From 784c9dca53c203449f8821f2f8b82825f471e30e Mon Sep 17 00:00:00 2001 From: mr-tz Date: Wed, 25 Oct 2023 16:01:12 +0200 Subject: [PATCH] upgrade rules using updated script --- ...-on-executable-memory-pages-using-arbitrary-code-guard.yml | 4 +++- anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml | 4 +++- .../anti-av/patch-event-tracing-for-windows-function.yml | 4 +++- .../protect-spawned-processes-with-mitigation-policies.yml | 4 +++- .../debugger-detection/check-for-debugger-via-api.yml | 4 +++- .../debugger-detection/check-for-hardware-breakpoints.yml | 4 +++- ...eck-for-kernel-debugger-via-shared-user-data-structure.yml | 4 +++- .../debugger-detection/check-for-outputdebugstring-error.yml | 4 +++- .../debugger-detection/check-for-peb-beingdebugged-flag.yml | 4 +++- .../debugger-detection/check-for-peb-ntglobalflag-flag.yml | 4 +++- .../check-for-protected-handle-exception.yml | 4 +++- .../debugger-detection/check-for-software-breakpoints.yml | 4 +++- .../check-for-time-delay-via-gettickcount.yml | 4 +++- .../check-for-time-delay-via-queryperformancecounter.yml | 4 +++- .../debugger-detection/check-for-trap-flag-exception.yml | 4 +++- .../debugger-detection/check-for-unexpected-memory-writes.yml | 4 +++- .../debugger-detection/check-process-job-object.yml | 4 +++- .../debugger-detection/check-processdebugport.yml | 4 +++- .../execute-anti-debugging-instructions.yml | 4 +++- .../debugger-evasion/hide-thread-from-debugger.yml | 4 +++- .../anti-disasm/64-bit-execution-via-heavens-gate.yml | 4 +++- anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml | 4 +++- .../wine/check-if-process-is-running-under-wine.yml | 4 +++- .../anti-forensic/clear-logs/clear-windows-event-logs.yml | 4 +++- .../anti-forensic/crash-the-windows-event-logging-service.yml | 4 +++- .../anti-forensic/impersonate-file-version-information.yml | 4 +++- anti-analysis/anti-forensic/patch-process-command-line.yml | 4 +++- anti-analysis/anti-forensic/self-deletion/self-delete.yml | 4 +++- anti-analysis/anti-forensic/spoof-parent-pid.yml | 4 +++- anti-analysis/anti-forensic/timestomp/timestomp-file.yml | 4 +++- .../vm-detection/check-for-foreground-window-switch.yml | 4 +++- .../vm-detection/check-for-microsoft-office-emulation.yml | 4 +++- .../vm-detection/check-for-sandbox-username-or-hostname.yml | 4 +++- .../anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml | 4 +++- .../vm-detection/check-for-windows-sandbox-via-device.yml | 4 +++- .../vm-detection/check-for-windows-sandbox-via-dns-suffix.yml | 4 +++- .../check-for-windows-sandbox-via-genuine-state.yml | 4 +++- .../check-for-windows-sandbox-via-process-name.yml | 4 +++- .../vm-detection/check-for-windows-sandbox-via-registry.yml | 4 +++- .../vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml | 4 +++- .../detect-vm-via-motherboard-hardware-wmi-queries.yml | 4 +++- .../reference-anti-vm-strings-targeting-parallels.yml | 4 +++- .../vm-detection/reference-anti-vm-strings-targeting-qemu.yml | 4 +++- .../reference-anti-vm-strings-targeting-virtualbox.yml | 4 +++- .../reference-anti-vm-strings-targeting-virtualpc.yml | 4 +++- .../reference-anti-vm-strings-targeting-vmware.yml | 4 +++- .../vm-detection/reference-anti-vm-strings-targeting-xen.yml | 4 +++- .../anti-vm/vm-detection/reference-anti-vm-strings.yml | 4 +++- anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml | 4 +++- .../obfuscation/obfuscated-with-babel-obfuscator.yml | 4 +++- anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml | 4 +++- .../obfuscation/obfuscated-with-deepsea-obfuscator.yml | 4 +++- anti-analysis/obfuscation/obfuscated-with-dotfuscator.yml | 4 +++- anti-analysis/obfuscation/obfuscated-with-smartassembly.yml | 4 +++- .../obfuscation/obfuscated-with-spicesdotnet-obfuscator.yml | 4 +++- anti-analysis/obfuscation/obfuscated-with-vs-obfuscation.yml | 4 +++- anti-analysis/obfuscation/obfuscated-with-yano.yml | 4 +++- .../string/stackstring/contain-obfuscated-stackstrings.yml | 4 +++- anti-analysis/packer/amber/packed-with-amber.yml | 4 +++- anti-analysis/packer/aspack/packed-with-aspack.yml | 4 +++- anti-analysis/packer/confuser/packed-with-confuser.yml | 4 +++- anti-analysis/packer/generic/packed-with-generic-packer.yml | 4 +++- anti-analysis/packer/gopacker/packed-with-gopacker.yml | 4 +++- anti-analysis/packer/huan/packed-with-huan.yml | 4 +++- anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml | 4 +++- anti-analysis/packer/nspack/packed-with-nspack.yml | 4 +++- anti-analysis/packer/pebundle/packed-with-pebundle.yml | 4 +++- anti-analysis/packer/pecompact/packed-with-pecompact.yml | 4 +++- anti-analysis/packer/pelocknt/packed-with-pelocknt.yml | 4 +++- anti-analysis/packer/peshield/packed-with-peshield.yml | 4 +++- anti-analysis/packer/pespin/packed-with-pespin.yml | 4 +++- anti-analysis/packer/petite/packed-with-petite.yml | 4 +++- anti-analysis/packer/rlpack/packed-with-rlpack.yml | 4 +++- anti-analysis/packer/themida/packed-with-themida.yml | 4 +++- anti-analysis/packer/upack/packed-with-upack.yml | 4 +++- anti-analysis/packer/upx/packed-with-upx.yml | 4 +++- anti-analysis/packer/vmprotect/packed-with-vmprotect.yml | 4 +++- anti-analysis/packer/y0da/packed-with-y0da-crypter.yml | 4 +++- anti-analysis/reference-analysis-tools-strings.yml | 4 +++- .../acquire-credentials-from-windows-credential-manager.yml | 4 +++- .../browser/gather-chrome-based-browser-login-information.yml | 4 +++- collection/browser/gather-firefox-profile-information.yml | 4 +++- collection/credit-card/parse-credit-card-information.yml | 4 +++- collection/database/sql/reference-sql-statements.yml | 4 +++- collection/database/wmi/reference-wmi-statements.yml | 4 +++- collection/file-managers/gather-3d-ftp-information.yml | 4 +++- collection/file-managers/gather-alftp-information.yml | 4 +++- collection/file-managers/gather-bitkinex-information.yml | 4 +++- collection/file-managers/gather-blazeftp-information.yml | 4 +++- .../file-managers/gather-bulletproof-ftp-information.yml | 4 +++- collection/file-managers/gather-classicftp-information.yml | 4 +++- collection/file-managers/gather-coreftp-information.yml | 4 +++- collection/file-managers/gather-cuteftp-information.yml | 4 +++- collection/file-managers/gather-cyberduck-information.yml | 4 +++- collection/file-managers/gather-direct-ftp-information.yml | 4 +++- .../file-managers/gather-directory-opus-information.yml | 4 +++- collection/file-managers/gather-expandrive-information.yml | 4 +++- .../file-managers/gather-faststone-browser-information.yml | 4 +++- collection/file-managers/gather-fasttrack-ftp-information.yml | 4 +++- collection/file-managers/gather-ffftp-information.yml | 4 +++- collection/file-managers/gather-filezilla-information.yml | 4 +++- collection/file-managers/gather-flashfxp-information.yml | 4 +++- collection/file-managers/gather-fling-ftp-information.yml | 4 +++- collection/file-managers/gather-freshftp-information.yml | 4 +++- collection/file-managers/gather-frigate3-information.yml | 4 +++- collection/file-managers/gather-ftp-commander-information.yml | 4 +++- collection/file-managers/gather-ftp-explorer-information.yml | 4 +++- collection/file-managers/gather-ftp-voyager-information.yml | 4 +++- collection/file-managers/gather-ftpgetter-information.yml | 4 +++- collection/file-managers/gather-ftpinfo-information.yml | 4 +++- collection/file-managers/gather-ftpnow-information.yml | 4 +++- collection/file-managers/gather-ftprush-information.yml | 4 +++- collection/file-managers/gather-ftpshell-information.yml | 4 +++- .../file-managers/gather-global-downloader-information.yml | 4 +++- collection/file-managers/gather-goftp-information.yml | 4 +++- collection/file-managers/gather-leapftp-information.yml | 4 +++- collection/file-managers/gather-netdrive-information.yml | 4 +++- collection/file-managers/gather-nexusfile-information.yml | 4 +++- collection/file-managers/gather-nova-ftp-information.yml | 4 +++- collection/file-managers/gather-robo-ftp-information.yml | 4 +++- collection/file-managers/gather-securefx-information.yml | 4 +++- collection/file-managers/gather-smart-ftp-information.yml | 4 +++- collection/file-managers/gather-softx-ftp-information.yml | 4 +++- .../file-managers/gather-southriver-webdrive-information.yml | 4 +++- collection/file-managers/gather-staff-ftp-information.yml | 4 +++- .../file-managers/gather-total-commander-information.yml | 4 +++- collection/file-managers/gather-turbo-ftp-information.yml | 4 +++- collection/file-managers/gather-ultrafxp-information.yml | 4 +++- collection/file-managers/gather-winscp-information.yml | 4 +++- collection/file-managers/gather-winzip-information.yml | 4 +++- collection/file-managers/gather-wise-ftp-information.yml | 4 +++- collection/file-managers/gather-ws-ftp-information.yml | 4 +++- collection/file-managers/gather-xftp-information.yml | 4 +++- collection/get-geographical-location.yml | 4 +++- .../group-policy/discover-group-policy-via-gpresult.yml | 4 +++- collection/keylog/log-keystrokes-via-application-hook.yml | 4 +++- collection/keylog/log-keystrokes-via-polling.yml | 4 +++- collection/keylog/log-keystrokes.yml | 4 +++- collection/microphone/capture-microphone-audio.yml | 4 +++- .../network/capture-network-configuration-via-ipconfig.yml | 4 +++- collection/network/capture-packets-using-sharppcap.yml | 4 +++- collection/network/capture-public-ip.yml | 4 +++- collection/network/get-domain-trust-relationships.yml | 4 +++- collection/network/get-mac-address-on-windows.yml | 4 +++- .../steal-keepass-passwords-using-keefarce.yml | 4 +++- collection/screenshot/capture-screenshot-via-keybd-event.yml | 4 +++- collection/screenshot/capture-screenshot.yml | 4 +++- collection/use-dotnet-library-sharpclipboard.yml | 4 +++- collection/webcam/capture-webcam-image.yml | 4 +++- communication/c2/file-transfer/download-and-write-a-file.yml | 4 +++- communication/c2/file-transfer/write-and-execute-a-file.yml | 4 +++- communication/c2/shell/create-reverse-shell-on-linux.yml | 4 +++- communication/c2/shell/create-reverse-shell.yml | 4 +++- .../c2/shell/execute-shell-command-and-capture-output.yml | 4 +++- .../execute-shell-command-received-from-socket-on-linux.yml | 4 +++- communication/dns/reference-dns-over-https-endpoints.yml | 4 +++- communication/dns/resolve-dns.yml | 4 +++- communication/ftp/send/send-file-using-ftp.yml | 4 +++- communication/http/client/check-http-status-code.yml | 4 +++- communication/http/client/connect-to-http-server.yml | 4 +++- communication/http/client/connect-to-url.yml | 4 +++- communication/http/client/create-bits-job.yml | 4 +++- communication/http/client/create-http-request.yml | 4 +++- .../decompress-http-response-via-iencodingfilterfactory.yml | 4 +++- communication/http/client/download-url.yml | 4 +++- communication/http/client/extract-http-body.yml | 4 +++- .../http/client/get-http-document-via-iwebbrowser2.yml | 4 +++- .../http/client/get-http-response-content-encoding.yml | 4 +++- communication/http/client/prepare-http-request.yml | 4 +++- communication/http/client/read-data-from-internet.yml | 4 +++- communication/http/client/receive-http-response.yml | 4 +++- communication/http/client/send-file-via-http.yml | 4 +++- communication/http/client/send-http-request.yml | 4 +++- communication/http/get-http-content-length.yml | 4 +++- communication/http/initialize-iwebbrowser2.yml | 4 +++- communication/http/initialize-winhttp-library.yml | 4 +++- communication/http/read-http-header.yml | 4 +++- communication/http/reference-http-user-agent-string.yml | 4 +++- communication/http/server/receive-http-request.yml | 4 +++- communication/http/server/send-http-response.yml | 4 +++- communication/http/server/start-http-server.yml | 4 +++- communication/http/set-http-header.yml | 4 +++- communication/icmp/send-icmp-echo-request.yml | 4 +++- communication/ip/convert-ip-address-from-string.yml | 4 +++- communication/mailslot/create-mailslot.yml | 4 +++- communication/mailslot/read-from-mailslot.yml | 4 +++- communication/named-pipe/connect/connect-pipe.yml | 4 +++- communication/named-pipe/create/create-pipe.yml | 4 +++- .../named-pipe/create/create-two-anonymous-pipes.yml | 4 +++- communication/named-pipe/read/read-pipe.yml | 4 +++- communication/named-pipe/write/write-pipe.yml | 4 +++- communication/receive-data.yml | 4 +++- communication/send-data.yml | 4 +++- communication/socket/create-raw-socket.yml | 4 +++- communication/socket/create-vmci-socket.yml | 4 +++- communication/socket/get-socket-status.yml | 4 +++- communication/socket/initialize-winsock-library.yml | 4 +++- communication/socket/receive/receive-data-on-socket.yml | 4 +++- communication/socket/send/send-data-on-socket.yml | 4 +++- communication/socket/set-socket-configuration.yml | 4 +++- communication/socket/tcp/connect-tcp-socket.yml | 4 +++- .../socket/tcp/create-tcp-socket-via-raw-afd-driver.yml | 4 +++- communication/socket/tcp/create-tcp-socket.yml | 4 +++- .../obtain-transmitpackets-callback-function-via-wsaioctl.yml | 4 +++- communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml | 4 +++- communication/socket/udp/send/create-udp-socket.yml | 4 +++- communication/tcp/client/act-as-tcp-client.yml | 4 +++- communication/tcp/serve/start-tcp-server.yml | 4 +++- compiler/autohotkey/compiled-with-autohotkey.yml | 4 +++- compiler/autoit/compiled-with-autoit.yml | 4 +++- compiler/cx_freeze/compiled-with-cx_freeze.yml | 4 +++- compiler/d/compiled-with-dmd.yml | 4 +++- compiler/delphi/compiled-with-borland-delphi.yml | 4 +++- compiler/exe4j/compiled-with-exe4j.yml | 4 +++- compiler/go/compiled-with-go.yml | 4 +++- compiler/mingw/compiled-with-mingw-for-windows.yml | 4 +++- compiler/nim/compiled-with-nim.yml | 4 +++- compiler/nuitka/compiled-with-nuitka.yml | 4 +++- compiler/perl2exe/compiled-with-perl2exe.yml | 4 +++- compiler/ps2exe/compiled-with-ps2exe.yml | 4 +++- compiler/py2exe/compiled-with-py2exe.yml | 4 +++- compiler/pyarmor/compiled-with-pyarmor.yml | 4 +++- compiler/rust/compiled-with-rust.yml | 4 +++- compiler/v/compiled-with-v.yml | 4 +++- compiler/vb/compiled-from-visual-basic.yml | 4 +++- compiler/zig/compiled-with-zig.yml | 4 +++- .../checksum/adler32/compute-adler32-checksum.yml | 4 +++- data-manipulation/checksum/crc32/hash-data-with-crc32.yml | 4 +++- .../validate-payment-card-number-using-luhn-algorithm.yml | 4 +++- data-manipulation/compression/compress-data-using-lzo.yml | 4 +++- data-manipulation/compression/compress-data-via-winapi.yml | 4 +++- .../compression/compress-data-via-zlib-inflate-or-deflate.yml | 4 +++- data-manipulation/compression/decompress-data-using-aplib.yml | 4 +++- data-manipulation/compression/decompress-data-using-lzo.yml | 4 +++- .../compression/decompress-data-using-quicklz.yml | 4 +++- data-manipulation/compression/decompress-data-using-ucl.yml | 4 +++- .../decompress-data-via-iencodingfilterfactory.yml | 4 +++- .../decode-data-using-base64-via-dword-translation-table.yml | 4 +++- .../encoding/base64/decode-data-using-base64-via-winapi.yml | 4 +++- .../encoding/base64/encode-data-using-base64-via-winapi.yml | 4 +++- .../encoding/base64/encode-data-using-base64.yml | 4 +++- data-manipulation/encoding/base64/reference-base64-string.yml | 4 +++- data-manipulation/encoding/xor/encode-data-using-xor.yml | 4 +++- .../aes/decrypt-data-using-aes-via-x86-extensions.yml | 4 +++- .../encryption/aes/encrypt-data-using-aes-mixcolumns-step.yml | 4 +++- .../encryption/aes/encrypt-data-using-aes-via-dotnet.yml | 4 +++- .../encryption/aes/encrypt-data-using-aes-via-winapi.yml | 4 +++- .../encryption/aes/manually-build-aes-constants.yml | 4 +++- .../encryption/aes/use-dotnet-library-encryptdecryptutils.yml | 4 +++- .../encryption/blowfish/encrypt-data-using-blowfish.yml | 4 +++- .../encryption/camellia/encrypt-data-using-camellia.yml | 4 +++- .../encryption/create-new-key-via-cryptacquirecontext.yml | 4 +++- .../encryption/des/encrypt-data-using-des-via-winapi.yml | 4 +++- data-manipulation/encryption/des/encrypt-data-using-des.yml | 4 +++- .../encryption/dpapi/encrypt-data-using-dpapi.yml | 4 +++- .../elliptic-curve/encrypt-data-using-curve25519.yml | 4 +++- .../encryption/encrypt-data-using-memfrob-from-glibc.yml | 4 +++- .../encryption/encrypt-or-decrypt-via-wincrypt.yml | 4 +++- .../get-outbound-credentials-handle-via-credssp.yml | 4 +++- .../hc-128/encrypt-data-using-hc-128-via-wolfssl.yml | 4 +++- .../encryption/hc-128/encrypt-data-using-hc-128.yml | 4 +++- data-manipulation/encryption/import-public-key.yml | 4 +++- .../encryption/rc4/encrypt-data-using-rc4-ksa.yml | 4 +++- .../encryption/rc4/encrypt-data-using-rc4-prga.yml | 4 +++- .../encryption/rc4/encrypt-data-using-rc4-via-winapi.yml | 4 +++- .../rc4/encrypt-data-using-rc4-with-custom-key-via-winapi.yml | 4 +++- data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml | 4 +++- data-manipulation/encryption/rsa/reference-public-rsa-key.yml | 4 +++- .../encryption/skipjack/encrypt-data-using-skipjack.yml | 4 +++- .../encryption/sosemanuk/encrypt-data-using-sosemanuk.yml | 4 +++- data-manipulation/encryption/tea/decrypt-data-using-tea.yml | 4 +++- data-manipulation/encryption/tea/encrypt-data-using-tea.yml | 4 +++- .../encryption/twofish/encrypt-data-using-twofish.yml | 4 +++- data-manipulation/encryption/vest/encrypt-data-using-vest.yml | 4 +++- data-manipulation/encryption/xtea/encrypt-data-using-xtea.yml | 4 +++- .../encryption/xxtea/encrypt-data-using-xxtea.yml | 4 +++- data-manipulation/hashing/djb2/hash-data-using-djb2.yml | 4 +++- data-manipulation/hashing/fnv/hash-data-using-fnv.yml | 4 +++- data-manipulation/hashing/hash-data-via-wincrypt.yml | 4 +++- data-manipulation/hashing/md5/hash-data-with-md5.yml | 4 +++- data-manipulation/hashing/murmur/hash-data-using-murmur3.yml | 4 +++- data-manipulation/hashing/sha1/hash-data-using-sha1.yml | 4 +++- data-manipulation/hashing/sha224/hash-data-using-sha224.yml | 4 +++- data-manipulation/hashing/sha256/hash-data-using-sha256.yml | 4 +++- data-manipulation/hashing/sha384/hash-data-using-sha384.yml | 4 +++- data-manipulation/hashing/sha512/hash-data-using-sha512.yml | 4 +++- data-manipulation/hashing/tiger/hash-data-using-tiger.yml | 4 +++- data-manipulation/hmac/authenticate-hmac.yml | 4 +++- data-manipulation/json/use-dotnet-library-newtonsoftjson.yml | 4 +++- .../prng/generate-random-numbers-via-rtlgenrandom.yml | 4 +++- data-manipulation/prng/generate-random-numbers-via-winapi.yml | 4 +++- .../generate-random-numbers-using-a-mersenne-twister.yml | 4 +++- data-manipulation/svg/use-dotnet-library-sharpvectors.yml | 4 +++- .../packaged-as-single-file-dotnet-application.yml | 4 +++- .../packaged-as-an-iexpress-self-extracting-archive.yml | 4 +++- .../inno-setup/packaged-as-an-inno-setup-installer.yml | 4 +++- executable/pe/export/forwarded-export.yml | 4 +++- executable/pe/pdb/contains-pdb-path.yml | 4 +++- .../tls/contain-a-thread-local-storage-tls-section.yml | 4 +++- executable/resource/access-dotnet-resource.yml | 4 +++- .../embed-dependencies-as-resources-using-fodycostura.yml | 4 +++- .../resource/extract-resource-via-kernel32-functions.yml | 4 +++- executable/subfile/pe/contain-an-embedded-pe-file.yml | 4 +++- host-interaction/bootloader/disable-code-signing.yml | 4 +++- host-interaction/bootloader/get-uefi-variable.yml | 4 +++- host-interaction/bootloader/manipulate-boot-configuration.yml | 4 +++- host-interaction/bootloader/manipulate-safe-mode-programs.yml | 4 +++- host-interaction/bootloader/set-uefi-variable.yml | 4 +++- host-interaction/cli/accept-command-line-arguments.yml | 4 +++- host-interaction/cli/resolve-path-using-msvcrt.yml | 4 +++- host-interaction/clipboard/open-clipboard.yml | 4 +++- host-interaction/clipboard/read-clipboard-data.yml | 4 +++- host-interaction/clipboard/write-clipboard-data.yml | 4 +++- host-interaction/console/manipulate-console-buffer.yml | 4 +++- host-interaction/driver/create-device-object.yml | 4 +++- host-interaction/driver/disable-driver-code-integrity.yml | 4 +++- host-interaction/driver/install-driver.yml | 4 +++- .../driver/interact-with-driver-via-control-codes.yml | 4 +++- .../environment-variable/get-comspec-environment-variable.yml | 4 +++- .../environment-variable/query-environment-variable.yml | 4 +++- .../environment-variable/set-environment-variable.yml | 4 +++- host-interaction/file-system/bypass-mark-of-the-web.yml | 4 +++- .../file-system/change-file-permission-on-linux.yml | 4 +++- host-interaction/file-system/copy/copy-file.yml | 4 +++- .../file-system/create-virtual-file-system-in-dotnet.yml | 4 +++- host-interaction/file-system/create/create-directory.yml | 4 +++- host-interaction/file-system/delete/delete-directory.yml | 4 +++- host-interaction/file-system/delete/delete-file.yml | 4 +++- host-interaction/file-system/exists/check-if-file-exists.yml | 4 +++- .../file-system/files/list/enumerate-files-on-linux.yml | 4 +++- .../file-system/files/list/enumerate-files-on-windows.yml | 4 +++- .../file-system/files/list/enumerate-files-recursively.yml | 4 +++- host-interaction/file-system/get-common-file-path.yml | 4 +++- .../file-system/get-file-system-object-information.yml | 4 +++- host-interaction/file-system/get-program-files-directory.yml | 4 +++- .../get-windows-directory-from-kuser_shared_data.yml | 4 +++- host-interaction/file-system/meta/get-file-attributes.yml | 4 +++- host-interaction/file-system/meta/get-file-size.yml | 4 +++- host-interaction/file-system/meta/get-file-version-info.yml | 4 +++- host-interaction/file-system/meta/set-file-attributes.yml | 4 +++- host-interaction/file-system/move/move-file.yml | 4 +++- host-interaction/file-system/read/read-file-on-linux.yml | 4 +++- host-interaction/file-system/read/read-file-on-windows.yml | 4 +++- host-interaction/file-system/read/read-file-via-mapping.yml | 4 +++- host-interaction/file-system/read/read-ini-file.yml | 4 +++- host-interaction/file-system/read/read-virtual-disk.yml | 4 +++- .../file-system/reference-absolute-stream-path-on-windows.yml | 4 +++- .../bypass-windows-file-protection.yml | 4 +++- host-interaction/file-system/write/write-file-on-linux.yml | 4 +++- host-interaction/file-system/write/write-file-on-windows.yml | 4 +++- host-interaction/filter/enumerate-minifilter-drivers.yml | 4 +++- host-interaction/filter/register-minifilter-driver.yml | 4 +++- host-interaction/filter/start-minifilter-driver.yml | 4 +++- .../modify/access-firewall-settings-via-inetfwmgr.yml | 4 +++- host-interaction/gui/console/set-console-window-title.yml | 4 +++- host-interaction/gui/enumerate-gui-resources.yml | 4 +++- host-interaction/gui/logon/references-logon-banner.yml | 4 +++- host-interaction/gui/session/lock/lock-the-desktop.yml | 4 +++- .../gui/session/wallpaper/change-the-wallpaper.yml | 4 +++- host-interaction/gui/set-application-hook.yml | 4 +++- host-interaction/gui/switch-active-desktop.yml | 4 +++- host-interaction/gui/taskbar/find/find-taskbar.yml | 4 +++- .../gui/taskbar/hide/hide-the-windows-taskbar.yml | 4 +++- host-interaction/gui/window/find/find-graphical-window.yml | 4 +++- .../gui/window/get-text/get-graphical-window-text.yml | 4 +++- host-interaction/gui/window/hide/hide-graphical-window.yml | 4 +++- host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml | 4 +++- host-interaction/hardware/cpu/get-cpu-information.yml | 4 +++- .../hardware/cpu/get-number-of-processor-cores.yml | 4 +++- host-interaction/hardware/cpu/get-number-of-processors.yml | 4 +++- host-interaction/hardware/enumerate-devices-by-category.yml | 4 +++- host-interaction/hardware/keyboard/get-keyboard-layout.yml | 4 +++- host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml | 4 +++- host-interaction/hardware/memory/get-memory-capacity.yml | 4 +++- host-interaction/hardware/memory/get-memory-information.yml | 4 +++- host-interaction/hardware/mouse/swap-mouse-buttons.yml | 4 +++- .../hardware/storage/enumerate-disk-properties.yml | 4 +++- host-interaction/hardware/storage/get-disk-information.yml | 4 +++- host-interaction/hardware/storage/get-disk-size.yml | 4 +++- .../log/clfs/read-data-from-clfs-log-container.yml | 4 +++- .../log/debug/write-event/print-debug-messages.yml | 4 +++- .../log/winevt/access/access-the-windows-event-log.yml | 4 +++- .../memory/create-new-application-domain-in-dotnet.yml | 4 +++- host-interaction/mutex/check-mutex-and-exit.yml | 4 +++- host-interaction/mutex/check-mutex.yml | 4 +++- host-interaction/mutex/create-mutex.yml | 4 +++- host-interaction/mutex/create-semaphore-on-linux.yml | 4 +++- host-interaction/mutex/lock-file.yml | 4 +++- host-interaction/mutex/lock-semaphore-on-linux.yml | 4 +++- host-interaction/mutex/unlock-semaphore-on-linux.yml | 4 +++- host-interaction/network/address/get-local-ipv4-addresses.yml | 4 +++- .../connectivity/check-internet-connectivity-via-wininet.yml | 4 +++- .../network/connectivity/set-tcp-connection-state.yml | 4 +++- .../network/domain/enumerate-domain-computers-via-ldap.yml | 4 +++- .../network/domain/get-domain-controller-name.yml | 4 +++- host-interaction/network/domain/get-domain-information.yml | 4 +++- .../network/interface/get-networking-interfaces.yml | 4 +++- .../network/traffic/copy/copy-network-traffic.yml | 4 +++- .../traffic/filter/register-network-filter-via-wfp-api.yml | 4 +++- host-interaction/os/hostname/get-hostname.yml | 4 +++- .../os/info/get-system-information-on-windows.yml | 4 +++- host-interaction/os/shutdown-system.yml | 4 +++- host-interaction/os/version/check-os-version.yml | 4 +++- host-interaction/os/version/get-kernel-version.yml | 4 +++- host-interaction/os/version/get-linux-distribution.yml | 4 +++- host-interaction/process/allocate-thread-local-storage.yml | 4 +++- .../create-a-process-with-modified-io-handles-and-window.yml | 4 +++- host-interaction/process/create/create-process-on-linux.yml | 4 +++- host-interaction/process/create/create-process-on-windows.yml | 4 +++- host-interaction/process/create/create-process-suspended.yml | 4 +++- host-interaction/process/create/execute-command.yml | 4 +++- .../process/dump/create-process-memory-minidump.yml | 4 +++- host-interaction/process/get-process-heap-flags.yml | 4 +++- host-interaction/process/get-process-heap-force-flags.yml | 4 +++- .../process/inject/allocate-or-change-rwx-memory.yml | 4 +++- .../process/inject/allocate-user-process-rwx-memory.yml | 4 +++- .../process/inject/attach-user-process-memory.yml | 4 +++- host-interaction/process/inject/free-user-process-memory.yml | 4 +++- host-interaction/process/inject/hijack-thread-execution.yml | 4 +++- host-interaction/process/inject/inject-apc.yml | 4 +++- host-interaction/process/inject/inject-dll.yml | 4 +++- host-interaction/process/inject/inject-pe.yml | 4 +++- .../inject/inject-shellcode-using-a-file-mapping-object.yml | 4 +++- .../inject/inject-shellcode-using-extra-window-memory.yml | 4 +++- .../inject-shellcode-using-window-subclass-procedure.yml | 4 +++- host-interaction/process/inject/inject-thread.yml | 4 +++- host-interaction/process/inject/use-process-doppelgänging.yml | 4 +++- host-interaction/process/inject/use-process-replacement.yml | 4 +++- .../enumerate-processes-on-remote-desktop-session-host.yml | 4 +++- .../list/enumerate-processes-via-ntquerysysteminformation.yml | 4 +++- host-interaction/process/list/enumerate-processes.yml | 4 +++- host-interaction/process/list/find-process-by-pid.yml | 4 +++- host-interaction/process/list/get-explorer-pid.yml | 4 +++- host-interaction/process/map-section-object.yml | 4 +++- host-interaction/process/modify/acquire-debug-privileges.yml | 4 +++- host-interaction/process/modify/modify-access-privileges.yml | 4 +++- .../process/modules/list/enumerate-process-modules.yml | 4 +++- host-interaction/process/set-thread-local-storage-value.yml | 4 +++- .../process/terminate/terminate-process-via-kill.yml | 4 +++- host-interaction/process/terminate/terminate-process.yml | 4 +++- host-interaction/recycle-bin/empty-recycle-bin-quietly.yml | 4 +++- .../create-registry-key-via-offline-registry-library.yml | 4 +++- host-interaction/registry/create/set-registry-value.yml | 4 +++- host-interaction/registry/delete/delete-registry-key.yml | 4 +++- host-interaction/registry/delete/delete-registry-value.yml | 4 +++- .../open-registry-key-via-offline-registry-library.yml | 4 +++- host-interaction/registry/query-or-enumerate-registry-key.yml | 4 +++- .../registry/query-or-enumerate-registry-value.yml | 4 +++- .../query-registry-key-via-offline-registry-library.yml | 4 +++- .../set-registry-key-via-offline-registry-library.yml | 4 +++- host-interaction/service/continue-service.yml | 4 +++- host-interaction/service/create/create-service.yml | 4 +++- host-interaction/service/delete/delete-service.yml | 4 +++- host-interaction/service/list/enumerate-services.yml | 4 +++- host-interaction/service/modify/modify-service.yml | 4 +++- host-interaction/service/pause-service.yml | 4 +++- host-interaction/service/query-service-configuration.yml | 4 +++- host-interaction/service/query-service-status.yml | 4 +++- host-interaction/service/run-as-service.yml | 4 +++- host-interaction/service/start/start-service.yml | 4 +++- host-interaction/service/stop/stop-service.yml | 4 +++- host-interaction/session/get-current-user-on-linux.yml | 4 +++- host-interaction/session/get-logon-sessions.yml | 4 +++- host-interaction/session/get-session-integrity-level.yml | 4 +++- host-interaction/session/get-session-user-name.yml | 4 +++- host-interaction/session/get-token-membership.yml | 4 +++- host-interaction/session/get-user-security-identifier.yml | 4 +++- host-interaction/software/get-installed-programs.yml | 4 +++- host-interaction/thread/create/create-thread.yml | 4 +++- host-interaction/thread/list/enumerate-threads.yml | 4 +++- host-interaction/thread/resume/resume-thread.yml | 4 +++- host-interaction/thread/suspend/suspend-thread.yml | 4 +++- host-interaction/thread/terminate/terminate-thread.yml | 4 +++- host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml | 4 +++- host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml | 4 +++- host-interaction/uac/bypass/bypass-uac-via-rpc.yml | 4 +++- .../uac/bypass/bypass-uac-via-token-manipulation.yml | 4 +++- .../wmi/connect-to-wmi-namespace-via-wbemlocator.yml | 4 +++- .../inhibit-system-recovery/delete-volume-shadow-copies.yml | 4 +++- .../wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml | 4 +++- .../limitation/file/internal-autohotkey-file-limitation.yml | 4 +++- internal/limitation/file/internal-autoit-file-limitation.yml | 4 +++- .../limitation/file/internal-installer-file-limitation.yml | 4 +++- internal/limitation/file/internal-packer-file-limitation.yml | 4 +++- .../limitation/file/internal-visual-basic-file-limitation.yml | 4 +++- lib/allocate-memory.yml | 4 +++- lib/allocate-or-change-rw-memory.yml | 4 +++- lib/calculate-modulo-256-via-x86-assembly.yml | 4 +++- lib/change-memory-protection.yml | 4 +++- lib/contain-loop.yml | 4 +++- lib/contain-pusha-popa-sequence.yml | 4 +++- lib/create-or-open-file.yml | 4 +++- lib/create-or-open-registry-key.yml | 4 +++- lib/create-or-open-section-object.yml | 4 +++- lib/delay-execution.yml | 4 +++- lib/duplicate-stdin-and-stdout.yml | 4 +++- lib/get-os-version.yml | 4 +++- lib/get-service-handle.yml | 4 +++- lib/open-process.yml | 4 +++- lib/open-thread.yml | 4 +++- lib/peb-access.yml | 4 +++- ...ent-card-number-using-luhn-algorithm-with-lookup-table.yml | 4 +++- ...-card-number-using-luhn-algorithm-with-no-lookup-table.yml | 4 +++- lib/write-process-memory.yml | 4 +++- linking/runtime-linking/access-peb-ldr_data.yml | 4 +++- linking/runtime-linking/get-kernel32-base-address.yml | 4 +++- linking/runtime-linking/get-ntdll-base-address.yml | 4 +++- .../runtime-linking/link-function-at-runtime-on-windows.yml | 4 +++- linking/runtime-linking/link-many-functions-at-runtime.yml | 4 +++- .../resolve-function-by-brute-ratel-badger-hash.yml | 4 +++- linking/runtime-linking/resolve-function-by-fin8-fasthash.yml | 4 +++- linking/static/aplib/linked-against-aplib.yml | 4 +++- linking/static/cryptopp/linked-against-crypto.yml | 4 +++- linking/static/libcurl/linked-against-libcurl.yml | 4 +++- linking/static/linked-against-cpp-standard-library.yml | 4 +++- linking/static/msdetours/linked-against-microsoft-detours.yml | 4 +++- linking/static/openssl/linked-against-openssl.yml | 4 +++- linking/static/polarssl/linked-against-polarsslmbed-tls.yml | 4 +++- linking/static/sqlite3/linked-against-cppsqlite3.yml | 4 +++- linking/static/sqlite3/linked-against-sqlite3.yml | 4 +++- linking/static/wolfcrypt/linked-against-wolfcrypt.yml | 4 +++- linking/static/wolfssl/linked-against-wolfssl.yml | 4 +++- linking/static/zlib/linked-against-zlib.yml | 4 +++- load-code/dotnet/load-windows-common-language-runtime.yml | 4 +++- .../execute-vbscript-javascript-or-jscript-in-memory.yml | 4 +++- load-code/pe/access-pe-header.yml | 4 +++- load-code/pe/enumerate-pe-sections.yml | 4 +++- load-code/pe/inject-dll-reflectively.yml | 4 +++- load-code/pe/inspect-section-memory-permissions.yml | 4 +++- load-code/pe/parse-pe-header.yml | 4 +++- load-code/pe/rebuild-import-table.yml | 4 +++- load-code/pe/resolve-function-by-parsing-pe-exports.yml | 4 +++- load-code/powershell/run-powershell-expression.yml | 4 +++- load-code/shellcode/execute-shellcode-via-copyfile2.yml | 4 +++- .../shellcode/execute-shellcode-via-createthreadpoolwait.yml | 4 +++- .../execute-shellcode-via-windows-callback-function.yml | 4 +++- load-code/shellcode/execute-shellcode-via-windows-fibers.yml | 4 +++- load-code/shellcode/spawn-thread-to-rwx-shellcode.yml | 4 +++- malware-family/plugx/match-known-plugx-module.yml | 4 +++- nursery/access-wmi-data-in-dotnet.yml | 4 +++- nursery/add-file-to-cabinet-file.yml | 4 +++- nursery/add-user-account-group.yml | 4 +++- nursery/add-user-account-to-group.yml | 4 +++- nursery/add-user-account.yml | 4 +++- nursery/add-value-to-global-atom-table.yml | 4 +++- nursery/allocate-unmanaged-memory-in-dotnet.yml | 4 +++- nursery/append-data-to-clfs-log-container.yml | 4 +++- nursery/authenticate-data-with-md5-mac.yml | 4 +++- nursery/build-docker-image.yml | 4 +++- .../bypass-uac-via-scheduled-task-environment-variable.yml | 4 +++- nursery/capture-network-configuration-via-ifconfig.yml | 4 +++- nursery/capture-process-snapshot-data.yml | 4 +++- nursery/capture-screenshot-in-go.yml | 4 +++- nursery/capture-webcam-video.yml | 4 +++- nursery/change-user-account-password.yml | 4 +++- nursery/check-clipboard-data.yml | 4 +++- nursery/check-file-extension-in-dotnet.yml | 4 +++- nursery/check-for-minimum-number-of-windows-on-screen.yml | 4 +++- nursery/check-for-process-debug-object.yml | 4 +++- nursery/check-for-sandbox-via-mac-address-ouis-in-dotnet.yml | 4 +++- nursery/check-for-vm-using-instruction-vpcext.yml | 4 +++- nursery/check-for-windows-sandbox-via-mutex.yml | 4 +++- nursery/check-for-windows-sandbox-via-subdirectory.yml | 4 +++- nursery/check-if-directory-exists.yml | 4 +++- nursery/check-license-value.yml | 4 +++- nursery/check-processdebugflags.yml | 4 +++- nursery/check-systemkerneldebuggerinformation.yml | 4 +++- nursery/check-thread-yield-allowed.yml | 4 +++- nursery/clear-clipboard-data.yml | 4 +++- nursery/collect-ssh-keys.yml | 4 +++- ...unicate-with-kernel-module-via-netlink-socket-on-linux.yml | 4 +++- nursery/compare-security-identifiers.yml | 4 +++- nursery/compile-csharp-in-dotnet.yml | 4 +++- nursery/compile-dotnet-assembly.yml | 4 +++- nursery/compile-visual-basic-in-dotnet.yml | 4 +++- nursery/compiled-from-epl.yml | 4 +++- nursery/compiled-with-exescript.yml | 4 +++- nursery/compress-data-using-gzip-in-dotnet.yml | 4 +++- nursery/connect-network-resource.yml | 4 +++- .../contain-a-thread-local-storage-tls-section-in-dotnet.yml | 4 +++- ...d-write-data-to-windows-directory-using-indirect-calls.yml | 4 +++- nursery/create-container.yml | 4 +++- nursery/create-process-via-wmi-in-dotnet.yml | 4 +++- nursery/create-registry-key-via-stdregprov.yml | 4 +++- nursery/create-restart-manager-session.yml | 4 +++- nursery/create-zip-archive-in-dotnet.yml | 4 +++- nursery/debug-build.yml | 4 +++- nursery/decode-data-using-base64-in-dotnet.yml | 4 +++- nursery/decode-data-using-url-encoding.yml | 4 +++- nursery/decrypt-data-using-rsa.yml | 4 +++- nursery/decrypt-data-via-sspi.yml | 4 +++- nursery/delete-internet-cache.yml | 4 +++- nursery/delete-registry-key-via-offline-registry-library.yml | 4 +++- nursery/delete-registry-key-via-stdregprov.yml | 4 +++- nursery/delete-registry-value-via-stdregprov.yml | 4 +++- nursery/delete-user-account-from-group.yml | 4 +++- nursery/delete-user-account-group.yml | 4 +++- nursery/delete-user-account.yml | 4 +++- nursery/delete-windows-backup-catalog.yml | 4 +++- nursery/deserialize-json-in-dotnet.yml | 4 +++- nursery/destroy-software-breakpoint-capability.yml | 4 +++- nursery/disable-automatic-windows-recovery-features.yml | 4 +++- nursery/display-service-notification-message-box.yml | 4 +++- nursery/empty-the-recycle-bin.yml | 4 +++- nursery/enable-safe-mode-boot.yml | 4 +++- nursery/encrypt-data-using-aes-via-x86-extensions.yml | 4 +++- nursery/encrypt-data-using-aes.yml | 4 +++- nursery/encrypt-data-using-fakem-cipher.yml | 4 +++- nursery/encrypt-data-using-openssl-dsa.yml | 4 +++- nursery/encrypt-data-using-openssl-ecdsa.yml | 4 +++- nursery/encrypt-data-using-openssl-rsa.yml | 4 +++- nursery/encrypt-data-using-rc4-via-systemfunction032.yml | 4 +++- nursery/encrypt-data-using-rsa.yml | 4 +++- nursery/encrypt-data-using-salsa20-or-chacha.yml | 4 +++- nursery/encrypt-data-via-sspi.yml | 4 +++- nursery/encrypt-or-decrypt-data-via-bcrypt.yml | 4 +++- nursery/enumerate-browser-history.yml | 4 +++- nursery/enumerate-device-drivers-on-linux.yml | 4 +++- nursery/enumerate-device-drivers-on-windows.yml | 4 +++- nursery/enumerate-disk-volumes.yml | 4 +++- nursery/enumerate-drives.yml | 4 +++- nursery/enumerate-internet-cache.yml | 4 +++- nursery/enumerate-network-shares.yml | 4 +++- nursery/enumerate-pe-sections-in-dotnet.yml | 4 +++- nursery/enumerate-processes-that-use-resource.yml | 4 +++- nursery/enumerate-processes-via-procfs.yml | 4 +++- nursery/enumerate-system-firmware-tables.yml | 4 +++- nursery/execute-dotnet-assembly.yml | 4 +++- .../execute-shell-command-via-windows-remote-management.yml | 4 +++- nursery/execute-shellcode-via-indirect-call.yml | 4 +++- nursery/execute-sqlite-statement-in-dotnet.yml | 4 +++- nursery/execute-syscall-instruction.yml | 4 +++- nursery/execute-via-asynchronous-task-in-dotnet.yml | 4 +++- nursery/execute-via-timer-in-dotnet.yml | 4 +++- nursery/extract-zip-archive-in-dotnet.yml | 4 +++- nursery/find-data-using-regex-in-dotnet.yml | 4 +++- nursery/find-process-by-name.yml | 4 +++- nursery/flush-cabinet-file.yml | 4 +++- nursery/generate-method-via-reflection-in-dotnet.yml | 4 +++- nursery/generate-random-bytes-in-dotnet.yml | 4 +++- nursery/generate-random-filename-in-dotnet.yml | 4 +++- nursery/generate-random-numbers-in-dotnet.yml | 4 +++- nursery/generate-random-numbers-using-the-delphi-lcg.yml | 4 +++- nursery/get-client-handle-via-schannel.yml | 4 +++- nursery/get-current-pid-on-linux.yml | 4 +++- nursery/get-file-system-information-on-linux.yml | 4 +++- nursery/get-http-request-uri.yml | 4 +++- nursery/get-inbound-credentials-handle-via-credssp.yml | 4 +++- nursery/get-mac-address-on-linux.yml | 4 +++- nursery/get-networking-parameters.yml | 4 +++- nursery/get-ntoskrnl-base-address.yml | 4 +++- nursery/get-os-information-via-kuser_shared_data.yml | 4 +++- nursery/get-os-version-in-dotnet.yml | 4 +++- nursery/get-password-database-entry-on-linux.yml | 4 +++- nursery/get-process-image-filename.yml | 4 +++- nursery/get-proxy.yml | 4 +++- nursery/get-remote-cert-context-via-schannel.yml | 4 +++- nursery/get-routing-table.yml | 4 +++- nursery/get-session-information.yml | 4 +++- nursery/get-socket-information.yml | 4 +++- nursery/get-storage-device-properties.yml | 4 +++- nursery/get-system-firmware-table.yml | 4 +++- nursery/get-system-information-on-linux.yml | 4 +++- nursery/get-system-web-proxy.yml | 4 +++- nursery/get-thread-local-storage-value.yml | 4 +++- nursery/get-token-privileges.yml | 4 +++- nursery/hash-data-using-aphash.yml | 4 +++- nursery/hash-data-using-crc32b.yml | 4 +++- nursery/hash-data-using-jshash.yml | 4 +++- nursery/hash-data-using-md4.yml | 4 +++- nursery/hash-data-using-murmur2.yml | 4 +++- nursery/hash-data-using-ripemd128.yml | 4 +++- nursery/hash-data-using-ripemd256.yml | 4 +++- nursery/hash-data-using-ripemd320.yml | 4 +++- nursery/hash-data-using-rshash.yml | 4 +++- nursery/hash-data-using-sha1-via-wincrypt.yml | 4 +++- nursery/hash-data-using-sha1-via-x86-extensions.yml | 4 +++- nursery/hash-data-using-sha256-via-x86-extensions.yml | 4 +++- nursery/hash-data-using-sha512managed-in-dotnet.yml | 4 +++- nursery/hash-data-using-whirlpool.yml | 4 +++- nursery/hash-data-via-bcrypt.yml | 4 +++- nursery/hook-routines-via-microsoft-detours.yml | 4 +++- nursery/hooked-by-api-override.yml | 4 +++- nursery/impersonate-user.yml | 4 +++- nursery/implement-com-dll.yml | 4 +++- nursery/initialize-hashing-via-wincrypt.yml | 4 +++- nursery/inspect-load-icon-resource.yml | 4 +++- nursery/interact-with-iptables.yml | 4 +++- nursery/invoke-dotnet-assembly-method.yml | 4 +++- nursery/link-function-at-runtime-on-linux.yml | 4 +++- nursery/linked-against-cpp-http-library.yml | 4 +++- nursery/linked-against-cpp-json-library.yml | 4 +++- nursery/linked-against-cpp-regex-library.yml | 4 +++- nursery/linked-against-go-process-enumeration-library.yml | 4 +++- nursery/linked-against-go-registry-library.yml | 4 +++- nursery/linked-against-go-static-asset-library.yml | 4 +++- nursery/linked-against-go-wmi-library.yml | 4 +++- nursery/linked-against-libsodium.yml | 4 +++- nursery/linked-against-xzip.yml | 4 +++- nursery/list-containers.yml | 4 +++- nursery/list-domain-servers.yml | 4 +++- nursery/list-drag-and-drop-files.yml | 4 +++- nursery/list-groups-for-user-account.yml | 4 +++- nursery/list-tcp-connections-and-listeners.yml | 4 +++- nursery/list-udp-connections-and-listeners.yml | 4 +++- nursery/list-user-account-groups.yml | 4 +++- nursery/list-user-accounts-for-group.yml | 4 +++- nursery/list-user-accounts.yml | 4 +++- nursery/listen-for-remote-procedure-calls.yml | 4 +++- nursery/load-dotnet-assembly.yml | 4 +++- nursery/load-xml-in-dotnet.yml | 4 +++- nursery/log-keystrokes-via-input-method-manager.yml | 4 +++- nursery/log-keystrokes-via-raw-input-data.yml | 4 +++- nursery/make-an-http-request-with-a-cookie.yml | 4 +++- nursery/manipulate-console-window.yml | 4 +++- nursery/manipulate-network-credentials-in-dotnet.yml | 4 +++- nursery/manipulate-unmanaged-memory-in-dotnet.yml | 4 +++- nursery/manipulate-user-privileges.yml | 4 +++- nursery/mark-thread-detached-on-linux.yml | 4 +++- nursery/migrate-process-to-active-window-station.yml | 4 +++- nursery/mixed-mode.yml | 4 +++- nursery/monitor-clipboard-content.yml | 4 +++- nursery/monitor-local-ipv4-address-changes.yml | 4 +++- nursery/move-directory.yml | 4 +++- nursery/obfuscated-with-koivm.yml | 4 +++- nursery/open-cabinet-file.yml | 4 +++- nursery/packaged-as-a-createinstall-installer.yml | 4 +++- nursery/packaged-as-a-nsis-installer.yml | 4 +++- nursery/packaged-as-a-pintool.yml | 4 +++- nursery/packaged-as-a-winzip-self-extracting-archive.yml | 4 +++- nursery/packaged-as-a-wise-installer.yml | 4 +++- nursery/packaged-as-an-installshield-installer.yml | 4 +++- nursery/packed-with-ccg.yml | 4 +++- nursery/packed-with-crunch.yml | 4 +++- nursery/packed-with-dragon-armor.yml | 4 +++- nursery/packed-with-enigma.yml | 4 +++- nursery/packed-with-epack.yml | 4 +++- nursery/packed-with-maskpe.yml | 4 +++- nursery/packed-with-mew.yml | 4 +++- nursery/packed-with-mpress.yml | 4 +++- nursery/packed-with-neolite.yml | 4 +++- nursery/packed-with-pepack.yml | 4 +++- nursery/packed-with-perplex.yml | 4 +++- nursery/packed-with-procrypt.yml | 4 +++- nursery/packed-with-rpcrypt.yml | 4 +++- nursery/packed-with-seausfx.yml | 4 +++- nursery/packed-with-shrinker.yml | 4 +++- nursery/packed-with-simple-pack.yml | 4 +++- nursery/packed-with-starforce.yml | 4 +++- nursery/packed-with-svkp.yml | 4 +++- nursery/packed-with-tsuloader.yml | 4 +++- nursery/packed-with-vprotect.yml | 4 +++- nursery/packed-with-wwpack.yml | 4 +++- nursery/parse-url.yml | 4 +++- nursery/persist-via-gnome-autostart-on-linux.yml | 4 +++- nursery/power-down-monitor.yml | 4 +++- nursery/prompt-user-for-credentials.yml | 4 +++- nursery/query-or-enumerate-registry-key-via-stdregprov.yml | 4 +++- nursery/query-or-enumerate-registry-value-via-stdregprov.yml | 4 +++- nursery/query-remote-server-for-available-data.yml | 4 +++- nursery/read-and-send-data-from-client-to-server.yml | 4 +++- nursery/read-process-memory.yml | 4 +++- nursery/read-raw-disk-data.yml | 4 +++- nursery/rebuilt-by-imprec.yml | 4 +++- nursery/receive-and-write-data-from-server-to-client.yml | 4 +++- nursery/reference-114dns-dns-server.yml | 4 +++- nursery/reference-aes-constants.yml | 4 +++- nursery/reference-alidns-dns-server.yml | 4 +++- nursery/reference-base58-string.yml | 4 +++- nursery/reference-cloudflare-dns-server.yml | 4 +++- nursery/reference-comodo-secure-dns-server.yml | 4 +++- nursery/reference-cryptocurrency-strings.yml | 4 +++- nursery/reference-google-public-dns-server.yml | 4 +++- nursery/reference-hurricane-electric-dns-server.yml | 4 +++- nursery/reference-kornet-dns-server.yml | 4 +++- nursery/reference-l3-dns-server.yml | 4 +++- nursery/reference-opendns-dns-server.yml | 4 +++- nursery/reference-processor-manufacturer-constants.yml | 4 +++- nursery/reference-quad9-dns-server.yml | 4 +++- nursery/reference-screen-saver-executable.yml | 4 +++- nursery/reference-startup-folder.yml | 4 +++- nursery/reference-the-vmware-io-port.yml | 4 +++- nursery/reference-verisign-dns-server.yml | 4 +++- nursery/register-http-server-url.yml | 4 +++- nursery/register-raw-input-devices.yml | 4 +++- nursery/resize-volume-shadow-copy-storage.yml | 4 +++- nursery/resolve-function-by-djb2-hash.yml | 4 +++- nursery/resolve-function-by-fnv-1a-hash.yml | 4 +++- nursery/resolve-function-by-hash.yml | 4 +++- nursery/run-in-container.yml | 4 +++- nursery/save-image-in-dotnet.yml | 4 +++- nursery/schedule-task-via-itaskservice.yml | 4 +++- nursery/search-for-credit-card-data.yml | 4 +++- nursery/send-data-to-internet.yml | 4 +++- nursery/send-email-in-dotnet.yml | 4 +++- nursery/send-http-request-with-host-header.yml | 4 +++- nursery/send-keystrokes.yml | 4 +++- nursery/send-request-in-dotnet.yml | 4 +++- nursery/send-sms-on-android.yml | 4 +++- nursery/serialize-json-in-dotnet.yml | 4 +++- nursery/set-current-directory.yml | 4 +++- nursery/set-global-application-hook.yml | 4 +++- nursery/set-http-cookie.yml | 4 +++- nursery/set-http-user-agent-in-dotnet.yml | 4 +++- nursery/set-registry-value-via-stdregprov.yml | 4 +++- nursery/set-thread-name-on-linux.yml | 4 +++- nursery/set-web-proxy-in-dotnet.yml | 4 +++- nursery/terminate-process-by-name-in-dotnet.yml | 4 +++- nursery/terminate-process-by-name.yml | 4 +++- nursery/unmanaged-call-via-dynamic-pinvoke-in-dotnet.yml | 4 +++- nursery/unmanaged-call.yml | 4 +++- persistence/act-as-dhcp-server-callout-dll.yml | 4 +++- persistence/act-as-dns-server-plugin-dll.yml | 4 +++- .../authentication-process/act-as-credential-manager-dll.yml | 4 +++- .../authentication-process/act-as-password-filter-dll.yml | 4 +++- .../act-as-security-support-provider-dll.yml | 4 +++- .../act-as-subauthentication-package-dll.yml | 4 +++- persistence/create-shortcut-via-ishelllink.yml | 4 +++- persistence/exchange/act-as-exchange-transport-agent.yml | 4 +++- persistence/iis/persist-via-iis-module.yml | 4 +++- persistence/iis/persist-via-isapi-extension.yml | 4 +++- persistence/office/act-as-excel-xll-add-in.yml | 4 +++- persistence/office/act-as-office-com-add-in.yml | 4 +++- persistence/office/act-as-word-wll-add-in.yml | 4 +++- persistence/persist-via-desktop-autostart.yml | 4 +++- persistence/persist-via-shell-profile-or-rc-file.yml | 4 +++- .../disable-appinit_dlls-code-signature-enforcement.yml | 4 +++- .../appinitdlls/persist-via-appinit_dlls-registry-key.yml | 4 +++- .../registry/ginadll/persist-via-ginadll-registry-key.yml | 4 +++- .../registry/persist-via-active-setup-registry-key.yml | 4 +++- persistence/registry/run/persist-via-run-registry-key.yml | 4 +++- .../persist-via-winlogon-helper-dll-registry-key.yml | 4 +++- persistence/scheduled-tasks/schedule-task-via-at.yml | 4 +++- .../scheduled-tasks/schedule-task-via-itaskscheduler.yml | 4 +++- persistence/scheduled-tasks/schedule-task-via-schtasks.yml | 4 +++- persistence/service/persist-via-rc-script.yml | 4 +++- persistence/service/persist-via-windows-service.yml | 4 +++- persistence/startup-folder/get-startup-folder.yml | 4 +++- persistence/startup-folder/write-file-to-startup-folder.yml | 4 +++- runtime/dotnet/compiled-to-the-dotnet-platform.yml | 4 +++- runtime/dotnet/execute-via-dotnet-startup-hook.yml | 4 +++- .../diebold-nixdorf/load-diebold-nixdorf-atm-library.yml | 4 +++- .../diebold-nixdorf/reference-diebold-atm-routines.yml | 4 +++- .../identify-atm-dispenser-service-provider.yml | 4 +++- .../automated-teller-machine/ncr/load-ncr-atm-library.yml | 4 +++- .../ncr/reference-ncr-atm-library-routines.yml | 4 +++- targeting/language/identify-system-language-via-api.yml | 4 +++- 847 files changed, 2541 insertions(+), 847 deletions(-) diff --git a/anti-analysis/anti-av/block-operations-on-executable-memory-pages-using-arbitrary-code-guard.yml b/anti-analysis/anti-av/block-operations-on-executable-memory-pages-using-arbitrary-code-guard.yml index 0ff303f8..509313e8 100644 --- a/anti-analysis/anti-av/block-operations-on-executable-memory-pages-using-arbitrary-code-guard.yml +++ b/anti-analysis/anti-av/block-operations-on-executable-memory-pages-using-arbitrary-code-guard.