namespace: host-interaction/clipboard - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Collection::Clipboard Data [T1115] diff --git a/nursery/monitor-local-ipv4-address-changes.yml b/nursery/monitor-local-ipv4-address-changes.yml index d083e29a..4a315ecc 100644 --- a/nursery/monitor-local-ipv4-address-changes.yml +++ b/nursery/monitor-local-ipv4-address-changes.yml @@ -3,7 +3,7 @@ rule: meta: name: monitor local IPv4 address changes namespace: host-interaction/network/address - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block att&ck: - Discover::System Network Configuration Discovery [T1016] diff --git a/nursery/open-cabinet-file.yml b/nursery/open-cabinet-file.yml index 154aebf9..4ffdc87d 100644 --- a/nursery/open-cabinet-file.yml +++ b/nursery/open-cabinet-file.yml @@ -2,7 +2,7 @@ rule: meta: name: open cabinet file namespace: host-interaction/file-system - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: https://docs.microsoft.com/en-us/windows/win32/msi/cabinet-files features: diff --git a/nursery/packaged-as-a-createinstall-installer.yml b/nursery/packaged-as-a-createinstall-installer.yml index cf0ed556..d9865ba3 100644 --- a/nursery/packaged-as-a-createinstall-installer.yml +++ b/nursery/packaged-as-a-createinstall-installer.yml @@ -2,7 +2,7 @@ rule: meta: name: packaged as a CreateInstall installer namespace: executable/installer/createinstall - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.createinstall.com/ diff --git a/nursery/packaged-as-a-nsis-installer.yml b/nursery/packaged-as-a-nsis-installer.yml index 7ef057e1..e8757ad3 100644 --- a/nursery/packaged-as-a-nsis-installer.yml +++ b/nursery/packaged-as-a-nsis-installer.yml @@ -2,7 +2,7 @@ rule: meta: name: packaged as a NSIS installer namespace: executable/installer/nsis - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file references: - https://nsis.sourceforge.io/Main_Page diff --git a/nursery/packaged-as-a-pintool.yml b/nursery/packaged-as-a-pintool.yml index 6705a143..5f89048b 100644 --- a/nursery/packaged-as-a-pintool.yml +++ b/nursery/packaged-as-a-pintool.yml @@ -2,7 +2,7 @@ rule: meta: name: packaged as a Pintool namespace: executable/pintool - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://software.intel.com/content/www/us/en/develop/articles/pin-a-dynamic-binary-instrumentation-tool.html diff --git a/nursery/packaged-as-a-winzip-self-extracting-archive.yml b/nursery/packaged-as-a-winzip-self-extracting-archive.yml index 66344db7..ba901243 100644 --- a/nursery/packaged-as-a-winzip-self-extracting-archive.yml +++ b/nursery/packaged-as-a-winzip-self-extracting-archive.yml @@ -2,7 +2,7 @@ rule: meta: name: packaged as a WinZip self-extracting archive namespace: executable/installer/winzip - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.hexacorn.com/blog/2016/12/15/pe-section-names-re-visited/ diff --git a/nursery/packaged-as-a-wise-installer.yml b/nursery/packaged-as-a-wise-installer.yml index 45730b99..601a3dda 100644 --- a/nursery/packaged-as-a-wise-installer.yml +++ b/nursery/packaged-as-a-wise-installer.yml @@ -2,7 +2,7 @@ rule: meta: name: packaged as a Wise installer namespace: executable/installer/wiseinstall - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file features: - or: diff --git a/nursery/packaged-as-an-installshield-installer.yml b/nursery/packaged-as-an-installshield-installer.yml index 3a994c04..7186ed1f 100644 --- a/nursery/packaged-as-an-installshield-installer.yml +++ b/nursery/packaged-as-an-installshield-installer.yml @@ -2,7 +2,7 @@ rule: meta: name: packaged as an InstallShield installer namespace: executable/installer/installshield - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: file features: - or: diff --git a/nursery/packed-with-ccg.yml b/nursery/packed-with-ccg.yml index 63eba165..378649aa 100644 --- a/nursery/packed-with-ccg.yml +++ b/nursery/packed-with-ccg.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with CCG namespace: anti-analysis/packer/ccg - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-crunch.yml b/nursery/packed-with-crunch.yml index 1ccc3d44..9460dcc2 100644 --- a/nursery/packed-with-crunch.yml +++ b/nursery/packed-with-crunch.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Crunch namespace: anti-analysis/packer/crunch - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-dragon-armor.yml b/nursery/packed-with-dragon-armor.yml index 67fba92f..88f46583 100644 --- a/nursery/packed-with-dragon-armor.yml +++ b/nursery/packed-with-dragon-armor.