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-av authors: - jakub.jozwiak@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Impair Defenses::Disable or Modify Tools [T1562.001] mbc: diff --git a/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml b/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml index 9c7ffc69..f88c5428 100644 --- a/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml +++ b/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-av authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Anti-Behavioral Analysis::Virtual Machine Detection [B0009] - Anti-Behavioral Analysis::Sandbox Detection [B0007] diff --git a/anti-analysis/anti-av/patch-event-tracing-for-windows-function.yml b/anti-analysis/anti-av/patch-event-tracing-for-windows-function.yml index bce84559..e6b51df1 100644 --- a/anti-analysis/anti-av/patch-event-tracing-for-windows-function.yml +++ b/anti-analysis/anti-av/patch-event-tracing-for-windows-function.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-av authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Impair Defenses::Disable or Modify Tools [T1562.001] mbc: diff --git a/anti-analysis/anti-av/protect-spawned-processes-with-mitigation-policies.yml b/anti-analysis/anti-av/protect-spawned-processes-with-mitigation-policies.yml index e96604b2..1e23aaeb 100644 --- a/anti-analysis/anti-av/protect-spawned-processes-with-mitigation-policies.yml +++ b/anti-analysis/anti-av/protect-spawned-processes-with-mitigation-policies.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-av authors: - jakub.jozwiak@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Impair Defenses::Disable or Modify Tools [T1562.001] mbc: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml index 86b4d7bd..e82935b8 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Anti-Behavioral Analysis::Debugger Detection::CheckRemoteDebuggerPresent [B0001.002] - Anti-Behavioral Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031] diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml index a053a173..20f873f1 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::Hardware Breakpoints [B0001.005] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml index 8ff372a7..5232dd9d 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml index 1fd5dc6b..03726d77 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Anti-Behavioral Analysis::Debugger Detection::OutputDebugString [B0001.016] examples: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml index ce30cc8c..32fc1d12 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires offset features mbc: - Anti-Behavioral Analysis::Debugger Detection::Process Environment Block BeingDebugged [B0001.035] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml index c0fc4871..9fbffe04 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml index 18bc29b2..f8ff190e 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Anti-Behavioral Analysis::Debugger Detection::SetHandleInformation [B0001.024] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml index 9e14035a..36698f66 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints [B0001.025] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml index ea7651c5..6d8f7ffb 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount [B0001.032] examples: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml index fe952047..f1656e39 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check QueryPerformanceCounter [B0001.033] examples: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml index c504d5bb..ba561e73 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml b/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml index e2bb60d8..66dafe3b 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Anti-Behavioral Analysis::Debugger Detection::Memory Write Watching [B0001.010] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml b/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml index 7f143959..3dd92a34 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml b/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml index fc1cbc38..0e49e479 100644 --- a/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml +++ b/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Anti-Behavioral Analysis::Debugger Detection::NtQueryInformationProcess [B0001.012] references: diff --git a/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml b/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml index 857fedb5..573617dd 100644 --- a/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml +++ b/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::Anti-debugging Instructions [B0001.034] examples: diff --git a/anti-analysis/anti-debugging/debugger-evasion/hide-thread-from-debugger.yml b/anti-analysis/anti-debugging/debugger-evasion/hide-thread-from-debugger.yml index 7f50b0e2..cebab288 100644 --- a/anti-analysis/anti-debugging/debugger-evasion/hide-thread-from-debugger.yml +++ b/anti-analysis/anti-debugging/debugger-evasion/hide-thread-from-debugger.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Defense Evasion::Debugger Evasion [T1622] mbc: diff --git a/anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml b/anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml index 6cdac8fa..822f1b66 100644 --- a/anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml +++ b/anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for instructions related to executing 64-bit code from a 32-bit process (Heaven's Gate) - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Defense Evasion::Disable or Evade Security Tools::Heavens Gate [F0004.008] references: diff --git a/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml b/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml index e22ec11a..cf6d8665 100644 --- a/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml +++ b/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-disasm authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Anti-Static Analysis::Disassembler Evasion [B0012] examples: diff --git a/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml b/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml index 7e3933f0..61e60213 100644 --- a/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml +++ b/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-emulation/wine authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml b/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml index 0b72f2ce..b7dc9d1e 100644 --- a/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml +++ b/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-forensic/clear-logs authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Defense Evasion::Indicator Removal::Clear Windows Event Logs [T1070.001] examples: diff --git a/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml b/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml index 41f4e9fb..44d865d5 100644 --- a/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml +++ b/anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-forensic authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Impair Defenses::Disable Windows Event Logging [T1562.002] references: diff --git a/anti-analysis/anti-forensic/impersonate-file-version-information.yml b/anti-analysis/anti-forensic/impersonate-file-version-information.yml index ccf77d08..c21faefe 100644 --- a/anti-analysis/anti-forensic/impersonate-file-version-information.yml +++ b/anti-analysis/anti-forensic/impersonate-file-version-information.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for Windows API calls associated with reading and then writing file version information of executables on disk. Malware can use these calls to overwrite its own version information with that of a legitimate executable on the system (for instance, explorer.exe) to make it appear to be a legitimate application. - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Indicator Removal [T1070] references: diff --git a/anti-analysis/anti-forensic/patch-process-command-line.yml b/anti-analysis/anti-forensic/patch-process-command-line.yml index 12a9f51d..4a1d0f02 100644 --- a/anti-analysis/anti-forensic/patch-process-command-line.yml +++ b/anti-analysis/anti-forensic/patch-process-command-line.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, offset features att&ck: - Defense Evasion::Process Injection [T1055] mbc: diff --git a/anti-analysis/anti-forensic/self-deletion/self-delete.yml b/anti-analysis/anti-forensic/self-deletion/self-delete.yml index 0b0b75f1..c467d957 100644 --- a/anti-analysis/anti-forensic/self-deletion/self-delete.yml +++ b/anti-analysis/anti-forensic/self-deletion/self-delete.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Indicator Removal::File Deletion [T1070.004] mbc: diff --git a/anti-analysis/anti-forensic/spoof-parent-pid.yml b/anti-analysis/anti-forensic/spoof-parent-pid.yml index 81e4cac3..6b1344d7 100644 --- a/anti-analysis/anti-forensic/spoof-parent-pid.yml +++ b/anti-analysis/anti-forensic/spoof-parent-pid.yml @@ -5,7 +5,9 @@ rule: namespace: anti-analysis/anti-forensic authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Access Token Manipulation::Parent PID Spoofing [T1134.004] references: diff --git a/anti-analysis/anti-forensic/timestomp/timestomp-file.yml b/anti-analysis/anti-forensic/timestomp/timestomp-file.yml index f5dfdf48..2041fc93 100644 --- a/anti-analysis/anti-forensic/timestomp/timestomp-file.yml +++ b/anti-analysis/anti-forensic/timestomp/timestomp-file.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-forensic/timestomp authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Indicator Removal::Timestomp [T1070.006] examples: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-foreground-window-switch.yml b/anti-analysis/anti-vm/vm-detection/check-for-foreground-window-switch.yml index 412bc98e..1058f48f 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-foreground-window-switch.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-foreground-window-switch.yml @@ -5,7 +5,9 @@ rule: authors: - ervin.ocampo@mandiant.com description: Detect usage of GetForegroundWindow and Sleep APIs to check if there is any foreground window switch. Typically, sandboxes do not switch the foreground window like a user would in a normal environment. - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based Checks [T1497.002] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml b/anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml index 0aaeadff..6471461d 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-sandbox-username-or-hostname.yml b/anti-analysis/anti-vm/vm-detection/check-for-sandbox-username-or-hostname.yml index 50a2d18a..8b7e3e9a 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-sandbox-username-or-hostname.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-sandbox-username-or-hostname.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - "echernofsky@google.com" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion [T1497] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml b/anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml index 1fe94837..e9f398a8 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - BitsOfBinary - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based Checks [T1497.002] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml index 7a23ab58..4a5f2492 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml index f3426eb5..ee9f88c5 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires offset features att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml index 9d1d548a..730119f0 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml index f3fcb711..b51b7e09 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml index a529a98d..a6cbfbec 100644 --- a/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml +++ b/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml b/anti-analysis/anti-vm/vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml index e19528ff..2425a19a 100644 --- a/anti-analysis/anti-vm/vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml +++ b/anti-analysis/anti-vm/vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml @@ -5,7 +5,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - anders.vejlby@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/detect-vm-via-motherboard-hardware-wmi-queries.yml b/anti-analysis/anti-vm/vm-detection/detect-vm-via-motherboard-hardware-wmi-queries.yml index 56c83068..cba1a9eb 100644 --- a/anti-analysis/anti-vm/vm-detection/detect-vm-via-motherboard-hardware-wmi-queries.yml +++ b/anti-analysis/anti-vm/vm-detection/detect-vm-via-motherboard-hardware-wmi-queries.yml @@ -5,7 +5,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - anders.vejlby@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml index 33cd55c2..b25cc26b 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml index c9ebbf58..fe62a87d 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml index 208f7fe5..2c54cddd 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml index d5dfab88..69fe0a33 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml index 71b42490..04cb942a 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - "@johnk3r" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml index 04c9e58c..3beb59be 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml index b68d3f4b..100d3357 100644 --- a/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml +++ b/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml b/anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml index 547b7354..9e803df0 100644 --- a/anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml +++ b/anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-babel-obfuscator.yml b/anti-analysis/obfuscation/obfuscated-with-babel-obfuscator.yml index e664fe3f..533aed0e 100644 --- a/anti-analysis/obfuscation/obfuscated-with-babel-obfuscator.yml +++ b/anti-analysis/obfuscation/obfuscated-with-babel-obfuscator.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml b/anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml index 2426a94c..35c4e018 100644 --- a/anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml +++ b/anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - johnk3r - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-deepsea-obfuscator.yml b/anti-analysis/obfuscation/obfuscated-with-deepsea-obfuscator.yml index d93d1240..2881966f 100644 --- a/anti-analysis/obfuscation/obfuscated-with-deepsea-obfuscator.yml +++ b/anti-analysis/obfuscation/obfuscated-with-deepsea-obfuscator.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-dotfuscator.yml b/anti-analysis/obfuscation/obfuscated-with-dotfuscator.yml index 1758eeff..0e18b2bf 100644 --- a/anti-analysis/obfuscation/obfuscated-with-dotfuscator.yml +++ b/anti-analysis/obfuscation/obfuscated-with-dotfuscator.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-smartassembly.yml b/anti-analysis/obfuscation/obfuscated-with-smartassembly.yml index a3412a29..fb9e7e91 100644 --- a/anti-analysis/obfuscation/obfuscated-with-smartassembly.yml +++ b/anti-analysis/obfuscation/obfuscated-with-smartassembly.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-spicesdotnet-obfuscator.yml b/anti-analysis/obfuscation/obfuscated-with-spicesdotnet-obfuscator.yml index 21ea9be4..ff7115b5 100644 --- a/anti-analysis/obfuscation/obfuscated-with-spicesdotnet-obfuscator.yml +++ b/anti-analysis/obfuscation/obfuscated-with-spicesdotnet-obfuscator.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-vs-obfuscation.yml b/anti-analysis/obfuscation/obfuscated-with-vs-obfuscation.yml index bd432997..5e3fa94c 100644 --- a/anti-analysis/obfuscation/obfuscated-with-vs-obfuscation.yml +++ b/anti-analysis/obfuscation/obfuscated-with-vs-obfuscation.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/obfuscated-with-yano.yml b/anti-analysis/obfuscation/obfuscated-with-yano.yml index ca1dbc27..d24ac0bf 100644 --- a/anti-analysis/obfuscation/obfuscated-with-yano.yml +++ b/anti-analysis/obfuscation/obfuscated-with-yano.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml b/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml index 9df3b452..2c038c89 100644 --- a/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml +++ b/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation/string/stackstring authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] mbc: diff --git a/anti-analysis/packer/amber/packed-with-amber.yml b/anti-analysis/packer/amber/packed-with-amber.yml index 946dc2d7..806b6946 100644 --- a/anti-analysis/packer/amber/packed-with-amber.yml +++ b/anti-analysis/packer/amber/packed-with-amber.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/amber authors: - "john.gorman@mandiant.com" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/aspack/packed-with-aspack.yml b/anti-analysis/packer/aspack/packed-with-aspack.yml index 8b2bb84a..cf7382f9 100644 --- a/anti-analysis/packer/aspack/packed-with-aspack.yml +++ b/anti-analysis/packer/aspack/packed-with-aspack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/aspack authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/confuser/packed-with-confuser.yml b/anti-analysis/packer/confuser/packed-with-confuser.yml index 1139026f..5ae05210 100644 --- a/anti-analysis/packer/confuser/packed-with-confuser.yml +++ b/anti-analysis/packer/confuser/packed-with-confuser.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/confuser authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires class features att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/generic/packed-with-generic-packer.yml b/anti-analysis/packer/generic/packed-with-generic-packer.yml index 1a9258d7..bfe3bec6 100644 --- a/anti-analysis/packer/generic/packed-with-generic-packer.yml +++ b/anti-analysis/packer/generic/packed-with-generic-packer.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/generic authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/gopacker/packed-with-gopacker.yml b/anti-analysis/packer/gopacker/packed-with-gopacker.yml index 47bc95c6..2ece8830 100644 --- a/anti-analysis/packer/gopacker/packed-with-gopacker.yml +++ b/anti-analysis/packer/gopacker/packed-with-gopacker.yml @@ -5,7 +5,9 @@ rule: authors: - jared.wilson@mandiant.com description: The sample appears to be packed with GoPacker. - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/huan/packed-with-huan.yml b/anti-analysis/packer/huan/packed-with-huan.yml index d3dbd44d..f6562205 100644 --- a/anti-analysis/packer/huan/packed-with-huan.yml +++ b/anti-analysis/packer/huan/packed-with-huan.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/huan authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml b/anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml index eabe63b7..4eabfa4a 100644 --- a/anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml +++ b/anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/kkrunchy authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/nspack/packed-with-nspack.yml b/anti-analysis/packer/nspack/packed-with-nspack.yml index c6070a7a..9eab472a 100644 --- a/anti-analysis/packer/nspack/packed-with-nspack.yml +++ b/anti-analysis/packer/nspack/packed-with-nspack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/nspack authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/pebundle/packed-with-pebundle.yml b/anti-analysis/packer/pebundle/packed-with-pebundle.yml index 9da8d71a..68eefea0 100644 --- a/anti-analysis/packer/pebundle/packed-with-pebundle.yml +++ b/anti-analysis/packer/pebundle/packed-with-pebundle.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/pebundle authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/pecompact/packed-with-pecompact.yml b/anti-analysis/packer/pecompact/packed-with-pecompact.yml index 0aff3944..a203b3d6 100644 --- a/anti-analysis/packer/pecompact/packed-with-pecompact.yml +++ b/anti-analysis/packer/pecompact/packed-with-pecompact.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/pecompact authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/pelocknt/packed-with-pelocknt.yml b/anti-analysis/packer/pelocknt/packed-with-pelocknt.yml index 9a037748..9a76a5fe 100644 --- a/anti-analysis/packer/pelocknt/packed-with-pelocknt.yml +++ b/anti-analysis/packer/pelocknt/packed-with-pelocknt.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/pelocknt authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/peshield/packed-with-peshield.yml b/anti-analysis/packer/peshield/packed-with-peshield.yml index 2a8ee5de..e76a283e 100644 --- a/anti-analysis/packer/peshield/packed-with-peshield.yml +++ b/anti-analysis/packer/peshield/packed-with-peshield.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/peshield authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/pespin/packed-with-pespin.yml b/anti-analysis/packer/pespin/packed-with-pespin.yml index 9377a151..7e3a5dc9 100644 --- a/anti-analysis/packer/pespin/packed-with-pespin.yml +++ b/anti-analysis/packer/pespin/packed-with-pespin.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/pespin authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/petite/packed-with-petite.yml b/anti-analysis/packer/petite/packed-with-petite.yml index 82df3cc2..12dd911b 100644 --- a/anti-analysis/packer/petite/packed-with-petite.yml +++ b/anti-analysis/packer/petite/packed-with-petite.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/petite authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/rlpack/packed-with-rlpack.yml b/anti-analysis/packer/rlpack/packed-with-rlpack.yml index b6cae30c..3551dcd3 100644 --- a/anti-analysis/packer/rlpack/packed-with-rlpack.yml +++ b/anti-analysis/packer/rlpack/packed-with-rlpack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/rlpack authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/themida/packed-with-themida.yml b/anti-analysis/packer/themida/packed-with-themida.yml index 758a41f5..9320e4cb 100644 --- a/anti-analysis/packer/themida/packed-with-themida.yml +++ b/anti-analysis/packer/themida/packed-with-themida.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/themida authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/upack/packed-with-upack.yml b/anti-analysis/packer/upack/packed-with-upack.yml index e31c984b..ea4420eb 100644 --- a/anti-analysis/packer/upack/packed-with-upack.yml +++ b/anti-analysis/packer/upack/packed-with-upack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/upack authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/upx/packed-with-upx.yml b/anti-analysis/packer/upx/packed-with-upx.yml index ee87c947..27396d09 100644 --- a/anti-analysis/packer/upx/packed-with-upx.yml +++ b/anti-analysis/packer/upx/packed-with-upx.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/upx authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml b/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml index 68ffb093..edf1872a 100644 --- a/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml +++ b/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/vmprotect authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/packer/y0da/packed-with-y0da-crypter.yml b/anti-analysis/packer/y0da/packed-with-y0da-crypter.yml index af95dd95..bcc70ca6 100644 --- a/anti-analysis/packer/y0da/packed-with-y0da-crypter.yml +++ b/anti-analysis/packer/y0da/packed-with-y0da-crypter.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/y0da authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/anti-analysis/reference-analysis-tools-strings.yml b/anti-analysis/reference-analysis-tools-strings.yml index b0e80c5c..22624d9b 100644 --- a/anti-analysis/reference-analysis-tools-strings.yml +++ b/anti-analysis/reference-analysis-tools-strings.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Discovery::Analysis Tool Discovery::Process detection [B0013.001] references: diff --git a/collection/acquire-credentials-from-windows-credential-manager.yml b/collection/acquire-credentials-from-windows-credential-manager.yml index 73777b3b..2d1dd88b 100644 --- a/collection/acquire-credentials-from-windows-credential-manager.yml +++ b/collection/acquire-credentials-from-windows-credential-manager.yml @@ -5,7 +5,9 @@ rule: namespace: collection authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Credential Access::Credentials from Password Stores::Windows Credential Manager [T1555.004] examples: diff --git a/collection/browser/gather-chrome-based-browser-login-information.yml b/collection/browser/gather-chrome-based-browser-login-information.yml index a2020985..7fa879ac 100644 --- a/collection/browser/gather-chrome-based-browser-login-information.yml +++ b/collection/browser/gather-chrome-based-browser-login-information.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - still@teamt5.org - scope: file + scopes: + static: file + dynamic: file att&ck: - Credential Access::Credentials from Password Stores::Credentials from Web Browsers [T1555.003] examples: diff --git a/collection/browser/gather-firefox-profile-information.yml b/collection/browser/gather-firefox-profile-information.yml index 6e268da2..e60fae03 100644 --- a/collection/browser/gather-firefox-profile-information.yml +++ b/collection/browser/gather-firefox-profile-information.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - still@teamt5.org - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores::Credentials from Web Browsers [T1555.003] examples: diff --git a/collection/credit-card/parse-credit-card-information.yml b/collection/credit-card/parse-credit-card-information.yml index cd551c62..855d0686 100644 --- a/collection/credit-card/parse-credit-card-information.yml +++ b/collection/credit-card/parse-credit-card-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/credit-card authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic, Not features mbc: - Data::Check String [C0019] examples: diff --git a/collection/database/sql/reference-sql-statements.yml b/collection/database/sql/reference-sql-statements.yml index 303f7e95..fb7daa57 100644 --- a/collection/database/sql/reference-sql-statements.yml +++ b/collection/database/sql/reference-sql-statements.yml @@ -4,7 +4,9 @@ rule: namespace: collection/database/sql authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Data from Information Repositories [T1213] examples: diff --git a/collection/database/wmi/reference-wmi-statements.yml b/collection/database/wmi/reference-wmi-statements.yml index 6db0b12a..18bbcf72 100644 --- a/collection/database/wmi/reference-wmi-statements.yml +++ b/collection/database/wmi/reference-wmi-statements.yml @@ -4,7 +4,9 @@ rule: namespace: collection/database/wmi authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Data from Information Repositories [T1213] examples: diff --git a/collection/file-managers/gather-3d-ftp-information.yml b/collection/file-managers/gather-3d-ftp-information.yml index 1b263751..183e7e6c 100644 --- a/collection/file-managers/gather-3d-ftp-information.yml +++ b/collection/file-managers/gather-3d-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-alftp-information.yml b/collection/file-managers/gather-alftp-information.yml index 0464e22b..c177630d 100644 --- a/collection/file-managers/gather-alftp-information.yml +++ b/collection/file-managers/gather-alftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-bitkinex-information.yml b/collection/file-managers/gather-bitkinex-information.yml index f714b513..610692a2 100644 --- a/collection/file-managers/gather-bitkinex-information.yml +++ b/collection/file-managers/gather-bitkinex-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-blazeftp-information.yml b/collection/file-managers/gather-blazeftp-information.yml index 900a14e0..50c464f3 100644 --- a/collection/file-managers/gather-blazeftp-information.yml +++ b/collection/file-managers/gather-blazeftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-bulletproof-ftp-information.yml b/collection/file-managers/gather-bulletproof-ftp-information.yml index ddc4d2ac..eff43d32 100644 --- a/collection/file-managers/gather-bulletproof-ftp-information.yml +++ b/collection/file-managers/gather-bulletproof-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-classicftp-information.yml b/collection/file-managers/gather-classicftp-information.yml index bea23c3d..9fa41274 100644 --- a/collection/file-managers/gather-classicftp-information.yml +++ b/collection/file-managers/gather-classicftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-coreftp-information.yml b/collection/file-managers/gather-coreftp-information.yml index 11882724..052fb224 100644 --- a/collection/file-managers/gather-coreftp-information.yml +++ b/collection/file-managers/gather-coreftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-cuteftp-information.yml b/collection/file-managers/gather-cuteftp-information.yml index 6bdb13fc..78c21fd9 100644 --- a/collection/file-managers/gather-cuteftp-information.yml +++ b/collection/file-managers/gather-cuteftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-cyberduck-information.yml b/collection/file-managers/gather-cyberduck-information.yml index 9e2473e2..dd094e44 100644 --- a/collection/file-managers/gather-cyberduck-information.yml +++ b/collection/file-managers/gather-cyberduck-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-direct-ftp-information.yml b/collection/file-managers/gather-direct-ftp-information.yml index bee5d1f7..30b4d1b8 100644 --- a/collection/file-managers/gather-direct-ftp-information.yml +++ b/collection/file-managers/gather-direct-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-directory-opus-information.yml b/collection/file-managers/gather-directory-opus-information.yml index 6310f16d..93e6ca5a 100644 --- a/collection/file-managers/gather-directory-opus-information.yml +++ b/collection/file-managers/gather-directory-opus-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-expandrive-information.yml b/collection/file-managers/gather-expandrive-information.yml index cadd077f..0fec6df2 100644 --- a/collection/file-managers/gather-expandrive-information.yml +++ b/collection/file-managers/gather-expandrive-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-faststone-browser-information.yml b/collection/file-managers/gather-faststone-browser-information.yml index de98c2bf..94d48120 100644 --- a/collection/file-managers/gather-faststone-browser-information.yml +++ b/collection/file-managers/gather-faststone-browser-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-fasttrack-ftp-information.yml b/collection/file-managers/gather-fasttrack-ftp-information.yml index 3f699652..3c210f01 100644 --- a/collection/file-managers/gather-fasttrack-ftp-information.yml +++ b/collection/file-managers/gather-fasttrack-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ffftp-information.yml b/collection/file-managers/gather-ffftp-information.yml index d6082f49..7ab79002 100644 --- a/collection/file-managers/gather-ffftp-information.yml +++ b/collection/file-managers/gather-ffftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-filezilla-information.yml b/collection/file-managers/gather-filezilla-information.yml index 6409b3aa..9f9b48e2 100644 --- a/collection/file-managers/gather-filezilla-information.yml +++ b/collection/file-managers/gather-filezilla-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-flashfxp-information.yml b/collection/file-managers/gather-flashfxp-information.yml index 3f82c5a9..cfd1e836 100644 --- a/collection/file-managers/gather-flashfxp-information.yml +++ b/collection/file-managers/gather-flashfxp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-fling-ftp-information.yml b/collection/file-managers/gather-fling-ftp-information.yml index 266ea83a..e09ac5ab 100644 --- a/collection/file-managers/gather-fling-ftp-information.yml +++ b/collection/file-managers/gather-fling-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-freshftp-information.yml b/collection/file-managers/gather-freshftp-information.yml index b77c089c..74965be6 100644 --- a/collection/file-managers/gather-freshftp-information.yml +++ b/collection/file-managers/gather-freshftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] examples: diff --git a/collection/file-managers/gather-frigate3-information.yml b/collection/file-managers/gather-frigate3-information.yml index 742233bf..cd97ad7f 100644 --- a/collection/file-managers/gather-frigate3-information.yml +++ b/collection/file-managers/gather-frigate3-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftp-commander-information.yml b/collection/file-managers/gather-ftp-commander-information.yml index 7bd8bc5e..49f236ba 100644 --- a/collection/file-managers/gather-ftp-commander-information.yml +++ b/collection/file-managers/gather-ftp-commander-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftp-explorer-information.yml b/collection/file-managers/gather-ftp-explorer-information.yml index 96d06dbd..7c4733db 100644 --- a/collection/file-managers/gather-ftp-explorer-information.yml +++ b/collection/file-managers/gather-ftp-explorer-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftp-voyager-information.yml b/collection/file-managers/gather-ftp-voyager-information.yml index e8c1405d..ee724d4c 100644 --- a/collection/file-managers/gather-ftp-voyager-information.yml +++ b/collection/file-managers/gather-ftp-voyager-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftpgetter-information.yml b/collection/file-managers/gather-ftpgetter-information.yml index 3c439334..3a2412b7 100644 --- a/collection/file-managers/gather-ftpgetter-information.yml +++ b/collection/file-managers/gather-ftpgetter-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftpinfo-information.yml b/collection/file-managers/gather-ftpinfo-information.yml index 0008e9e3..e3fbfe1b 100644 --- a/collection/file-managers/gather-ftpinfo-information.yml +++ b/collection/file-managers/gather-ftpinfo-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftpnow-information.yml b/collection/file-managers/gather-ftpnow-information.yml index d2b21bcb..5e3fe704 100644 --- a/collection/file-managers/gather-ftpnow-information.yml +++ b/collection/file-managers/gather-ftpnow-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] examples: diff --git a/collection/file-managers/gather-ftprush-information.yml b/collection/file-managers/gather-ftprush-information.yml index 117a9e80..9fbb5292 100644 --- a/collection/file-managers/gather-ftprush-information.yml +++ b/collection/file-managers/gather-ftprush-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ftpshell-information.yml b/collection/file-managers/gather-ftpshell-information.yml index 136a8e5f..50ff8d90 100644 --- a/collection/file-managers/gather-ftpshell-information.yml +++ b/collection/file-managers/gather-ftpshell-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-global-downloader-information.yml b/collection/file-managers/gather-global-downloader-information.yml index 9ed4df52..bc3ee446 100644 --- a/collection/file-managers/gather-global-downloader-information.yml +++ b/collection/file-managers/gather-global-downloader-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-goftp-information.yml b/collection/file-managers/gather-goftp-information.yml index 3462abb3..c9766053 100644 --- a/collection/file-managers/gather-goftp-information.yml +++ b/collection/file-managers/gather-goftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-leapftp-information.yml b/collection/file-managers/gather-leapftp-information.yml index 92d69628..425d7667 100644 --- a/collection/file-managers/gather-leapftp-information.yml +++ b/collection/file-managers/gather-leapftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] examples: diff --git a/collection/file-managers/gather-netdrive-information.yml b/collection/file-managers/gather-netdrive-information.yml index 1b875e13..652e2a1e 100644 --- a/collection/file-managers/gather-netdrive-information.yml +++ b/collection/file-managers/gather-netdrive-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-nexusfile-information.yml b/collection/file-managers/gather-nexusfile-information.yml index 06254cc5..97107817 100644 --- a/collection/file-managers/gather-nexusfile-information.yml +++ b/collection/file-managers/gather-nexusfile-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-nova-ftp-information.yml b/collection/file-managers/gather-nova-ftp-information.yml index 09d81b66..d6ef1623 100644 --- a/collection/file-managers/gather-nova-ftp-information.yml +++ b/collection/file-managers/gather-nova-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] examples: diff --git a/collection/file-managers/gather-robo-ftp-information.yml b/collection/file-managers/gather-robo-ftp-information.yml index 74fb146e..c35cef85 100644 --- a/collection/file-managers/gather-robo-ftp-information.yml +++ b/collection/file-managers/gather-robo-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-securefx-information.yml b/collection/file-managers/gather-securefx-information.yml index 59463104..90f4a390 100644 --- a/collection/file-managers/gather-securefx-information.yml +++ b/collection/file-managers/gather-securefx-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-smart-ftp-information.yml b/collection/file-managers/gather-smart-ftp-information.yml index dff32f4a..abefbdbf 100644 --- a/collection/file-managers/gather-smart-ftp-information.yml +++ b/collection/file-managers/gather-smart-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-softx-ftp-information.yml b/collection/file-managers/gather-softx-ftp-information.yml index 22c507a9..e785cfd7 100644 --- a/collection/file-managers/gather-softx-ftp-information.yml +++ b/collection/file-managers/gather-softx-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-southriver-webdrive-information.yml b/collection/file-managers/gather-southriver-webdrive-information.yml index 5197b090..7bb733d8 100644 --- a/collection/file-managers/gather-southriver-webdrive-information.yml +++ b/collection/file-managers/gather-southriver-webdrive-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-staff-ftp-information.yml b/collection/file-managers/gather-staff-ftp-information.yml index 6ee5de75..a4ed16d6 100644 --- a/collection/file-managers/gather-staff-ftp-information.yml +++ b/collection/file-managers/gather-staff-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-total-commander-information.yml b/collection/file-managers/gather-total-commander-information.yml index e2256187..a8375545 100644 --- a/collection/file-managers/gather-total-commander-information.yml +++ b/collection/file-managers/gather-total-commander-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-turbo-ftp-information.yml b/collection/file-managers/gather-turbo-ftp-information.yml index 1c9b8473..5ee2ebe9 100644 --- a/collection/file-managers/gather-turbo-ftp-information.yml +++ b/collection/file-managers/gather-turbo-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ultrafxp-information.yml b/collection/file-managers/gather-ultrafxp-information.yml index dc0e57cd..6476c708 100644 --- a/collection/file-managers/gather-ultrafxp-information.yml +++ b/collection/file-managers/gather-ultrafxp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] examples: diff --git a/collection/file-managers/gather-winscp-information.yml b/collection/file-managers/gather-winscp-information.yml index 81152c90..d6266afb 100644 --- a/collection/file-managers/gather-winscp-information.yml +++ b/collection/file-managers/gather-winscp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-winzip-information.yml b/collection/file-managers/gather-winzip-information.yml index 59f79aad..775f081d 100644 --- a/collection/file-managers/gather-winzip-information.yml +++ b/collection/file-managers/gather-winzip-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-wise-ftp-information.yml b/collection/file-managers/gather-wise-ftp-information.yml index 2d80d333..1cb33b96 100644 --- a/collection/file-managers/gather-wise-ftp-information.yml +++ b/collection/file-managers/gather-wise-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-ws-ftp-information.yml b/collection/file-managers/gather-ws-ftp-information.yml index ce2c27b3..c6f3fbfb 100644 --- a/collection/file-managers/gather-ws-ftp-information.yml +++ b/collection/file-managers/gather-ws-ftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/file-managers/gather-xftp-information.yml b/collection/file-managers/gather-xftp-information.yml index 484a2794..838fa928 100644 --- a/collection/file-managers/gather-xftp-information.yml +++ b/collection/file-managers/gather-xftp-information.yml @@ -4,7 +4,9 @@ rule: namespace: collection/file-managers authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Credential Access::Credentials from Password Stores [T1555] references: diff --git a/collection/get-geographical-location.yml b/collection/get-geographical-location.yml index 35d9e78d..761ba38f 100644 --- a/collection/get-geographical-location.yml +++ b/collection/get-geographical-location.yml @@ -6,7 +6,9 @@ rule: authors: - moritz.raabe - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Location Discovery [T1614] examples: diff --git a/collection/group-policy/discover-group-policy-via-gpresult.yml b/collection/group-policy/discover-group-policy-via-gpresult.yml index 867cfe5b..f1421276 100644 --- a/collection/group-policy/discover-group-policy-via-gpresult.yml +++ b/collection/group-policy/discover-group-policy-via-gpresult.yml @@ -4,7 +4,9 @@ rule: namespace: collection/group-policy authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Group Policy Discovery [T1615] examples: diff --git a/collection/keylog/log-keystrokes-via-application-hook.yml b/collection/keylog/log-keystrokes-via-application-hook.yml index 9f47b93a..9473791f 100644 --- a/collection/keylog/log-keystrokes-via-application-hook.yml +++ b/collection/keylog/log-keystrokes-via-application-hook.yml @@ -4,7 +4,9 @@ rule: namespace: collection/keylog authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Collection::Input Capture::Keylogging [T1056.001] mbc: diff --git a/collection/keylog/log-keystrokes-via-polling.yml b/collection/keylog/log-keystrokes-via-polling.yml index 3c1b6b95..77292864 100644 --- a/collection/keylog/log-keystrokes-via-polling.yml +++ b/collection/keylog/log-keystrokes-via-polling.yml @@ -4,7 +4,9 @@ rule: namespace: collection/keylog authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Collection::Input Capture::Keylogging [T1056.001] mbc: diff --git a/collection/keylog/log-keystrokes.yml b/collection/keylog/log-keystrokes.yml index 0853e2dd..9caf9e25 100644 --- a/collection/keylog/log-keystrokes.yml +++ b/collection/keylog/log-keystrokes.yml @@ -4,7 +4,9 @@ rule: namespace: collection/keylog authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Input Capture::Keylogging [T1056.001] examples: diff --git a/collection/microphone/capture-microphone-audio.yml b/collection/microphone/capture-microphone-audio.yml index f3cb212d..a8599690 100644 --- a/collection/microphone/capture-microphone-audio.yml +++ b/collection/microphone/capture-microphone-audio.yml @@ -4,7 +4,9 @@ rule: namespace: collection/microphone authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Audio Capture [T1123] examples: diff --git a/collection/network/capture-network-configuration-via-ipconfig.yml b/collection/network/capture-network-configuration-via-ipconfig.yml index ee6c87ac..1135d4c2 100644 --- a/collection/network/capture-network-configuration-via-ipconfig.yml +++ b/collection/network/capture-network-configuration-via-ipconfig.yml @@ -4,7 +4,9 @@ rule: namespace: collection/network authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Network Configuration Discovery [T1016] examples: diff --git a/collection/network/capture-packets-using-sharppcap.yml b/collection/network/capture-packets-using-sharppcap.yml index 85301600..4d8c60fc 100644 --- a/collection/network/capture-packets-using-sharppcap.yml +++ b/collection/network/capture-packets-using-sharppcap.yml @@ -4,7 +4,9 @@ rule: namespace: collection/network authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Network Sniffing [T1040] references: diff --git a/collection/network/capture-public-ip.yml b/collection/network/capture-public-ip.yml index 5c00ad6b..fa3fdea7 100644 --- a/collection/network/capture-public-ip.yml +++ b/collection/network/capture-public-ip.yml @@ -4,7 +4,9 @@ rule: namespace: collection/network authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Network Configuration Discovery [T1016] examples: diff --git a/collection/network/get-domain-trust-relationships.yml b/collection/network/get-domain-trust-relationships.yml index d57f9802..9af3d1df 100644 --- a/collection/network/get-domain-trust-relationships.yml +++ b/collection/network/get-domain-trust-relationships.yml @@ -4,7 +4,9 @@ rule: namespace: collection/network authors: - johnk3r - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Domain Trust Discovery [T1482] examples: diff --git a/collection/network/get-mac-address-on-windows.yml b/collection/network/get-mac-address-on-windows.yml index 3dc73645..6ded3c61 100644 --- a/collection/network/get-mac-address-on-windows.yml +++ b/collection/network/get-mac-address-on-windows.