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Dragon Armor namespace: anti-analysis/packer/dragon-armor - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-enigma.yml b/nursery/packed-with-enigma.yml index e9adf4b5..f798f3e7 100644 --- a/nursery/packed-with-enigma.yml +++ b/nursery/packed-with-enigma.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with enigma namespace: anti-analysis/packer/enigma - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-epack.yml b/nursery/packed-with-epack.yml index 0e159701..32bd4980 100644 --- a/nursery/packed-with-epack.yml +++ b/nursery/packed-with-epack.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Epack namespace: anti-analysis/packer/epack - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-maskpe.yml b/nursery/packed-with-maskpe.yml index 37421d85..e95694e0 100644 --- a/nursery/packed-with-maskpe.yml +++ b/nursery/packed-with-maskpe.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with MaskPE namespace: anti-analysis/packer/maskpe - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-mew.yml b/nursery/packed-with-mew.yml index 93b0987a..cd5c00f3 100644 --- a/nursery/packed-with-mew.yml +++ b/nursery/packed-with-mew.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with MEW namespace: anti-analysis/packer/mew - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-mpress.yml b/nursery/packed-with-mpress.yml index 0dc0cd6d..8ee135c1 100644 --- a/nursery/packed-with-mpress.yml +++ b/nursery/packed-with-mpress.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Mpress namespace: anti-analysis/packer/mpress - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-neolite.yml b/nursery/packed-with-neolite.yml index 170bc6df..492dca76 100644 --- a/nursery/packed-with-neolite.yml +++ b/nursery/packed-with-neolite.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Neolite namespace: anti-analysis/packer/neolite - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-pepack.yml b/nursery/packed-with-pepack.yml index 10e05b8d..09666a06 100644 --- a/nursery/packed-with-pepack.yml +++ b/nursery/packed-with-pepack.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Pepack namespace: anti-analysis/packer/pepack - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-perplex.yml b/nursery/packed-with-perplex.yml index a27be977..2971a06e 100644 --- a/nursery/packed-with-perplex.yml +++ b/nursery/packed-with-perplex.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Perplex namespace: anti-analysis/packer/perplex - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-procrypt.yml b/nursery/packed-with-procrypt.yml index 18bb43a8..bd2af78e 100644 --- a/nursery/packed-with-procrypt.yml +++ b/nursery/packed-with-procrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with ProCrypt namespace: anti-analysis/packer/procrypt - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-rpcrypt.yml b/nursery/packed-with-rpcrypt.yml index 063b2b11..37033e10 100644 --- a/nursery/packed-with-rpcrypt.yml +++ b/nursery/packed-with-rpcrypt.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with RPCrypt namespace: anti-analysis/packer/rpcrypt - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-seausfx.yml b/nursery/packed-with-seausfx.yml index 71ecd2d7..f988bd35 100644 --- a/nursery/packed-with-seausfx.yml +++ b/nursery/packed-with-seausfx.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with SeauSFX namespace: anti-analysis/packer/seausfx - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-shrinker.yml b/nursery/packed-with-shrinker.yml index 83900206..92ac405d 100644 --- a/nursery/packed-with-shrinker.yml +++ b/nursery/packed-with-shrinker.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Shrinker namespace: anti-analysis/packer/shrinker - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-simple-pack.yml b/nursery/packed-with-simple-pack.yml index 25469ba1..3d49c3e9 100644 --- a/nursery/packed-with-simple-pack.yml +++ b/nursery/packed-with-simple-pack.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Simple Pack namespace: anti-analysis/packer/simple-pack - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-starforce.yml b/nursery/packed-with-starforce.yml index 5522e06a..9fb9c380 100644 --- a/nursery/packed-with-starforce.yml +++ b/nursery/packed-with-starforce.