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - echernofsky@google.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] references: diff --git a/collection/password-manager/steal-keepass-passwords-using-keefarce.yml b/collection/password-manager/steal-keepass-passwords-using-keefarce.yml index e3f0bb49..bbc2420a 100644 --- a/collection/password-manager/steal-keepass-passwords-using-keefarce.yml +++ b/collection/password-manager/steal-keepass-passwords-using-keefarce.yml @@ -4,7 +4,9 @@ rule: namespace: collection/password-manager authors: - "@Ana06" - scope: file + scopes: + static: file + dynamic: file att&ck: - Credential Access::Credentials from Password Stores::Password Managers [T1555.005] references: diff --git a/collection/screenshot/capture-screenshot-via-keybd-event.yml b/collection/screenshot/capture-screenshot-via-keybd-event.yml index 1f783513..604f182d 100644 --- a/collection/screenshot/capture-screenshot-via-keybd-event.yml +++ b/collection/screenshot/capture-screenshot-via-keybd-event.yml @@ -4,7 +4,9 @@ rule: namespace: collection/screenshot authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[0].number features att&ck: - Collection::Screen Capture [T1113] mbc: diff --git a/collection/screenshot/capture-screenshot.yml b/collection/screenshot/capture-screenshot.yml index fe9ef9e3..175e1a15 100644 --- a/collection/screenshot/capture-screenshot.yml +++ b/collection/screenshot/capture-screenshot.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - "@_re_fox" - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Collection::Screen Capture [T1113] mbc: diff --git a/collection/use-dotnet-library-sharpclipboard.yml b/collection/use-dotnet-library-sharpclipboard.yml index 8e881a36..e4822902 100644 --- a/collection/use-dotnet-library-sharpclipboard.yml +++ b/collection/use-dotnet-library-sharpclipboard.yml @@ -4,7 +4,9 @@ rule: namespace: collection authors: - "@johnk3r" - scope: file + scopes: + static: file + dynamic: file att&ck: - Collection::Clipboard Data [T1115] mbc: diff --git a/collection/webcam/capture-webcam-image.yml b/collection/webcam/capture-webcam-image.yml index 173baa0b..987c6dfe 100644 --- a/collection/webcam/capture-webcam-image.yml +++ b/collection/webcam/capture-webcam-image.yml @@ -4,7 +4,9 @@ rule: namespace: collection/webcam authors: - johnk3r - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Collection::Video Capture [T1125] examples: diff --git a/communication/c2/file-transfer/download-and-write-a-file.yml b/communication/c2/file-transfer/download-and-write-a-file.yml index f78cc532..42f305d8 100644 --- a/communication/c2/file-transfer/download-and-write-a-file.yml +++ b/communication/c2/file-transfer/download-and-write-a-file.yml @@ -5,7 +5,9 @@ rule: maec/malware-category: downloader authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Command and Control::Ingress Tool Transfer [T1105] mbc: diff --git a/communication/c2/file-transfer/write-and-execute-a-file.yml b/communication/c2/file-transfer/write-and-execute-a-file.yml index aed75a19..dd974053 100644 --- a/communication/c2/file-transfer/write-and-execute-a-file.yml +++ b/communication/c2/file-transfer/write-and-execute-a-file.yml @@ -5,7 +5,9 @@ rule: maec/malware-category: launcher authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Execution::Install Additional Program [B0023] examples: diff --git a/communication/c2/shell/create-reverse-shell-on-linux.yml b/communication/c2/shell/create-reverse-shell-on-linux.yml index 0ed07655..3197bcf7 100644 --- a/communication/c2/shell/create-reverse-shell-on-linux.yml +++ b/communication/c2/shell/create-reverse-shell-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: communication/c2/shell authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Command and Scripting Interpreter::Unix Shell [T1059.004] mbc: diff --git a/communication/c2/shell/create-reverse-shell.yml b/communication/c2/shell/create-reverse-shell.yml index a6748b36..34c0f7aa 100644 --- a/communication/c2/shell/create-reverse-shell.yml +++ b/communication/c2/shell/create-reverse-shell.yml @@ -4,7 +4,9 @@ rule: namespace: communication/c2/shell authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Execution::Command and Scripting Interpreter::Windows Command Shell [T1059.003] mbc: diff --git a/communication/c2/shell/execute-shell-command-and-capture-output.yml b/communication/c2/shell/execute-shell-command-and-capture-output.yml index 1653efca..a5c49df2 100644 --- a/communication/c2/shell/execute-shell-command-and-capture-output.yml +++ b/communication/c2/shell/execute-shell-command-and-capture-output.yml @@ -4,7 +4,9 @@ rule: namespace: communication/c2/shell authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Command and Scripting Interpreter::Windows Command Shell [T1059.003] references: diff --git a/communication/c2/shell/execute-shell-command-received-from-socket-on-linux.yml b/communication/c2/shell/execute-shell-command-received-from-socket-on-linux.yml index f8b7688e..b3869dca 100644 --- a/communication/c2/shell/execute-shell-command-received-from-socket-on-linux.yml +++ b/communication/c2/shell/execute-shell-command-received-from-socket-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: communication/c2/shell authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Command and Scripting Interpreter::Unix Shell [T1059.004] examples: diff --git a/communication/dns/reference-dns-over-https-endpoints.yml b/communication/dns/reference-dns-over-https-endpoints.yml index 1a82e4f4..c2554414 100644 --- a/communication/dns/reference-dns-over-https-endpoints.yml +++ b/communication/dns/reference-dns-over-https-endpoints.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - markus.neis@swisscom.com / @markus_neis - scope: file + scopes: + static: file + dynamic: file mbc: - Communication::DNS Communication::Server Connect [C0011.002] references: diff --git a/communication/dns/resolve-dns.yml b/communication/dns/resolve-dns.yml index ff86f9d1..84ae20a3 100644 --- a/communication/dns/resolve-dns.yml +++ b/communication/dns/resolve-dns.yml @@ -7,7 +7,9 @@ rule: - johnk3r - joakim@intezer.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::DNS Communication::Resolve [C0011.001] examples: diff --git a/communication/ftp/send/send-file-using-ftp.yml b/communication/ftp/send/send-file-using-ftp.yml index a0903f86..43a92868 100644 --- a/communication/ftp/send/send-file-using-ftp.yml +++ b/communication/ftp/send/send-file-using-ftp.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::FTP Communication::Send File [C0004.001] - Communication::FTP Communication::WinINet [C0004.002] diff --git a/communication/http/client/check-http-status-code.yml b/communication/http/client/check-http-status-code.yml index c1d74ab2..e5d031a0 100644 --- a/communication/http/client/check-http-status-code.yml +++ b/communication/http/client/check-http-status-code.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Communication::HTTP Communication::Read Header [C0002.014] examples: diff --git a/communication/http/client/connect-to-http-server.yml b/communication/http/client/connect-to-http-server.yml index a679d89e..8f958bfb 100644 --- a/communication/http/client/connect-to-http-server.yml +++ b/communication/http/client/connect-to-http-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Connect to Server [C0002.009] examples: diff --git a/communication/http/client/connect-to-url.yml b/communication/http/client/connect-to-url.yml index 076d063b..918fbadb 100644 --- a/communication/http/client/connect-to-url.yml +++ b/communication/http/client/connect-to-url.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Open URL [C0002.004] examples: diff --git a/communication/http/client/create-bits-job.yml b/communication/http/client/create-bits-job.yml index a63f85de..85ad6704 100644 --- a/communication/http/client/create-bits-job.yml +++ b/communication/http/client/create-bits-job.yml @@ -6,7 +6,9 @@ rule: authors: - "@mr-tz" description: BITS jobs can be used to download data or achieve persistence (via SetNotifyCmdLine) - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features att&ck: - Defense Evasion::BITS Jobs [T1197] - Persistence::BITS Jobs [T1197] diff --git a/communication/http/client/create-http-request.yml b/communication/http/client/create-http-request.yml index 3ce2e563..f86d6699 100644 --- a/communication/http/client/create-http-request.yml +++ b/communication/http/client/create-http-request.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Create Request [C0002.012] examples: diff --git a/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml b/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml index 4d50aba6..52a7b68a 100644 --- a/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml +++ b/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Get Response [C0002.017] examples: diff --git a/communication/http/client/download-url.yml b/communication/http/client/download-url.yml index 27e3147d..bacf293d 100644 --- a/communication/http/client/download-url.yml +++ b/communication/http/client/download-url.yml @@ -6,7 +6,9 @@ rule: - matthew.williams@mandiant.com - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::HTTP Communication::Download URL [C0002.006] examples: diff --git a/communication/http/client/extract-http-body.yml b/communication/http/client/extract-http-body.yml index 25b03b4a..7ae94c20 100644 --- a/communication/http/client/extract-http-body.yml +++ b/communication/http/client/extract-http-body.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features mbc: - Communication::HTTP Communication::Extract Body [C0002.011] references: diff --git a/communication/http/client/get-http-document-via-iwebbrowser2.yml b/communication/http/client/get-http-document-via-iwebbrowser2.yml index 14a26ac7..0414fecf 100644 --- a/communication/http/client/get-http-document-via-iwebbrowser2.yml +++ b/communication/http/client/get-http-document-via-iwebbrowser2.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, offset features mbc: - Communication::HTTP Communication::Get Response [C0002.017] - Communication::HTTP Communication::IWebBrowser [C0002.010] diff --git a/communication/http/client/get-http-response-content-encoding.yml b/communication/http/client/get-http-response-content-encoding.yml index 0dd996d5..af83f7e0 100644 --- a/communication/http/client/get-http-response-content-encoding.yml +++ b/communication/http/client/get-http-response-content-encoding.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Communication::HTTP Communication::Get Response [C0002.017] examples: diff --git a/communication/http/client/prepare-http-request.yml b/communication/http/client/prepare-http-request.yml index 904ab80e..0215ad4e 100644 --- a/communication/http/client/prepare-http-request.yml +++ b/communication/http/client/prepare-http-request.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::HTTP Communication::Create Request [C0002.012] examples: diff --git a/communication/http/client/read-data-from-internet.yml b/communication/http/client/read-data-from-internet.yml index da502caf..4c48f76b 100644 --- a/communication/http/client/read-data-from-internet.yml +++ b/communication/http/client/read-data-from-internet.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Get Response [C0002.017] examples: diff --git a/communication/http/client/receive-http-response.yml b/communication/http/client/receive-http-response.yml index fb8d080b..ccabd60d 100644 --- a/communication/http/client/receive-http-response.yml +++ b/communication/http/client/receive-http-response.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Get Response [C0002.017] examples: diff --git a/communication/http/client/send-file-via-http.yml b/communication/http/client/send-file-via-http.yml index c6038f8a..30b277cd 100644 --- a/communication/http/client/send-file-via-http.yml +++ b/communication/http/client/send-file-via-http.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Communication::HTTP Communication::Send Data [C0002.005] examples: diff --git a/communication/http/client/send-http-request.yml b/communication/http/client/send-http-request.yml index 164bcfe2..1e3c06c8 100644 --- a/communication/http/client/send-http-request.yml +++ b/communication/http/client/send-http-request.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Communication::HTTP Communication::Send Request [C0002.003] examples: diff --git a/communication/http/get-http-content-length.yml b/communication/http/get-http-content-length.yml index 66612176..2f55ea33 100644 --- a/communication/http/get-http-content-length.yml +++ b/communication/http/get-http-content-length.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Communication::HTTP Communication [C0002] examples: diff --git a/communication/http/initialize-iwebbrowser2.yml b/communication/http/initialize-iwebbrowser2.yml index 03c5ecfe..4d7be0e1 100644 --- a/communication/http/initialize-iwebbrowser2.yml +++ b/communication/http/initialize-iwebbrowser2.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes features mbc: - Communication::HTTP Communication::IWebBrowser [C0002.010] references: diff --git a/communication/http/initialize-winhttp-library.yml b/communication/http/initialize-winhttp-library.yml index a58b6d9f..067f1842 100644 --- a/communication/http/initialize-winhttp-library.yml +++ b/communication/http/initialize-winhttp-library.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::HTTP Communication::WinHTTP [C0002.008] examples: diff --git a/communication/http/read-http-header.yml b/communication/http/read-http-header.yml index f9ecd0b9..680574f7 100644 --- a/communication/http/read-http-header.yml +++ b/communication/http/read-http-header.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::HTTP Communication::Read Header [C0002.014] examples: diff --git a/communication/http/reference-http-user-agent-string.yml b/communication/http/reference-http-user-agent-string.yml index 672dd614..4607be79 100644 --- a/communication/http/reference-http-user-agent-string.yml +++ b/communication/http/reference-http-user-agent-string.yml @@ -5,7 +5,9 @@ rule: namespace: communication/http authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication [C0002] references: diff --git a/communication/http/server/receive-http-request.yml b/communication/http/server/receive-http-request.yml index 40495772..15fe2811 100644 --- a/communication/http/server/receive-http-request.yml +++ b/communication/http/server/receive-http-request.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/server authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Receive Request [C0002.015] examples: diff --git a/communication/http/server/send-http-response.yml b/communication/http/server/send-http-response.yml index 14495c4b..7ecc81c4 100644 --- a/communication/http/server/send-http-response.yml +++ b/communication/http/server/send-http-response.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/server authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::HTTP Communication::Send Response [C0002.016] examples: diff --git a/communication/http/server/start-http-server.yml b/communication/http/server/start-http-server.yml index 7bfe1e0a..c6fe087c 100644 --- a/communication/http/server/start-http-server.yml +++ b/communication/http/server/start-http-server.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Start Server [C0002.018] examples: diff --git a/communication/http/set-http-header.yml b/communication/http/set-http-header.yml index 8a669336..9500b92a 100644 --- a/communication/http/set-http-header.yml +++ b/communication/http/set-http-header.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::HTTP Communication::Set Header [C0002.013] examples: diff --git a/communication/icmp/send-icmp-echo-request.yml b/communication/icmp/send-icmp-echo-request.yml index b8dbf761..31a777d7 100644 --- a/communication/icmp/send-icmp-echo-request.yml +++ b/communication/icmp/send-icmp-echo-request.yml @@ -4,7 +4,9 @@ rule: namespace: communication/icmp authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::ICMP Communication::Echo Request [C0014.002] references: diff --git a/communication/ip/convert-ip-address-from-string.yml b/communication/ip/convert-ip-address-from-string.yml index 0a00e2fe..99225e7d 100644 --- a/communication/ip/convert-ip-address-from-string.yml +++ b/communication/ip/convert-ip-address-from-string.yml @@ -5,7 +5,9 @@ rule: namespace: communication/ip authors: - "@mr-tz" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead examples: - 0796F1C1EA0A142FC1EB7109A44C86CB:0x405D20 features: diff --git a/communication/mailslot/create-mailslot.yml b/communication/mailslot/create-mailslot.yml index 9f9f6901..8cf723f3 100644 --- a/communication/mailslot/create-mailslot.yml +++ b/communication/mailslot/create-mailslot.yml @@ -4,7 +4,9 @@ rule: namespace: communication/mailslot authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::Interprocess Communication [C0003] references: diff --git a/communication/mailslot/read-from-mailslot.yml b/communication/mailslot/read-from-mailslot.yml index 2e309010..25b72f13 100644 --- a/communication/mailslot/read-from-mailslot.yml +++ b/communication/mailslot/read-from-mailslot.yml @@ -4,7 +4,9 @@ rule: namespace: communication/mailslot authors: - nick.simonian@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::Interprocess Communication [C0003] references: diff --git a/communication/named-pipe/connect/connect-pipe.yml b/communication/named-pipe/connect/connect-pipe.yml index 117b4dd3..d13574ea 100644 --- a/communication/named-pipe/connect/connect-pipe.yml +++ b/communication/named-pipe/connect/connect-pipe.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::Interprocess Communication::Connect Pipe [C0003.002] examples: diff --git a/communication/named-pipe/create/create-pipe.yml b/communication/named-pipe/create/create-pipe.yml index c0b68798..df3fdc3f 100644 --- a/communication/named-pipe/create/create-pipe.yml +++ b/communication/named-pipe/create/create-pipe.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::Interprocess Communication::Create Pipe [C0003.001] examples: diff --git a/communication/named-pipe/create/create-two-anonymous-pipes.yml b/communication/named-pipe/create/create-two-anonymous-pipes.yml index 42ec62a2..3a0ae45d 100644 --- a/communication/named-pipe/create/create-two-anonymous-pipes.yml +++ b/communication/named-pipe/create/create-two-anonymous-pipes.yml @@ -4,7 +4,9 @@ rule: namespace: communication/named-pipe/create authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::Interprocess Communication::Create Pipe [C0003.001] examples: diff --git a/communication/named-pipe/read/read-pipe.yml b/communication/named-pipe/read/read-pipe.yml index 21e7e0cc..6347df84 100644 --- a/communication/named-pipe/read/read-pipe.yml +++ b/communication/named-pipe/read/read-pipe.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com description: PeekNamedPipe isn't required to read from a pipe; however, pipes are often utilized to capture the output of a cmd.exe process. In a multi-thread instance, a new thread is created that calls PeekNamedPipe and ReadFile to obtain the command output. - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::Interprocess Communication::Read Pipe [C0003.003] examples: diff --git a/communication/named-pipe/write/write-pipe.yml b/communication/named-pipe/write/write-pipe.yml index 60a179e6..f3d78dd2 100644 --- a/communication/named-pipe/write/write-pipe.yml +++ b/communication/named-pipe/write/write-pipe.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Communication::Interprocess Communication::Write Pipe [C0003.004] examples: diff --git a/communication/receive-data.yml b/communication/receive-data.yml index c914b56b..29d80178 100644 --- a/communication/receive-data.yml +++ b/communication/receive-data.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com description: all known techniques for receiving data from a potential C2 server - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Command and Control::C2 Communication::Receive Data [B0030.002] examples: diff --git a/communication/send-data.yml b/communication/send-data.yml index d0bcb9ec..b972686a 100644 --- a/communication/send-data.yml +++ b/communication/send-data.yml @@ -6,7 +6,9 @@ rule: - william.ballenthin@mandiant.com - joakim@intezer.com description: all known techniques for sending data to a potential C2 server - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Command and Control::C2 Communication::Send Data [B0030.001] examples: diff --git a/communication/socket/create-raw-socket.yml b/communication/socket/create-raw-socket.yml index 4e5185b9..758e1c58 100644 --- a/communication/socket/create-raw-socket.yml +++ b/communication/socket/create-raw-socket.yml @@ -5,7 +5,9 @@ rule: namespace: communication/socket authors: - blas.kojusner@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Communication::Socket Communication::Create Socket [C0001.003] references: diff --git a/communication/socket/create-vmci-socket.yml b/communication/socket/create-vmci-socket.yml index 784fe3a5..d040d94e 100644 --- a/communication/socket/create-vmci-socket.yml +++ b/communication/socket/create-vmci-socket.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket authors: - jakub.jozwiak@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Communication::Socket Communication::Create Socket [C0001.003] references: diff --git a/communication/socket/get-socket-status.yml b/communication/socket/get-socket-status.yml index 01f849fd..17a2de87 100644 --- a/communication/socket/get-socket-status.yml +++ b/communication/socket/get-socket-status.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Network Configuration Discovery [T1016] mbc: diff --git a/communication/socket/initialize-winsock-library.yml b/communication/socket/initialize-winsock-library.yml index 31e3b46c..11af376f 100644 --- a/communication/socket/initialize-winsock-library.yml +++ b/communication/socket/initialize-winsock-library.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::Socket Communication::Initialize Winsock Library [C0001.009] examples: diff --git a/communication/socket/receive/receive-data-on-socket.yml b/communication/socket/receive/receive-data-on-socket.yml index 556df036..fee90dc0 100644 --- a/communication/socket/receive/receive-data-on-socket.yml +++ b/communication/socket/receive/receive-data-on-socket.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - joakim@intezer.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::Socket Communication::Receive Data [C0001.006] examples: diff --git a/communication/socket/send/send-data-on-socket.yml b/communication/socket/send/send-data-on-socket.yml index dd876cfd..2960cc78 100644 --- a/communication/socket/send/send-data-on-socket.yml +++ b/communication/socket/send/send-data-on-socket.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - joakim@intezer.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::Socket Communication::Send Data [C0001.007] examples: diff --git a/communication/socket/set-socket-configuration.yml b/communication/socket/set-socket-configuration.yml index 624f5a7f..38fbe506 100644 --- a/communication/socket/set-socket-configuration.yml +++ b/communication/socket/set-socket-configuration.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Communication::Socket Communication::Set Socket Config [C0001.001] examples: diff --git a/communication/socket/tcp/connect-tcp-socket.yml b/communication/socket/tcp/connect-tcp-socket.yml index 17e597e6..312f975b 100644 --- a/communication/socket/tcp/connect-tcp-socket.yml +++ b/communication/socket/tcp/connect-tcp-socket.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Communication::Socket Communication::Connect Socket [C0001.004] examples: diff --git a/communication/socket/tcp/create-tcp-socket-via-raw-afd-driver.yml b/communication/socket/tcp/create-tcp-socket-via-raw-afd-driver.yml index 4c1b1c30..ee02f8cc 100644 --- a/communication/socket/tcp/create-tcp-socket-via-raw-afd-driver.yml +++ b/communication/socket/tcp/create-tcp-socket-via-raw-afd-driver.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket/tcp authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Communication::Socket Communication::Create TCP Socket [C0001.011] references: diff --git a/communication/socket/tcp/create-tcp-socket.yml b/communication/socket/tcp/create-tcp-socket.yml index 936ab0aa..3c8eb127 100644 --- a/communication/socket/tcp/create-tcp-socket.yml +++ b/communication/socket/tcp/create-tcp-socket.yml @@ -7,7 +7,9 @@ rule: - joakim@intezer.com - anushka.virgaonkar@mandiant.com - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Communication::Socket Communication::Create TCP Socket [C0001.011] examples: diff --git a/communication/socket/tcp/send/obtain-transmitpackets-callback-function-via-wsaioctl.yml b/communication/socket/tcp/send/obtain-transmitpackets-callback-function-via-wsaioctl.yml index c49460ad..d41a3040 100644 --- a/communication/socket/tcp/send/obtain-transmitpackets-callback-function-via-wsaioctl.yml +++ b/communication/socket/tcp/send/obtain-transmitpackets-callback-function-via-wsaioctl.yml @@ -5,7 +5,9 @@ rule: authors: - jonathan.lepore@mandiant.com description: The TransmitPackets function transmits in-memory data or file data over a connected socket. The TransmitPackets function uses the operating system cache manager to retrieve file data, locking memory for the minimum time required to transmit and resulting in efficient, high-performance transmission. - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes, mnemonic features mbc: - Communication::Socket Communication::Send TCP Data [C0001.014] references: diff --git a/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml b/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml index 9ee59420..a409c583 100644 --- a/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml +++ b/communication/socket/tcp/send/send-tcp-data-via-wfp-api.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket/tcp/send authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Communication::Socket Communication::Send TCP Data [C0001.014] examples: diff --git a/communication/socket/udp/send/create-udp-socket.yml b/communication/socket/udp/send/create-udp-socket.yml index f51b639b..573cf910 100644 --- a/communication/socket/udp/send/create-udp-socket.yml +++ b/communication/socket/udp/send/create-udp-socket.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - joakim@intezer.com - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Communication::Socket Communication::Create UDP Socket [C0001.010] examples: diff --git a/communication/tcp/client/act-as-tcp-client.yml b/communication/tcp/client/act-as-tcp-client.yml index 1757a3c9..4c07ba00 100644 --- a/communication/tcp/client/act-as-tcp-client.yml +++ b/communication/tcp/client/act-as-tcp-client.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Communication::Socket Communication::TCP Client [C0001.008] examples: diff --git a/communication/tcp/serve/start-tcp-server.yml b/communication/tcp/serve/start-tcp-server.yml index f1a07a75..86a2fc1d 100644 --- a/communication/tcp/serve/start-tcp-server.yml +++ b/communication/tcp/serve/start-tcp-server.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Communication::Socket Communication::Start TCP Server [C0001.005] examples: diff --git a/compiler/autohotkey/compiled-with-autohotkey.yml b/compiler/autohotkey/compiled-with-autohotkey.yml index a4f1a683..14c719b5 100644 --- a/compiler/autohotkey/compiled-with-autohotkey.yml +++ b/compiler/autohotkey/compiled-with-autohotkey.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/autohotkey authors: - awillia2@cisco.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Execution::Command and Scripting Interpreter [T1059] references: diff --git a/compiler/autoit/compiled-with-autoit.yml b/compiler/autoit/compiled-with-autoit.yml index 24b0c1a2..a9b5be67 100644 --- a/compiler/autoit/compiled-with-autoit.yml +++ b/compiler/autoit/compiled-with-autoit.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/autoit authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Execution::Command and Scripting Interpreter [T1059] references: diff --git a/compiler/cx_freeze/compiled-with-cx_freeze.yml b/compiler/cx_freeze/compiled-with-cx_freeze.yml index bb5689e1..c14e7815 100644 --- a/compiler/cx_freeze/compiled-with-cx_freeze.yml +++ b/compiler/cx_freeze/compiled-with-cx_freeze.yml @@ -5,7 +5,9 @@ rule: authors: - "@mr-tz" - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Execution::Command and Scripting Interpreter::Python [T1059.006] - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/compiler/d/compiled-with-dmd.yml b/compiler/d/compiled-with-dmd.yml index af7a01ff..88a57328 100644 --- a/compiler/d/compiled-with-dmd.yml +++ b/compiler/d/compiled-with-dmd.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/d authors: - "@_re_fox" - scope: file + scopes: + static: file + dynamic: file references: - https://github.com/dlang/dmd examples: diff --git a/compiler/delphi/compiled-with-borland-delphi.yml b/compiler/delphi/compiled-with-borland-delphi.yml index 7b0a5dec..0ecf28a0 100644 --- a/compiler/delphi/compiled-with-borland-delphi.yml +++ b/compiler/delphi/compiled-with-borland-delphi.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - "@mr-tz" - scope: file + scopes: + static: file + dynamic: file examples: - 4BDD67FF852C221112337FECD0681EAC features: diff --git a/compiler/exe4j/compiled-with-exe4j.yml b/compiler/exe4j/compiled-with-exe4j.yml index a193fd0e..d6290b7f 100644 --- a/compiler/exe4j/compiled-with-exe4j.yml +++ b/compiler/exe4j/compiled-with-exe4j.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/exe4j authors: - johnk3r - scope: file + scopes: + static: file + dynamic: file examples: - 6b25f1e754ef486bbb28a66d46bababe:0x404EDE features: diff --git a/compiler/go/compiled-with-go.yml b/compiler/go/compiled-with-go.yml index 5e35e9f7..12d70d35 100644 --- a/compiler/go/compiled-with-go.yml +++ b/compiler/go/compiled-with-go.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/go authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - 49a34cfbeed733c24392c9217ef46bb6 features: diff --git a/compiler/mingw/compiled-with-mingw-for-windows.yml b/compiler/mingw/compiled-with-mingw-for-windows.yml index 34f67762..560a1491 100644 --- a/compiler/mingw/compiled-with-mingw-for-windows.yml +++ b/compiler/mingw/compiled-with-mingw-for-windows.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/mingw authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - 5b3968b47eb16a1cb88525e3b565eab1 features: diff --git a/compiler/nim/compiled-with-nim.yml b/compiler/nim/compiled-with-nim.yml index bd82dbe6..928f6e8f 100644 --- a/compiler/nim/compiled-with-nim.yml +++ b/compiler/nim/compiled-with-nim.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/nim authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - 580c37831fe98a254eb6c61c692c70d8.exe_ features: diff --git a/compiler/nuitka/compiled-with-nuitka.yml b/compiler/nuitka/compiled-with-nuitka.yml index 5953a6bb..933a7043 100644 --- a/compiler/nuitka/compiled-with-nuitka.yml +++ b/compiler/nuitka/compiled-with-nuitka.yml @@ -5,7 +5,9 @@ rule: authors: - "@williballenthin" - "@mr-tz" - scope: file + scopes: + static: file + dynamic: file examples: - 39ce034911a6ebd482af5893f9bdbd95 features: diff --git a/compiler/perl2exe/compiled-with-perl2exe.yml b/compiler/perl2exe/compiled-with-perl2exe.yml index 3900292c..b0e667c9 100644 --- a/compiler/perl2exe/compiled-with-perl2exe.yml +++ b/compiler/perl2exe/compiled-with-perl2exe.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/perl2exe authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope examples: - 873275ce8bf88ef66e9fa0c74b5c2a1e:0x4011C9 features: diff --git a/compiler/ps2exe/compiled-with-ps2exe.yml b/compiler/ps2exe/compiled-with-ps2exe.yml index fdf8812c..695c7006 100644 --- a/compiler/ps2exe/compiled-with-ps2exe.yml +++ b/compiler/ps2exe/compiled-with-ps2exe.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://github.com/ikarstein/ps2exe - https://github.com/MScholtes/PS2EXE diff --git a/compiler/py2exe/compiled-with-py2exe.yml b/compiler/py2exe/compiled-with-py2exe.yml index 88debc2f..7d096c84 100644 --- a/compiler/py2exe/compiled-with-py2exe.yml +++ b/compiler/py2exe/compiled-with-py2exe.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/py2exe authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead examples: - ed888dc2f04f5eac83d6d14088d002de:0x40194A features: diff --git a/compiler/pyarmor/compiled-with-pyarmor.yml b/compiler/pyarmor/compiled-with-pyarmor.yml index 5f174c80..76aff3fe 100644 --- a/compiler/pyarmor/compiled-with-pyarmor.yml +++ b/compiler/pyarmor/compiled-with-pyarmor.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/pyarmor authors: - "@stvemillertime, @itreallynick" - scope: file + scopes: + static: file + dynamic: file att&ck: - Execution::Command and Scripting Interpreter::Python [T1059.006] - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] diff --git a/compiler/rust/compiled-with-rust.yml b/compiler/rust/compiled-with-rust.yml index 0d61cf45..8a6cebcd 100644 --- a/compiler/rust/compiled-with-rust.yml +++ b/compiler/rust/compiled-with-rust.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - c3341b7dfbb9d43bca8c812e07b4299f:0x45F490 features: diff --git a/compiler/v/compiled-with-v.yml b/compiler/v/compiled-with-v.yml index b7df07d4..6a6c645b 100644 --- a/compiler/v/compiled-with-v.yml +++ b/compiler/v/compiled-with-v.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/v authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://vlang.io - https://github.com/vlang/v diff --git a/compiler/vb/compiled-from-visual-basic.yml b/compiler/vb/compiled-from-visual-basic.yml index 75077783..65a557e2 100644 --- a/compiler/vb/compiled-from-visual-basic.yml +++ b/compiler/vb/compiled-from-visual-basic.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/vb authors: - "@williballenthin" - scope: file + scopes: + static: file + dynamic: unsupported # requires import features examples: - 9bca6b99e7981208af4c7925b96fb9cf features: diff --git a/compiler/zig/compiled-with-zig.yml b/compiler/zig/compiled-with-zig.yml index 3ff240ef..d36e03dc 100644 --- a/compiler/zig/compiled-with-zig.yml +++ b/compiler/zig/compiled-with-zig.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/zig authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://ziglang.org - https://github.com/ziglang/zig diff --git a/data-manipulation/checksum/adler32/compute-adler32-checksum.yml b/data-manipulation/checksum/adler32/compute-adler32-checksum.yml index 111338da..246e8d27 100644 --- a/data-manipulation/checksum/adler32/compute-adler32-checksum.yml +++ b/data-manipulation/checksum/adler32/compute-adler32-checksum.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/checksum/adler32 authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, mnemonic features mbc: - Data::Checksum::Adler [C0032.005] references: diff --git a/data-manipulation/checksum/crc32/hash-data-with-crc32.yml b/data-manipulation/checksum/crc32/hash-data-with-crc32.yml index d8a9a623..f258a193 100644 --- a/data-manipulation/checksum/crc32/hash-data-with-crc32.yml +++ b/data-manipulation/checksum/crc32/hash-data-with-crc32.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/checksum/crc32 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, bytes, mnemonic features mbc: - Data::Checksum::CRC32 [C0032.001] examples: diff --git a/data-manipulation/checksum/luhn/validate-payment-card-number-using-luhn-algorithm.yml b/data-manipulation/checksum/luhn/validate-payment-card-number-using-luhn-algorithm.yml index 494d9bf1..262e534e 100644 --- a/data-manipulation/checksum/luhn/validate-payment-card-number-using-luhn-algorithm.yml +++ b/data-manipulation/checksum/luhn/validate-payment-card-number-using-luhn-algorithm.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/checksum/luhn authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Data::Checksum::Luhn [C0032.002] examples: diff --git a/data-manipulation/compression/compress-data-using-lzo.yml b/data-manipulation/compression/compress-data-using-lzo.yml index 8f82579e..f16c7517 100644 --- a/data-manipulation/compression/compress-data-using-lzo.yml +++ b/data-manipulation/compression/compress-data-using-lzo.yml @@ -6,7 +6,9 @@ rule: - david@edeca.net - david.cannings@pwc.com description: detects the compression routine from LZO - scope: function + scopes: + static: function + dynamic: thread mbc: - Data::Compress Data [C0024] references: diff --git a/data-manipulation/compression/compress-data-via-winapi.yml b/data-manipulation/compression/compress-data-via-winapi.yml index be953f26..3fad4753 100644 --- a/data-manipulation/compression/compress-data-via-winapi.yml +++ b/data-manipulation/compression/compress-data-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/compression authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Archive Collected Data::Archive via Library [T1560.002] mbc: diff --git a/data-manipulation/compression/compress-data-via-zlib-inflate-or-deflate.yml b/data-manipulation/compression/compress-data-via-zlib-inflate-or-deflate.yml index f6d36ea1..94a9fb82 100644 --- a/data-manipulation/compression/compress-data-via-zlib-inflate-or-deflate.yml +++ b/data-manipulation/compression/compress-data-via-zlib-inflate-or-deflate.yml @@ -5,7 +5,9 @@ rule: namespace: data-manipulation/compression authors: - blas.kojusner@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, bytes, mnemonic features mbc: - Data::Compress Data [C0024] references: diff --git a/data-manipulation/compression/decompress-data-using-aplib.yml b/data-manipulation/compression/decompress-data-using-aplib.yml index 59949e6e..6f6f4b58 100644 --- a/data-manipulation/compression/decompress-data-using-aplib.yml +++ b/data-manipulation/compression/decompress-data-using-aplib.yml @@ -7,7 +7,9 @@ rule: - moritz.raabe@mandiant.com - cdong49@gatech.edu description: detects decompression function of library aPLib - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Data::Decompress Data::aPLib [C0025.003] references: diff --git a/data-manipulation/compression/decompress-data-using-lzo.yml b/data-manipulation/compression/decompress-data-using-lzo.yml index 1383cf59..7e76fa56 100644 --- a/data-manipulation/compression/decompress-data-using-lzo.yml +++ b/data-manipulation/compression/decompress-data-using-lzo.yml @@ -6,7 +6,9 @@ rule: - david@edeca.net - david.cannings@pwc.com description: detects the decompression routine from LZO - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Data::Decompress Data [C0025] references: diff --git a/data-manipulation/compression/decompress-data-using-quicklz.yml b/data-manipulation/compression/decompress-data-using-quicklz.yml index a9cb92cd..5272a17a 100644 --- a/data-manipulation/compression/decompress-data-using-quicklz.yml +++ b/data-manipulation/compression/decompress-data-using-quicklz.yml @@ -5,7 +5,9 @@ rule: authors: - david@edeca.net description: detects the inner decompression loop from QuickLZ - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Data::Decompress Data::QuickLZ [C0025.001] references: diff --git a/data-manipulation/compression/decompress-data-using-ucl.yml b/data-manipulation/compression/decompress-data-using-ucl.yml index 02461623..937e644d 100644 --- a/data-manipulation/compression/decompress-data-using-ucl.yml +++ b/data-manipulation/compression/decompress-data-using-ucl.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/compression authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Data::Decompress Data [C0025] references: diff --git a/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml b/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml index e12a2d6e..7c9efd27 100644 --- a/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml +++ b/data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/compression authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features mbc: - Data::Decompress Data::IEncodingFilterFactory [C0025.002] references: diff --git a/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml b/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml index 877f551c..d8c1b9e6 100644 --- a/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml +++ b/data-manipulation/encoding/base64/decode-data-using-base64-via-dword-translation-table.yml @@ -5,7 +5,9 @@ rule: authors: - gilbert.elliot@mandiant.com - sara.rincon@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml b/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml index d5f40143..107c5cdc 100644 --- a/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml +++ b/data-manipulation/encoding/base64/decode-data-using-base64-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/base64 authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] examples: diff --git a/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml b/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml index c987cfd6..af2237c8 100644 --- a/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml +++ b/data-manipulation/encoding/base64/encode-data-using-base64-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/base64 authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] examples: diff --git a/data-manipulation/encoding/base64/encode-data-using-base64.yml b/data-manipulation/encoding/base64/encode-data-using-base64.yml index 582fd51b..ea1d673b 100644 --- a/data-manipulation/encoding/base64/encode-data-using-base64.yml +++ b/data-manipulation/encoding/base64/encode-data-using-base64.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encoding/base64/reference-base64-string.yml b/data-manipulation/encoding/base64/reference-base64-string.yml index 7713d1df..b1eb67f2 100644 --- a/data-manipulation/encoding/base64/reference-base64-string.yml +++ b/data-manipulation/encoding/base64/reference-base64-string.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/base64 authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encoding/xor/encode-data-using-xor.yml b/data-manipulation/encoding/xor/encode-data-using-xor.yml index b96be141..52633549 100644 --- a/data-manipulation/encoding/xor/encode-data-using-xor.yml +++ b/data-manipulation/encoding/xor/encode-data-using-xor.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/xor authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, Not features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml b/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml index f2c0164f..5ff4b385 100644 --- a/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml +++ b/data-manipulation/encryption/aes/decrypt-data-using-aes-via-x86-extensions.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] mbc: diff --git a/data-manipulation/encryption/aes/encrypt-data-using-aes-mixcolumns-step.yml b/data-manipulation/encryption/aes/encrypt-data-using-aes-mixcolumns-step.yml index 768aa7c3..0a091763 100644 --- a/data-manipulation/encryption/aes/encrypt-data-using-aes-mixcolumns-step.yml +++ b/data-manipulation/encryption/aes/encrypt-data-using-aes-mixcolumns-step.yml @@ -5,7 +5,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, mnemonic, operand[0].offset features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-dotnet.yml b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-dotnet.yml index af016342..085fc38c 100644 --- a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-dotnet.yml +++ b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires class features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml index e62b8e60..86c78647 100644 --- a/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml +++ b/data-manipulation/encryption/aes/encrypt-data-using-aes-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/aes/manually-build-aes-constants.yml b/data-manipulation/encryption/aes/manually-build-aes-constants.yml index a0acbc18..b49ac0b6 100644 --- a/data-manipulation/encryption/aes/manually-build-aes-constants.yml +++ b/data-manipulation/encryption/aes/manually-build-aes-constants.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - huynh.t.nhan@gmail.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/aes/use-dotnet-library-encryptdecryptutils.yml b/data-manipulation/encryption/aes/use-dotnet-library-encryptdecryptutils.yml index 4076aa16..55d659f2 100644 --- a/data-manipulation/encryption/aes/use-dotnet-library-encryptdecryptutils.yml +++ b/data-manipulation/encryption/aes/use-dotnet-library-encryptdecryptutils.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - "@johnk3r" - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/blowfish/encrypt-data-using-blowfish.yml b/data-manipulation/encryption/blowfish/encrypt-data-using-blowfish.yml index 1ae18757..e54ec23c 100644 --- a/data-manipulation/encryption/blowfish/encrypt-data-using-blowfish.yml +++ b/data-manipulation/encryption/blowfish/encrypt-data-using-blowfish.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/blowfish authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml b/data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml index 8456f1b0..9146a2c7 100644 --- a/data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml +++ b/data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/camellia authors: - '@_re_fox' - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml b/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml index 665a815e..15aeabe4 100644 --- a/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml +++ b/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - chuong.dong@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/des/encrypt-data-using-des-via-winapi.yml b/data-manipulation/encryption/des/encrypt-data-using-des-via-winapi.yml index 4e5207b9..f84760fc 100644 --- a/data-manipulation/encryption/des/encrypt-data-using-des-via-winapi.yml +++ b/data-manipulation/encryption/des/encrypt-data-using-des-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/des authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/des/encrypt-data-using-des.yml b/data-manipulation/encryption/des/encrypt-data-using-des.yml index eb0ae8cb..b858eb6f 100644 --- a/data-manipulation/encryption/des/encrypt-data-using-des.yml +++ b/data-manipulation/encryption/des/encrypt-data-using-des.