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with StarForce namespace: anti-analysis/packer/starforce - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-svkp.yml b/nursery/packed-with-svkp.yml index b35cda7b..1abaa866 100644 --- a/nursery/packed-with-svkp.yml +++ b/nursery/packed-with-svkp.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with SVKP namespace: anti-analysis/packer/svkp - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-themida.yml b/nursery/packed-with-themida.yml index 8cacadd8..9ef15c17 100644 --- a/nursery/packed-with-themida.yml +++ b/nursery/packed-with-themida.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with Themida namespace: anti-analysis/packer/themida - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-tsuloader.yml b/nursery/packed-with-tsuloader.yml index ce8c53dc..d8d3b35c 100644 --- a/nursery/packed-with-tsuloader.yml +++ b/nursery/packed-with-tsuloader.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with TSULoader namespace: anti-analysis/packer/tsuloader - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-vprotect.yml b/nursery/packed-with-vprotect.yml index 8abdc159..9e6d1b7e 100644 --- a/nursery/packed-with-vprotect.yml +++ b/nursery/packed-with-vprotect.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with VProtect namespace: anti-analysis/packer/vprotect - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/packed-with-wwpack.yml b/nursery/packed-with-wwpack.yml index dd36beb3..4e6dc00f 100644 --- a/nursery/packed-with-wwpack.yml +++ b/nursery/packed-with-wwpack.yml @@ -2,7 +2,7 @@ rule: meta: name: packed with WWPACK namespace: anti-analysis/packer/wwpack - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/nursery/parse-url.yml b/nursery/parse-url.yml index 46905fa6..ac50b65a 100644 --- a/nursery/parse-url.yml +++ b/nursery/parse-url.yml @@ -3,7 +3,7 @@ rule: meta: name: parse URL namespace: communication/http - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/prompt-user-for-credentials.yml b/nursery/prompt-user-for-credentials.yml index 8812007a..b6cfc943 100644 --- a/nursery/prompt-user-for-credentials.yml +++ b/nursery/prompt-user-for-credentials.yml @@ -3,7 +3,7 @@ rule: meta: name: prompt user for credentials namespace: collection/credentials - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function references: https://www.ired.team/offensive-security/credential-access-and-credential-dumping/credentials-collection-via-creduipromptforcredentials features: diff --git a/nursery/query-remote-server-for-available-data.yml b/nursery/query-remote-server-for-available-data.yml index 564a9118..ee29018a 100644 --- a/nursery/query-remote-server-for-available-data.yml +++ b/nursery/query-remote-server-for-available-data.yml @@ -3,7 +3,7 @@ rule: meta: name: query remote server for available data namespace: communication - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/read-and-send-data-from-client-to-server.yml b/nursery/read-and-send-data-from-client-to-server.yml index 1823beb0..838d644d 100644 --- a/nursery/read-and-send-data-from-client-to-server.yml +++ b/nursery/read-and-send-data-from-client-to-server.yml @@ -2,7 +2,7 @@ rule: meta: name: read and send data from client to server namespace: c2/file-transfer - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function features: - and: diff --git a/nursery/read-process-memory.yml b/nursery/read-process-memory.yml index 6111a919..0735ffa6 100644 --- a/nursery/read-process-memory.yml +++ b/nursery/read-process-memory.yml @@ -3,7 +3,7 @@ rule: name: read process memory namespace: host-interaction/process author: - - matthew.williams@fireeye.com + - matthew.williams@mandiant.com - "@_re_fox" scope: function features: diff --git a/nursery/read-raw-disk-data.yml b/nursery/read-raw-disk-data.yml index b4de1208..cdada737 100644 --- a/nursery/read-raw-disk-data.yml +++ b/nursery/read-raw-disk-data.yml @@ -2,7 +2,7 @@ rule: meta: name: read raw disk data namespace: host-interaction/file-system - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file features: - or: diff --git a/nursery/rebuilt-by-imprec.yml b/nursery/rebuilt-by-imprec.yml index f32d4f77..1ea037e0 100644 --- a/nursery/rebuilt-by-imprec.yml +++ b/nursery/rebuilt-by-imprec.yml @@ -2,7 +2,7 @@ rule: meta: name: rebuilt by ImpRec namespace: executable/imprec - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/ diff --git a/nursery/receive-and-write-data-from-server-to-client.yml b/nursery/receive-and-write-data-from-server-to-client.yml index 3936d10b..a03486b7 100644 --- a/nursery/receive-and-write-data-from-server-to-client.yml +++ b/nursery/receive-and-write-data-from-server-to-client.yml @@ -2,7 +2,7 @@ rule: meta: name: receive and write data from server to client namespace: c2/file-transfer - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function features: - and: diff --git a/nursery/reference-114dns-dns-server.yml b/nursery/reference-114dns-dns-server.yml index 8c579058..57e56d14 100644 --- a/nursery/reference-114dns-dns-server.yml +++ b/nursery/reference-114dns-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference 114DNS DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.114dns.com/ diff --git a/nursery/reference-aes-constants.yml b/nursery/reference-aes-constants.yml index f9b1929f..f123a0a5 100644 --- a/nursery/reference-aes-constants.yml +++ b/nursery/reference-aes-constants.yml @@ -2,7 +2,7 @@ rule: meta: name: reference AES constants namespace: data-manipulation/encryption/aes - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] diff --git a/nursery/reference-alidns-dns-server.yml b/nursery/reference-alidns-dns-server.yml index 5833b397..2a1f565e 100644 --- a/nursery/reference-alidns-dns-server.yml +++ b/nursery/reference-alidns-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference AliDNS DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.alidns.com/ diff --git a/nursery/reference-cloudflare-dns-server.yml b/nursery/reference-cloudflare-dns-server.yml index 00becf23..4f0bef82 100644 --- a/nursery/reference-cloudflare-dns-server.yml +++ b/nursery/reference-cloudflare-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Cloudflare DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.techradar.com/news/best-dns-server diff --git a/nursery/reference-comodo-secure-dns-server.yml b/nursery/reference-comodo-secure-dns-server.yml index c3cf6fa2..b7ac603d 100644 --- a/nursery/reference-comodo-secure-dns-server.yml +++ b/nursery/reference-comodo-secure-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Comodo Secure DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.techradar.com/news/best-dns-server diff --git a/nursery/reference-google-public-dns-server.yml b/nursery/reference-google-public-dns-server.yml index a704945c..46935657 100644 --- a/nursery/reference-google-public-dns-server.yml +++ b/nursery/reference-google-public-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Google Public DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.techradar.com/news/best-dns-server diff --git a/nursery/reference-hurricane-electric-dns-server.yml b/nursery/reference-hurricane-electric-dns-server.yml index a15b494c..b2e44872 100644 --- a/nursery/reference-hurricane-electric-dns-server.yml +++ b/nursery/reference-hurricane-electric-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Hurricane Electric DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://dns.he.net/ diff --git a/nursery/reference-kornet-dns-server.yml b/nursery/reference-kornet-dns-server.yml index a4aa3ffe..3e92456a 100644 --- a/nursery/reference-kornet-dns-server.yml +++ b/nursery/reference-kornet-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference kornet DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://whatismyipaddress.com/ip/168.126.63.1 diff --git a/nursery/reference-l3-dns-server.yml b/nursery/reference-l3-dns-server.yml index 96e28bbe..b9e43090 100644 --- a/nursery/reference-l3-dns-server.yml +++ b/nursery/reference-l3-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference L3 DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.quora.com/What-is-a-4-2-2-1-DNS-server diff --git a/nursery/reference-opendns-dns-server.yml b/nursery/reference-opendns-dns-server.yml index 047bd273..3dcb0a31 100644 --- a/nursery/reference-opendns-dns-server.yml +++ b/nursery/reference-opendns-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference OpenDNS DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.techradar.com/news/best-dns-server diff --git a/nursery/reference-processor-manufacturer-constants.yml b/nursery/reference-processor-manufacturer-constants.yml index 1255690c..3a284862 100644 --- a/nursery/reference-processor-manufacturer-constants.yml +++ b/nursery/reference-processor-manufacturer-constants.yml @@ -2,7 +2,7 @@ rule: meta: name: reference processor manufacturer constants namespace: anti-analysis/anti-vm/vm-detection - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/nursery/reference-quad9-dns-server.yml