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, bytes, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml b/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml index aed6fbbe..637160e5 100644 --- a/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml +++ b/data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml b/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml index 6efdfa87..16a5cda9 100644 --- a/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml +++ b/data-manipulation/encryption/elliptic-curve/encrypt-data-using-curve25519.yml @@ -5,7 +5,9 @@ rule: authors: - dimiter.andonov@mandiant.com description: Targets code that enforces Curve25519's secret key restrictions. The specification states "The legitimate users are assumed to generate independent uniform random secret keys. A user can, for example, generate 32 uniform random bytes, clear bits 0, 1, 2 of the first byte, clear bit 7 of the last byte, and set bit 6 of the last byte." - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] examples: diff --git a/data-manipulation/encryption/encrypt-data-using-memfrob-from-glibc.yml b/data-manipulation/encryption/encrypt-data-using-memfrob-from-glibc.yml index 97c8afb8..b96a7f5d 100644 --- a/data-manipulation/encryption/encrypt-data-using-memfrob-from-glibc.yml +++ b/data-manipulation/encryption/encrypt-data-using-memfrob-from-glibc.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - zander.work@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml b/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml index 744a16ab..d73c6d35 100644 --- a/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml +++ b/data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml b/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml index 1eb5145b..e882c0bb 100644 --- a/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml +++ b/data-manipulation/encryption/get-outbound-credentials-handle-via-credssp.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] references: diff --git a/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128-via-wolfssl.yml b/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128-via-wolfssl.yml index d079f522..31a17bf3 100755 --- a/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128-via-wolfssl.yml +++ b/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128-via-wolfssl.yml @@ -5,7 +5,9 @@ rule: namespace: data-manipulation/encryption/hc-128 authors: - blaine.stancill@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128.yml b/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128.yml index 7db6103e..a401c9c0 100644 --- a/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128.yml +++ b/data-manipulation/encryption/hc-128/encrypt-data-using-hc-128.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for instruction mnemonics associated with initialization of the HC-128 stream cipher - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/import-public-key.yml b/data-manipulation/encryption/import-public-key.yml index 6bf44a53..53764f55 100644 --- a/data-manipulation/encryption/import-public-key.yml +++ b/data-manipulation/encryption/import-public-key.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Cryptography::Encryption Key::Import Public Key [C0028.001] examples: diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml index 516444e2..d0a9fa26 100644 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rc4 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic, Not features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml index 93c17aa4..9066f37e 100644 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rc4 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic, basicblock features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml index c1354f46..582a627e 100644 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rc4 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-with-custom-key-via-winapi.yml b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-with-custom-key-via-winapi.yml index 7dfc2422..18c46655 100755 --- a/data-manipulation/encryption/rc4/encrypt-data-using-rc4-with-custom-key-via-winapi.yml +++ b/data-manipulation/encryption/rc4/encrypt-data-using-rc4-with-custom-key-via-winapi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rc4 authors: - blaine.stancill@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml b/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml index d571b803..8fd7578b 100644 --- a/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml +++ b/data-manipulation/encryption/rc6/encrypt-data-using-rc6.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rc6 authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/rsa/reference-public-rsa-key.yml b/data-manipulation/encryption/rsa/reference-public-rsa-key.yml index 05cdcba1..f4d96a98 100644 --- a/data-manipulation/encryption/rsa/reference-public-rsa-key.yml +++ b/data-manipulation/encryption/rsa/reference-public-rsa-key.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rsa authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Cryptography::Encryption Key [C0028] references: diff --git a/data-manipulation/encryption/skipjack/encrypt-data-using-skipjack.yml b/data-manipulation/encryption/skipjack/encrypt-data-using-skipjack.yml index eb1763e7..ecd0b271 100644 --- a/data-manipulation/encryption/skipjack/encrypt-data-using-skipjack.yml +++ b/data-manipulation/encryption/skipjack/encrypt-data-using-skipjack.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/skipjack authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/sosemanuk/encrypt-data-using-sosemanuk.yml b/data-manipulation/encryption/sosemanuk/encrypt-data-using-sosemanuk.yml index dbda8d11..a13a2086 100644 --- a/data-manipulation/encryption/sosemanuk/encrypt-data-using-sosemanuk.yml +++ b/data-manipulation/encryption/sosemanuk/encrypt-data-using-sosemanuk.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for cryptographic constants associated with the Sosemanuk stream cipher - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/tea/decrypt-data-using-tea.yml b/data-manipulation/encryption/tea/decrypt-data-using-tea.yml index 887ba2c9..97d826fa 100755 --- a/data-manipulation/encryption/tea/decrypt-data-using-tea.yml +++ b/data-manipulation/encryption/tea/decrypt-data-using-tea.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - raymond.leong@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, mnemonic, Not features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/tea/encrypt-data-using-tea.yml b/data-manipulation/encryption/tea/encrypt-data-using-tea.yml index ffe8c60f..7262cb1d 100755 --- a/data-manipulation/encryption/tea/encrypt-data-using-tea.yml +++ b/data-manipulation/encryption/tea/encrypt-data-using-tea.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - raymond.leong@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, mnemonic, Not features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/twofish/encrypt-data-using-twofish.yml b/data-manipulation/encryption/twofish/encrypt-data-using-twofish.yml index 4ee2c821..e370ac2e 100644 --- a/data-manipulation/encryption/twofish/encrypt-data-using-twofish.yml +++ b/data-manipulation/encryption/twofish/encrypt-data-using-twofish.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/twofish authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/vest/encrypt-data-using-vest.yml b/data-manipulation/encryption/vest/encrypt-data-using-vest.yml index ceda4cfb..7c159070 100644 --- a/data-manipulation/encryption/vest/encrypt-data-using-vest.yml +++ b/data-manipulation/encryption/vest/encrypt-data-using-vest.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/vest authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/xtea/encrypt-data-using-xtea.yml b/data-manipulation/encryption/xtea/encrypt-data-using-xtea.yml index 4f51a9f0..27d99fb8 100755 --- a/data-manipulation/encryption/xtea/encrypt-data-using-xtea.yml +++ b/data-manipulation/encryption/xtea/encrypt-data-using-xtea.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/xtea authors: - raymond.leong@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/encryption/xxtea/encrypt-data-using-xxtea.yml b/data-manipulation/encryption/xxtea/encrypt-data-using-xxtea.yml index bd99f80a..565256c6 100755 --- a/data-manipulation/encryption/xxtea/encrypt-data-using-xxtea.yml +++ b/data-manipulation/encryption/xxtea/encrypt-data-using-xxtea.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/xxtea authors: - raymond.leong@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[1].number, characteristic, mnemonic, Not features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/data-manipulation/hashing/djb2/hash-data-using-djb2.yml b/data-manipulation/hashing/djb2/hash-data-using-djb2.yml index acdfe958..43a17879 100644 --- a/data-manipulation/hashing/djb2/hash-data-using-djb2.yml +++ b/data-manipulation/hashing/djb2/hash-data-using-djb2.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com - still@teamt5.org - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Data::Non-Cryptographic Hash::djb2 [C0030.006] references: diff --git a/data-manipulation/hashing/fnv/hash-data-using-fnv.yml b/data-manipulation/hashing/fnv/hash-data-using-fnv.yml index 825be537..40ddfa61 100644 --- a/data-manipulation/hashing/fnv/hash-data-using-fnv.yml +++ b/data-manipulation/hashing/fnv/hash-data-using-fnv.yml @@ -7,7 +7,9 @@ rule: - "@_re_fox" - michael.hunhoff@mandiant.com description: can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1, FNV-1a, FNV-0 - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Data::Non-Cryptographic Hash::FNV [C0030.005] references: diff --git a/data-manipulation/hashing/hash-data-via-wincrypt.yml b/data-manipulation/hashing/hash-data-via-wincrypt.yml index ae8572c5..6402d0af 100644 --- a/data-manipulation/hashing/hash-data-via-wincrypt.yml +++ b/data-manipulation/hashing/hash-data-via-wincrypt.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Cryptography::Cryptographic Hash [C0029] examples: diff --git a/data-manipulation/hashing/md5/hash-data-with-md5.yml b/data-manipulation/hashing/md5/hash-data-with-md5.yml index 9bf05b93..e270bc0d 100644 --- a/data-manipulation/hashing/md5/hash-data-with-md5.yml +++ b/data-manipulation/hashing/md5/hash-data-with-md5.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, Not features mbc: - Cryptography::Cryptographic Hash::MD5 [C0029.001] references: diff --git a/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml b/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml index da88c86f..4b87aca3 100644 --- a/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml +++ b/data-manipulation/hashing/murmur/hash-data-using-murmur3.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/murmur authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Data::Non-Cryptographic Hash::MurmurHash [C0030.001] references: diff --git a/data-manipulation/hashing/sha1/hash-data-using-sha1.yml b/data-manipulation/hashing/sha1/hash-data-using-sha1.yml index d5d0644d..76a8cbbe 100644 --- a/data-manipulation/hashing/sha1/hash-data-using-sha1.yml +++ b/data-manipulation/hashing/sha1/hash-data-using-sha1.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Cryptography::Cryptographic Hash::SHA1 [C0029.002] examples: diff --git a/data-manipulation/hashing/sha224/hash-data-using-sha224.yml b/data-manipulation/hashing/sha224/hash-data-using-sha224.yml index 205b69cb..cfaa86e2 100644 --- a/data-manipulation/hashing/sha224/hash-data-using-sha224.yml +++ b/data-manipulation/hashing/sha224/hash-data-using-sha224.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha224 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Cryptography::Cryptographic Hash::SHA224 [C0029.004] references: diff --git a/data-manipulation/hashing/sha256/hash-data-using-sha256.yml b/data-manipulation/hashing/sha256/hash-data-using-sha256.yml index 9f3400f9..4da48ab3 100644 --- a/data-manipulation/hashing/sha256/hash-data-using-sha256.yml +++ b/data-manipulation/hashing/sha256/hash-data-using-sha256.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Cryptography::Cryptographic Hash::SHA256 [C0029.003] references: diff --git a/data-manipulation/hashing/sha384/hash-data-using-sha384.yml b/data-manipulation/hashing/sha384/hash-data-using-sha384.yml index 1a723cef..d4ed183c 100644 --- a/data-manipulation/hashing/sha384/hash-data-using-sha384.yml +++ b/data-manipulation/hashing/sha384/hash-data-using-sha384.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha384 authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.rfc-editor.org/rfc/rfc6234 examples: diff --git a/data-manipulation/hashing/sha512/hash-data-using-sha512.yml b/data-manipulation/hashing/sha512/hash-data-using-sha512.yml index 1b09d83f..02bbe90c 100644 --- a/data-manipulation/hashing/sha512/hash-data-using-sha512.yml +++ b/data-manipulation/hashing/sha512/hash-data-using-sha512.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha512 authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.rfc-editor.org/rfc/rfc6234 examples: diff --git a/data-manipulation/hashing/tiger/hash-data-using-tiger.yml b/data-manipulation/hashing/tiger/hash-data-using-tiger.yml index 8be819bb..10c49d23 100644 --- a/data-manipulation/hashing/tiger/hash-data-using-tiger.yml +++ b/data-manipulation/hashing/tiger/hash-data-using-tiger.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/tiger authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, bytes, mnemonic features mbc: - Cryptography::Cryptographic Hash::Tiger [C0029.005] examples: diff --git a/data-manipulation/hmac/authenticate-hmac.yml b/data-manipulation/hmac/authenticate-hmac.yml index 8956e104..c82f61a0 100644 --- a/data-manipulation/hmac/authenticate-hmac.yml +++ b/data-manipulation/hmac/authenticate-hmac.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hmac authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features mbc: - Cryptography::Hashed Message Authentication Code [C0061] references: diff --git a/data-manipulation/json/use-dotnet-library-newtonsoftjson.yml b/data-manipulation/json/use-dotnet-library-newtonsoftjson.yml index 08d8b114..4fbffcbe 100644 --- a/data-manipulation/json/use-dotnet-library-newtonsoftjson.yml +++ b/data-manipulation/json/use-dotnet-library-newtonsoftjson.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/json authors: - "@johnk3r" - scope: file + scopes: + static: file + dynamic: file references: - https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-new-old-banking-trojan-brazil/ examples: diff --git a/data-manipulation/prng/generate-random-numbers-via-rtlgenrandom.yml b/data-manipulation/prng/generate-random-numbers-via-rtlgenrandom.yml index cd6b6e57..d94275d8 100644 --- a/data-manipulation/prng/generate-random-numbers-via-rtlgenrandom.yml +++ b/data-manipulation/prng/generate-random-numbers-via-rtlgenrandom.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - richard.weiss@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003] references: diff --git a/data-manipulation/prng/generate-random-numbers-via-winapi.yml b/data-manipulation/prng/generate-random-numbers-via-winapi.yml index 13670595..1bca70b8 100644 --- a/data-manipulation/prng/generate-random-numbers-via-winapi.yml +++ b/data-manipulation/prng/generate-random-numbers-via-winapi.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - johnk3r - scope: function + scopes: + static: function + dynamic: thread mbc: - Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003] examples: diff --git a/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml b/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml index 5f8a68b6..ab35eff5 100644 --- a/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml +++ b/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/prng/mersenne authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Cryptography::Generate Pseudo-random Sequence [C0021] examples: diff --git a/data-manipulation/svg/use-dotnet-library-sharpvectors.yml b/data-manipulation/svg/use-dotnet-library-sharpvectors.yml index b6cd87e5..9353bbe5 100644 --- a/data-manipulation/svg/use-dotnet-library-sharpvectors.yml +++ b/data-manipulation/svg/use-dotnet-library-sharpvectors.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/svg authors: - "@johnk3r" - scope: file + scopes: + static: file + dynamic: file references: - https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-new-old-banking-trojan-brazil/ examples: diff --git a/executable/dotnet-singlefile/packaged-as-single-file-dotnet-application.yml b/executable/dotnet-singlefile/packaged-as-single-file-dotnet-application.yml index ce43fd24..a07018e2 100644 --- a/executable/dotnet-singlefile/packaged-as-single-file-dotnet-application.yml +++ b/executable/dotnet-singlefile/packaged-as-single-file-dotnet-application.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: Single binary containing target .NET application and all application-dependent files - scope: file + scopes: + static: file + dynamic: file references: - https://learn.microsoft.com/en-us/dotnet/core/deploying/single-file/overview?tabs=cli examples: diff --git a/executable/installer/iexpress/packaged-as-an-iexpress-self-extracting-archive.yml b/executable/installer/iexpress/packaged-as-an-iexpress-self-extracting-archive.yml index 5d47d583..80c50f41 100644 --- a/executable/installer/iexpress/packaged-as-an-iexpress-self-extracting-archive.yml +++ b/executable/installer/iexpress/packaged-as-an-iexpress-self-extracting-archive.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/iexpress authors: - awillia2@cisco.com - scope: file + scopes: + static: file + dynamic: file references: - https://en.wikipedia.org/wiki/IExpress examples: diff --git a/executable/installer/inno-setup/packaged-as-an-inno-setup-installer.yml b/executable/installer/inno-setup/packaged-as-an-inno-setup-installer.yml index dd7a3e22..547a9685 100644 --- a/executable/installer/inno-setup/packaged-as-an-inno-setup-installer.yml +++ b/executable/installer/inno-setup/packaged-as-an-inno-setup-installer.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/inno-setup authors: - awillia2@cisco.com - scope: file + scopes: + static: file + dynamic: file references: - https://jrsoftware.org/isinfo.php examples: diff --git a/executable/pe/export/forwarded-export.yml b/executable/pe/export/forwarded-export.yml index 9e7495c9..bdd929c4 100644 --- a/executable/pe/export/forwarded-export.yml +++ b/executable/pe/export/forwarded-export.yml @@ -4,7 +4,9 @@ rule: namespace: executable/pe/export authors: - ronnie.salomonsen@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Execution::Shared Modules [T1129] examples: diff --git a/executable/pe/pdb/contains-pdb-path.yml b/executable/pe/pdb/contains-pdb-path.yml index 38d7d72f..efb1b946 100644 --- a/executable/pe/pdb/contains-pdb-path.yml +++ b/executable/pe/pdb/contains-pdb-path.yml @@ -4,7 +4,9 @@ rule: namespace: executable/pe/pdb authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - 464EF2CA59782CE697BC329713698CCC # level32.exe features: diff --git a/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml b/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml index b6688552..d1d81b18 100644 --- a/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml +++ b/executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml @@ -4,7 +4,9 @@ rule: namespace: executable/pe/section/tls authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - Practical Malware Analysis Lab 16-02.exe_ features: diff --git a/executable/resource/access-dotnet-resource.yml b/executable/resource/access-dotnet-resource.yml index 93aaf14e..c8c7726f 100644 --- a/executable/resource/access-dotnet-resource.yml +++ b/executable/resource/access-dotnet-resource.yml @@ -4,7 +4,9 @@ rule: namespace: executable/resource authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread examples: - 387f15043f0198fd3a637b0758c2b6dde9ead795c3ed70803426fc355731b173:0x06000084 features: diff --git a/executable/resource/embed-dependencies-as-resources-using-fodycostura.yml b/executable/resource/embed-dependencies-as-resources-using-fodycostura.yml index 3289c035..7d0e4cca 100644 --- a/executable/resource/embed-dependencies-as-resources-using-fodycostura.yml +++ b/executable/resource/embed-dependencies-as-resources-using-fodycostura.yml @@ -5,7 +5,9 @@ rule: authors: - "@johnk3r" - "@mr-tz" - scope: file + scopes: + static: file + dynamic: file references: - https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-new-old-banking-trojan-brazil/ examples: diff --git a/executable/resource/extract-resource-via-kernel32-functions.yml b/executable/resource/extract-resource-via-kernel32-functions.yml index beddea44..92513950 100644 --- a/executable/resource/extract-resource-via-kernel32-functions.yml +++ b/executable/resource/extract-resource-via-kernel32-functions.yml @@ -4,7 +4,9 @@ rule: namespace: executable/resource authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread examples: - BF88E1BD4A3BDE10B419A622278F1FF7:0x401000 - Practical Malware Analysis Lab 01-04.exe_:0x4011FC diff --git a/executable/subfile/pe/contain-an-embedded-pe-file.yml b/executable/subfile/pe/contain-an-embedded-pe-file.yml index 72760f0e..42a75b6e 100644 --- a/executable/subfile/pe/contain-an-embedded-pe-file.yml +++ b/executable/subfile/pe/contain-an-embedded-pe-file.yml @@ -4,7 +4,9 @@ rule: namespace: executable/subfile/pe authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Execution::Install Additional Program [B0023] examples: diff --git a/host-interaction/bootloader/disable-code-signing.yml b/host-interaction/bootloader/disable-code-signing.yml index 28d8ff52..468d98dd 100644 --- a/host-interaction/bootloader/disable-code-signing.yml +++ b/host-interaction/bootloader/disable-code-signing.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/bootloader authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Subvert Trust Controls::Code Signing Policy Modification [T1553.006] examples: diff --git a/host-interaction/bootloader/get-uefi-variable.yml b/host-interaction/bootloader/get-uefi-variable.yml index 24eed7cd..a165f80e 100644 --- a/host-interaction/bootloader/get-uefi-variable.yml +++ b/host-interaction/bootloader/get-uefi-variable.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/bootloader authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Persistence::Pre-OS Boot::System Firmware [T1542.001] references: diff --git a/host-interaction/bootloader/manipulate-boot-configuration.yml b/host-interaction/bootloader/manipulate-boot-configuration.yml index 60b1409b..b91396ed 100644 --- a/host-interaction/bootloader/manipulate-boot-configuration.yml +++ b/host-interaction/bootloader/manipulate-boot-configuration.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/bootloader authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/bcdedit-command-line-options examples: diff --git a/host-interaction/bootloader/manipulate-safe-mode-programs.yml b/host-interaction/bootloader/manipulate-safe-mode-programs.yml index 150ff9b1..145f0fb4 100644 --- a/host-interaction/bootloader/manipulate-safe-mode-programs.yml +++ b/host-interaction/bootloader/manipulate-safe-mode-programs.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/bootloader authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Impair Defenses::Safe Mode Boot [T1562.009] examples: diff --git a/host-interaction/bootloader/set-uefi-variable.yml b/host-interaction/bootloader/set-uefi-variable.yml index d4c66942..c9d7d52d 100644 --- a/host-interaction/bootloader/set-uefi-variable.yml +++ b/host-interaction/bootloader/set-uefi-variable.