b/nursery/reference-quad9-dns-server.yml index 71a743d5..f6c161ef 100644 --- a/nursery/reference-quad9-dns-server.yml +++ b/nursery/reference-quad9-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Quad9 DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.techradar.com/news/best-dns-server diff --git a/nursery/reference-screen-saver-executable.yml b/nursery/reference-screen-saver-executable.yml index 1c227f46..27fe1b72 100644 --- a/nursery/reference-screen-saver-executable.yml +++ b/nursery/reference-screen-saver-executable.yml @@ -2,7 +2,7 @@ rule: meta: name: reference screen saver executable namespace: persistence/screensaver - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com description: SCRNSAVE.EXE registry value specifies the name of the screen saver executable file scope: function att&ck: diff --git a/nursery/reference-startup-folder.yml b/nursery/reference-startup-folder.yml index 5282a0d8..e8956778 100644 --- a/nursery/reference-startup-folder.yml +++ b/nursery/reference-startup-folder.yml @@ -2,7 +2,7 @@ rule: meta: name: reference startup folder namespace: persistence/startup-folder - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: file att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] diff --git a/nursery/reference-the-vmware-io-port.yml b/nursery/reference-the-vmware-io-port.yml index ea100926..7f0adaaa 100644 --- a/nursery/reference-the-vmware-io-port.yml +++ b/nursery/reference-the-vmware-io-port.yml @@ -2,7 +2,7 @@ rule: meta: name: reference the VMWare IO port namespace: anti-analysis/anti-vm/vm-detection - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] diff --git a/nursery/reference-verisign-dns-server.yml b/nursery/reference-verisign-dns-server.yml index 700442c4..28442728 100644 --- a/nursery/reference-verisign-dns-server.yml +++ b/nursery/reference-verisign-dns-server.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Verisign DNS server namespace: communication/dns - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.techradar.com/news/best-dns-server diff --git a/nursery/register-http-server-url.yml b/nursery/register-http-server-url.yml index ffb6c30f..9a45995e 100644 --- a/nursery/register-http-server-url.yml +++ b/nursery/register-http-server-url.yml @@ -3,7 +3,7 @@ rule: meta: name: register HTTP server URL namespace: communication/http/server - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/register-raw-input-devices.yml b/nursery/register-raw-input-devices.yml index 9e127747..64231d37 100644 --- a/nursery/register-raw-input-devices.yml +++ b/nursery/register-raw-input-devices.yml @@ -3,7 +3,7 @@ rule: meta: name: register raw input devices namespace: host-interaction/hardware - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - or: diff --git a/nursery/resize-volume-shadow-copy-storage.yml b/nursery/resize-volume-shadow-copy-storage.yml index 1b8a64d3..cc418d16 100644 --- a/nursery/resize-volume-shadow-copy-storage.yml +++ b/nursery/resize-volume-shadow-copy-storage.yml @@ -3,7 +3,7 @@ rule: meta: name: resize volume shadow copy storage namespace: impact/inhibit-system-recovery - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - and: diff --git a/nursery/resolve-function-by-hash.yml b/nursery/resolve-function-by-hash.yml index 4026cbc0..aa20f7a5 100644 --- a/nursery/resolve-function-by-hash.yml +++ b/nursery/resolve-function-by-hash.yml @@ -2,7 +2,7 @@ rule: meta: name: resolve function by hash namespace: linking/runtime-linking - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Defense Evasion::Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] diff --git a/nursery/run-in-container.yml b/nursery/run-in-container.yml index 7734c3f0..994037d7 100644 --- a/nursery/run-in-container.yml +++ b/nursery/run-in-container.yml @@ -2,7 +2,7 @@ rule: meta: name: run in container namespace: host-interaction/container/docker - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function att&ck: - Execution::Container Administration Command [T1609] diff --git a/nursery/run-powershell-expression.yml b/nursery/run-powershell-expression.yml index ac24bf6a..a65e9c4f 100644 --- a/nursery/run-powershell-expression.yml +++ b/nursery/run-powershell-expression.yml @@ -2,7 +2,7 @@ rule: meta: name: run PowerShell expression namespace: load-code/powershell/ - author: anamaria.martinezgom@fireeye.com + author: anamaria.martinezgom@mandiant.com scope: function att&ck: - Execution::Command and Scripting Interpreter::PowerShell [T1059.001] diff --git a/nursery/schedule-task-via-itaskservice.yml b/nursery/schedule-task-via-itaskservice.yml index 2b27d2ee..bc182a66 100644 --- a/nursery/schedule-task-via-itaskservice.yml +++ b/nursery/schedule-task-via-itaskservice.yml @@ -2,7 +2,7 @@ rule: meta: name: schedule task via ITaskService namespace: persistence/scheduled-tasks - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: function att&ck: - Persistence/Scheduled Task/Job/Scheduled Task [T1053.005] diff --git a/nursery/search-for-credit-card-data.yml b/nursery/search-for-credit-card-data.yml index bf4dc5e7..ff8f1d2c 100644 --- a/nursery/search-for-credit-card-data.yml +++ b/nursery/search-for-credit-card-data.yml @@ -2,7 +2,7 @@ rule: meta: name: search for credit card data namespace: collection/credit-card - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function features: - and: diff --git a/nursery/send-http-request-with-host-header.yml b/nursery/send-http-request-with-host-header.yml index 35454163..0125a83c 100644 --- a/nursery/send-http-request-with-host-header.yml +++ b/nursery/send-http-request-with-host-header.yml @@ -2,7 +2,7 @@ rule: meta: name: send HTTP request with Host header namespace: communication/http - author: anamaria.martinezgom@fireeye.com + author: anamaria.martinezgom@mandiant.com scope: function features: - and: diff --git a/nursery/set-global-application-hook.yml b/nursery/set-global-application-hook.yml index fa09f684..b98cf172 100644 --- a/nursery/set-global-application-hook.yml +++ b/nursery/set-global-application-hook.yml @@ -2,7 +2,7 @@ rule: meta: name: set global application hook namespace: host-interaction/gui - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block features: - and: diff --git a/nursery/spoof-parent-pid.yml b/nursery/spoof-parent-pid.yml index 8444859b..d5e4d975 100644 --- a/nursery/spoof-parent-pid.yml +++ b/nursery/spoof-parent-pid.yml @@ -3,7 +3,7 @@ rule: meta: name: spoof parent PID namespace: anti-analysis/anti-forensic - author: michael.hunhoff@fireeye.com + author: michael.hunhoff@mandiant.com scope: basic block references: https://blog.f-secure.com/detecting-parent-pid-spoofing/ features: diff --git a/nursery/terminate-process-by-name.yml b/nursery/terminate-process-by-name.yml index 2a8aed73..393ee9fc 100644 --- a/nursery/terminate-process-by-name.yml +++ b/nursery/terminate-process-by-name.yml @@ -2,7 +2,7 @@ rule: meta: name: terminate process by name namespace: host-interaction/process/terminate - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function examples: # - unpacked Cl0p ransomware diff --git a/persistence/registry/persist-via-active-setup-registry-key.yml b/persistence/registry/persist-via-active-setup-registry-key.yml index 9f1d4356..c4caf923 100644 --- a/persistence/registry/persist-via-active-setup-registry-key.yml +++ b/persistence/registry/persist-via-active-setup-registry-key.yml @@ -2,7 +2,7 @@ rule: meta: name: persist via Active Setup registry key namespace: persistence/registry - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Boot or Logon Autostart Execution::Active Setup [T1547.014] diff --git a/persistence/registry/run/persist-via-run-registry-key.yml b/persistence/registry/run/persist-via-run-registry-key.yml index f9fde909..135c8cbf 100644 --- a/persistence/registry/run/persist-via-run-registry-key.yml +++ b/persistence/registry/run/persist-via-run-registry-key.yml @@ -2,7 +2,7 @@ rule: meta: name: persist via Run registry key namespace: persistence/registry/run - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] diff --git a/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml b/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml index 6f89678b..be8ee2ab 100644 --- a/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml +++ b/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml @@ -2,7 +2,7 @@ rule: meta: name: schedule task via ITaskScheduler namespace: persistence/scheduled-tasks - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Scheduled Task/Job::Scheduled Task [T1053.005] diff --git a/persistence/service/persist-via-windows-service.yml b/persistence/service/persist-via-windows-service.yml index d6ad4d70..381f2022 100644 --- a/persistence/service/persist-via-windows-service.yml +++ b/persistence/service/persist-via-windows-service.yml @@ -2,7 +2,7 @@ rule: meta: name: persist via Windows service namespace: persistence/service - author: moritz.raabe@fireeye.com + author: moritz.raabe@mandiant.com scope: function att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] diff --git a/persistence/startup-folder/get-startup-folder.yml b/persistence/startup-folder/get-startup-folder.yml index 75aa9adf..558846bb 100644 --- a/persistence/startup-folder/get-startup-folder.yml +++ b/persistence/startup-folder/get-startup-folder.yml @@ -2,7 +2,7 @@ rule: meta: name: get startup folder namespace: persistence/startup-folder - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: basic block att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] diff --git a/persistence/startup-folder/write-file-to-startup-folder.yml b/persistence/startup-folder/write-file-to-startup-folder.yml index 88719b2f..04aa70b7 100644 --- a/persistence/startup-folder/write-file-to-startup-folder.yml +++ b/persistence/startup-folder/write-file-to-startup-folder.yml @@ -2,7 +2,7 @@ rule: meta: name: write file to startup folder namespace: persistence/startup-folder - author: matthew.williams@fireeye.com + author: matthew.williams@mandiant.com scope: function att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] diff --git a/runtime/dotnet/compiled-to-the-net-platform.yml b/runtime/dotnet/compiled-to-the-net-platform.yml index d67aa14a..ef1cfe7f 100644 --- a/runtime/dotnet/compiled-to-the-net-platform.yml +++ b/runtime/dotnet/compiled-to-the-net-platform.yml @@ -2,7 +2,7 @@ rule: meta: name: compiled to the .NET platform namespace: runtime/dotnet - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file examples: - b9f5bd514485fb06da39beff051b9fdc diff --git a/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml b/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml index 8c47851c..9f697f2f 100644 --- a/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml +++ b/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml @@ -2,7 +2,7 @@ rule: meta: name: load Diebold Nixdorf ATM library namespace: targeting/automated-teller-machine/diebold-nixdorf - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.vkremez.com/2017/12/lets-learn-cutlet-atm-malware-internals.html diff --git a/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml b/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml index 31a41c53..abda9adb 100644 --- a/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml +++ b/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml @@ -2,7 +2,7 @@ rule: meta: name: reference Diebold ATM routines namespace: targeting/automated-teller-machine/diebold-nixdorf - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.fireeye.com/blog/threat-research/2017/01/new_ploutus_variant.html diff --git a/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml b/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml index 5edba6f7..c42d73a5 100644 --- a/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml +++ b/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml @@ -2,7 +2,7 @@ rule: meta: name: identify ATM dispenser service provider namespace: targeting/automated-teller-machine - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://doc.axxonsoft.com/confluence/display/atm70en/Configuring+the+connection+to+the+dispenser+service+provider diff --git a/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml b/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml index 570ede03..6517345a 100644 --- a/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml +++ b/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml @@ -2,7 +2,7 @@ rule: meta: name: load NCR ATM library namespace: targeting/automated-teller-machine/ncr - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: file references: - https://www.pcworld.com/article/2824572/leaked-programming-manual-may-help-criminals-develop-more-atm-malware.html diff --git a/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml b/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml index 389664da..beced26d 100644 --- a/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml +++ b/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml @@ -2,7 +2,7 @@ rule: meta: name: reference NCR ATM library routines namespace: targeting/automated-teller-machine/ncr - author: william.ballenthin@fireeye.com + author: william.ballenthin@mandiant.com scope: function references: - https://www.pcworld.com/article/2824572/leaked-programming-manual-may-help-criminals-develop-more-atm-malware.html