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/bootloader authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Persistence::Pre-OS Boot::System Firmware [T1542.001] references: diff --git a/host-interaction/cli/accept-command-line-arguments.yml b/host-interaction/cli/accept-command-line-arguments.yml index e4fcebd5..bf56e436 100644 --- a/host-interaction/cli/accept-command-line-arguments.yml +++ b/host-interaction/cli/accept-command-line-arguments.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Execution::Command and Scripting Interpreter [T1059] mbc: diff --git a/host-interaction/cli/resolve-path-using-msvcrt.yml b/host-interaction/cli/resolve-path-using-msvcrt.yml index 90e700fe..943b6ec4 100644 --- a/host-interaction/cli/resolve-path-using-msvcrt.yml +++ b/host-interaction/cli/resolve-path-using-msvcrt.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/cli authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::File and Directory Discovery [T1083] examples: diff --git a/host-interaction/clipboard/open-clipboard.yml b/host-interaction/clipboard/open-clipboard.yml index b973bf6e..5765585a 100644 --- a/host-interaction/clipboard/open-clipboard.yml +++ b/host-interaction/clipboard/open-clipboard.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/clipboard authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Clipboard Data [T1115] examples: diff --git a/host-interaction/clipboard/read-clipboard-data.yml b/host-interaction/clipboard/read-clipboard-data.yml index f920f8f6..14f30d66 100644 --- a/host-interaction/clipboard/read-clipboard-data.yml +++ b/host-interaction/clipboard/read-clipboard-data.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Collection::Clipboard Data [T1115] references: diff --git a/host-interaction/clipboard/write-clipboard-data.yml b/host-interaction/clipboard/write-clipboard-data.yml index cbc655c0..dead8a80 100644 --- a/host-interaction/clipboard/write-clipboard-data.yml +++ b/host-interaction/clipboard/write-clipboard-data.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Impact::Clipboard Modification [E1510] references: diff --git a/host-interaction/console/manipulate-console-buffer.yml b/host-interaction/console/manipulate-console-buffer.yml index d5a09408..21fa1f52 100644 --- a/host-interaction/console/manipulate-console-buffer.yml +++ b/host-interaction/console/manipulate-console-buffer.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Operating System::Console [C0033] references: diff --git a/host-interaction/driver/create-device-object.yml b/host-interaction/driver/create-device-object.yml index 5f5c82a0..894d95b4 100644 --- a/host-interaction/driver/create-device-object.yml +++ b/host-interaction/driver/create-device-object.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/driver authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread examples: - Practical Malware Analysis Lab 10-03.sys_:0x00010706 features: diff --git a/host-interaction/driver/disable-driver-code-integrity.yml b/host-interaction/driver/disable-driver-code-integrity.yml index 05948e6e..bbc6e07c 100644 --- a/host-interaction/driver/disable-driver-code-integrity.yml +++ b/host-interaction/driver/disable-driver-code-integrity.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/driver authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Impair Defenses::Disable or Modify Tools [T1562.001] mbc: diff --git a/host-interaction/driver/install-driver.yml b/host-interaction/driver/install-driver.yml index a7a7f5e0..dd719578 100644 --- a/host-interaction/driver/install-driver.yml +++ b/host-interaction/driver/install-driver.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/driver authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] mbc: diff --git a/host-interaction/driver/interact-with-driver-via-control-codes.yml b/host-interaction/driver/interact-with-driver-via-control-codes.yml index d54015a5..45dd6d37 100644 --- a/host-interaction/driver/interact-with-driver-via-control-codes.yml +++ b/host-interaction/driver/interact-with-driver-via-control-codes.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/driver authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::System Services::Service Execution [T1569.002] examples: diff --git a/host-interaction/environment-variable/get-comspec-environment-variable.yml b/host-interaction/environment-variable/get-comspec-environment-variable.yml index 360570d7..c112635d 100644 --- a/host-interaction/environment-variable/get-comspec-environment-variable.yml +++ b/host-interaction/environment-variable/get-comspec-environment-variable.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/environment-variable authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Information Discovery [T1082] mbc: diff --git a/host-interaction/environment-variable/query-environment-variable.yml b/host-interaction/environment-variable/query-environment-variable.yml index 4ef54c8c..c1981db6 100644 --- a/host-interaction/environment-variable/query-environment-variable.yml +++ b/host-interaction/environment-variable/query-environment-variable.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - "@_re_fox" - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Information Discovery [T1082] mbc: diff --git a/host-interaction/environment-variable/set-environment-variable.yml b/host-interaction/environment-variable/set-environment-variable.yml index 897aed27..1aa080df 100644 --- a/host-interaction/environment-variable/set-environment-variable.yml +++ b/host-interaction/environment-variable/set-environment-variable.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/environment-variable authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Operating System::Environment Variable::Set Variable [C0034.001] examples: diff --git a/host-interaction/file-system/bypass-mark-of-the-web.yml b/host-interaction/file-system/bypass-mark-of-the-web.yml index 0f5c40f9..11759fb7 100644 --- a/host-interaction/file-system/bypass-mark-of-the-web.yml +++ b/host-interaction/file-system/bypass-mark-of-the-web.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Subvert Trust Controls::Mark-of-the-Web Bypass [T1553.005] examples: diff --git a/host-interaction/file-system/change-file-permission-on-linux.yml b/host-interaction/file-system/change-file-permission-on-linux.yml index 872badff..1426972d 100644 --- a/host-interaction/file-system/change-file-permission-on-linux.yml +++ b/host-interaction/file-system/change-file-permission-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - joakim@intezer.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - File System::Set File Attributes [C0050] examples: diff --git a/host-interaction/file-system/copy/copy-file.yml b/host-interaction/file-system/copy/copy-file.yml index 2b3913a4..5040e739 100644 --- a/host-interaction/file-system/copy/copy-file.yml +++ b/host-interaction/file-system/copy/copy-file.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - File System::Copy File [C0045] examples: diff --git a/host-interaction/file-system/create-virtual-file-system-in-dotnet.yml b/host-interaction/file-system/create-virtual-file-system-in-dotnet.yml index 79474ebb..3f47b1b8 100644 --- a/host-interaction/file-system/create-virtual-file-system-in-dotnet.yml +++ b/host-interaction/file-system/create-virtual-file-system-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Hide Artifacts::Hidden File System [T1564.005] mbc: diff --git a/host-interaction/file-system/create/create-directory.yml b/host-interaction/file-system/create/create-directory.yml index d43de4d3..bfa2bd53 100644 --- a/host-interaction/file-system/create/create-directory.yml +++ b/host-interaction/file-system/create/create-directory.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - File System::Create Directory [C0046] examples: diff --git a/host-interaction/file-system/delete/delete-directory.yml b/host-interaction/file-system/delete/delete-directory.yml index 41edc033..e1147883 100644 --- a/host-interaction/file-system/delete/delete-directory.yml +++ b/host-interaction/file-system/delete/delete-directory.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - File System::Delete Directory [C0048] examples: diff --git a/host-interaction/file-system/delete/delete-file.yml b/host-interaction/file-system/delete/delete-file.yml index 95f4d1df..81c4494d 100644 --- a/host-interaction/file-system/delete/delete-file.yml +++ b/host-interaction/file-system/delete/delete-file.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - File System::Delete File [C0047] examples: diff --git a/host-interaction/file-system/exists/check-if-file-exists.yml b/host-interaction/file-system/exists/check-if-file-exists.yml index 9891433b..fd2d5f10 100644 --- a/host-interaction/file-system/exists/check-if-file-exists.yml +++ b/host-interaction/file-system/exists/check-if-file-exists.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/files/list/enumerate-files-on-linux.yml b/host-interaction/file-system/files/list/enumerate-files-on-linux.yml index ff6c579b..75f7a94a 100644 --- a/host-interaction/file-system/files/list/enumerate-files-on-linux.yml +++ b/host-interaction/file-system/files/list/enumerate-files-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/files/list authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/files/list/enumerate-files-on-windows.yml b/host-interaction/file-system/files/list/enumerate-files-on-windows.yml index 3b9a4179..c5c495b9 100644 --- a/host-interaction/file-system/files/list/enumerate-files-on-windows.yml +++ b/host-interaction/file-system/files/list/enumerate-files-on-windows.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/files/list/enumerate-files-recursively.yml b/host-interaction/file-system/files/list/enumerate-files-recursively.yml index f80a082c..da40c643 100644 --- a/host-interaction/file-system/files/list/enumerate-files-recursively.yml +++ b/host-interaction/file-system/files/list/enumerate-files-recursively.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/get-common-file-path.yml b/host-interaction/file-system/get-common-file-path.yml index 13ca9804..6c1a3290 100644 --- a/host-interaction/file-system/get-common-file-path.yml +++ b/host-interaction/file-system/get-common-file-path.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/get-file-system-object-information.yml b/host-interaction/file-system/get-file-system-object-information.yml index a5a9d5a5..302b337d 100644 --- a/host-interaction/file-system/get-file-system-object-information.yml +++ b/host-interaction/file-system/get-file-system-object-information.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::File and Directory Discovery [T1083] examples: diff --git a/host-interaction/file-system/get-program-files-directory.yml b/host-interaction/file-system/get-program-files-directory.yml index 88dfead3..a6d5e30c 100644 --- a/host-interaction/file-system/get-program-files-directory.yml +++ b/host-interaction/file-system/get-program-files-directory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::File and Directory Discovery [T1083] examples: diff --git a/host-interaction/file-system/get-windows-directory-from-kuser_shared_data.yml b/host-interaction/file-system/get-windows-directory-from-kuser_shared_data.yml index acd2d387..8620abef 100644 --- a/host-interaction/file-system/get-windows-directory-from-kuser_shared_data.yml +++ b/host-interaction/file-system/get-windows-directory-from-kuser_shared_data.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - david.cannings@pwc.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead references: - http://www.rohitab.com/discuss/topic/42325-the-kuser-shared-data-structure/ - https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/ntexapi_x/kuser_shared_data/index.htm diff --git a/host-interaction/file-system/meta/get-file-attributes.yml b/host-interaction/file-system/meta/get-file-attributes.yml index a1b929a1..327674df 100644 --- a/host-interaction/file-system/meta/get-file-attributes.yml +++ b/host-interaction/file-system/meta/get-file-attributes.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - File System::Get File Attributes [C0049] examples: diff --git a/host-interaction/file-system/meta/get-file-size.yml b/host-interaction/file-system/meta/get-file-size.yml index 2d212bfa..3a1630ef 100644 --- a/host-interaction/file-system/meta/get-file-size.yml +++ b/host-interaction/file-system/meta/get-file-size.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/meta/get-file-version-info.yml b/host-interaction/file-system/meta/get-file-version-info.yml index 5bd99c1c..c61ccc59 100644 --- a/host-interaction/file-system/meta/get-file-version-info.yml +++ b/host-interaction/file-system/meta/get-file-version-info.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::File and Directory Discovery [T1083] mbc: diff --git a/host-interaction/file-system/meta/set-file-attributes.yml b/host-interaction/file-system/meta/set-file-attributes.yml index 53ea96ee..228946c3 100644 --- a/host-interaction/file-system/meta/set-file-attributes.yml +++ b/host-interaction/file-system/meta/set-file-attributes.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::File and Directory Permissions Modification [T1222] mbc: diff --git a/host-interaction/file-system/move/move-file.yml b/host-interaction/file-system/move/move-file.yml index 9e8b23f4..8564ee8c 100644 --- a/host-interaction/file-system/move/move-file.yml +++ b/host-interaction/file-system/move/move-file.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - File System::Move File [C0063] examples: diff --git a/host-interaction/file-system/read/read-file-on-linux.yml b/host-interaction/file-system/read/read-file-on-linux.yml index 6b1db96b..00af92f3 100644 --- a/host-interaction/file-system/read/read-file-on-linux.yml +++ b/host-interaction/file-system/read/read-file-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/read authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread mbc: - File System::Read File [C0051] examples: diff --git a/host-interaction/file-system/read/read-file-on-windows.yml b/host-interaction/file-system/read/read-file-on-windows.yml index f971aca7..484eead0 100644 --- a/host-interaction/file-system/read/read-file-on-windows.yml +++ b/host-interaction/file-system/read/read-file-on-windows.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - File System::Read File [C0051] examples: diff --git a/host-interaction/file-system/read/read-file-via-mapping.yml b/host-interaction/file-system/read/read-file-via-mapping.yml index d7aea180..dc4ef966 100644 --- a/host-interaction/file-system/read/read-file-via-mapping.yml +++ b/host-interaction/file-system/read/read-file-via-mapping.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/read authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - File System::Read File [C0051] examples: diff --git a/host-interaction/file-system/read/read-ini-file.yml b/host-interaction/file-system/read/read-ini-file.yml index 3de512a2..cd5d8984 100644 --- a/host-interaction/file-system/read/read-ini-file.yml +++ b/host-interaction/file-system/read/read-ini-file.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - File System::Read File [C0051] examples: diff --git a/host-interaction/file-system/read/read-virtual-disk.yml b/host-interaction/file-system/read/read-virtual-disk.yml index b1e72d21..b81bdc4e 100644 --- a/host-interaction/file-system/read/read-virtual-disk.yml +++ b/host-interaction/file-system/read/read-virtual-disk.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/read authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread mbc: - File System::Read Virtual Disk [C0056] references: diff --git a/host-interaction/file-system/reference-absolute-stream-path-on-windows.yml b/host-interaction/file-system/reference-absolute-stream-path-on-windows.yml index 3b571d84..3a1f2939 100644 --- a/host-interaction/file-system/reference-absolute-stream-path-on-windows.yml +++ b/host-interaction/file-system/reference-absolute-stream-path-on-windows.yml @@ -5,7 +5,9 @@ rule: authors: - blas.kojusner@mandiant.com - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead references: - https://learn.microsoft.com/en-us/windows/win32/fileio/file-streams examples: diff --git a/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml b/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml index 67c13e02..3a346b8c 100644 --- a/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml +++ b/host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/windows-file-protection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Defense Evasion::Disable or Evade Security Tools::Bypass Windows File Protection [F0004.007] examples: diff --git a/host-interaction/file-system/write/write-file-on-linux.yml b/host-interaction/file-system/write/write-file-on-linux.yml index ea501c4a..80e551d1 100644 --- a/host-interaction/file-system/write/write-file-on-linux.yml +++ b/host-interaction/file-system/write/write-file-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/write authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread mbc: - File System::Writes File [C0052] examples: diff --git a/host-interaction/file-system/write/write-file-on-windows.yml b/host-interaction/file-system/write/write-file-on-windows.yml index d380d53f..cc9e7525 100644 --- a/host-interaction/file-system/write/write-file-on-windows.yml +++ b/host-interaction/file-system/write/write-file-on-windows.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - File System::Writes File [C0052] examples: diff --git a/host-interaction/filter/enumerate-minifilter-drivers.yml b/host-interaction/filter/enumerate-minifilter-drivers.yml index 46c3dcd3..bac74e8f 100644 --- a/host-interaction/filter/enumerate-minifilter-drivers.yml +++ b/host-interaction/filter/enumerate-minifilter-drivers.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/filter authors: - aseel.kayal@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://posts.specterops.io/mimidrv-in-depth-4d273d19e148 - https://learn.microsoft.com/en-us/windows-hardware/drivers/ifs/filter-manager-concepts diff --git a/host-interaction/filter/register-minifilter-driver.yml b/host-interaction/filter/register-minifilter-driver.yml index 71e80fc7..1da57ba4 100644 --- a/host-interaction/filter/register-minifilter-driver.yml +++ b/host-interaction/filter/register-minifilter-driver.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/filter authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Hardware::Install Driver::Minifilter [C0037.001] references: diff --git a/host-interaction/filter/start-minifilter-driver.yml b/host-interaction/filter/start-minifilter-driver.yml index b62e44c0..ab1318f8 100644 --- a/host-interaction/filter/start-minifilter-driver.yml +++ b/host-interaction/filter/start-minifilter-driver.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/filter authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Hardware::Load Driver::Minifilter [C0023.001] references: diff --git a/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml b/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml index 56976b9d..3c5fb77b 100644 --- a/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml +++ b/host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/firewall/modify authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features att&ck: - Discovery::Software Discovery::Security Software Discovery [T1518.001] - Defense Evasion::Impair Defenses::Disable or Modify System Firewall [T1562.004] diff --git a/host-interaction/gui/console/set-console-window-title.yml b/host-interaction/gui/console/set-console-window-title.yml index c89d7fe3..6111a779 100644 --- a/host-interaction/gui/console/set-console-window-title.yml +++ b/host-interaction/gui/console/set-console-window-title.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/console authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Operating System::Console [C0033] examples: diff --git a/host-interaction/gui/enumerate-gui-resources.yml b/host-interaction/gui/enumerate-gui-resources.yml index 3926f4ee..ef4a136e 100644 --- a/host-interaction/gui/enumerate-gui-resources.yml +++ b/host-interaction/gui/enumerate-gui-resources.yml @@ -5,7 +5,9 @@ rule: authors: - johnk3r - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::Application Window Discovery [T1010] examples: diff --git a/host-interaction/gui/logon/references-logon-banner.yml b/host-interaction/gui/logon/references-logon-banner.yml index 3f6114e7..bcff45f2 100644 --- a/host-interaction/gui/logon/references-logon-banner.yml +++ b/host-interaction/gui/logon/references-logon-banner.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/logon authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead examples: - c3341b7dfbb9d43bca8c812e07b4299f:0x4066FC features: diff --git a/host-interaction/gui/session/lock/lock-the-desktop.yml b/host-interaction/gui/session/lock/lock-the-desktop.yml index a9343b93..af0d1042 100644 --- a/host-interaction/gui/session/lock/lock-the-desktop.yml +++ b/host-interaction/gui/session/lock/lock-the-desktop.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/session/lock authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Impact::Endpoint Denial of Service [T1499] examples: diff --git a/host-interaction/gui/session/wallpaper/change-the-wallpaper.yml b/host-interaction/gui/session/wallpaper/change-the-wallpaper.yml index ebe0dc9a..68486ff3 100644 --- a/host-interaction/gui/session/wallpaper/change-the-wallpaper.yml +++ b/host-interaction/gui/session/wallpaper/change-the-wallpaper.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/session authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Operating System::Wallpaper [C0035] examples: diff --git a/host-interaction/gui/set-application-hook.yml b/host-interaction/gui/set-application-hook.yml index 530a8ab9..52299cbb 100644 --- a/host-interaction/gui/set-application-hook.yml +++ b/host-interaction/gui/set-application-hook.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread examples: - Practical Malware Analysis Lab 12-03.exe_:0x401000 features: diff --git a/host-interaction/gui/switch-active-desktop.yml b/host-interaction/gui/switch-active-desktop.yml index 54d3ac48..5160f6bb 100644 --- a/host-interaction/gui/switch-active-desktop.yml +++ b/host-interaction/gui/switch-active-desktop.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Debugger Evasion [T1622] mbc: diff --git a/host-interaction/gui/taskbar/find/find-taskbar.yml b/host-interaction/gui/taskbar/find/find-taskbar.yml index 324f02f8..ec3210ab 100644 --- a/host-interaction/gui/taskbar/find/find-taskbar.yml +++ b/host-interaction/gui/taskbar/find/find-taskbar.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/taskbar/find authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Discovery::Taskbar Discovery [B0043] examples: diff --git a/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml b/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml index 5e670e5b..cc6b2e63 100644 --- a/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml +++ b/host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/taskbar/hide authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Hide Artifacts [T1564] examples: diff --git a/host-interaction/gui/window/find/find-graphical-window.yml b/host-interaction/gui/window/find/find-graphical-window.yml index 7113a1bc..e44cec35 100644 --- a/host-interaction/gui/window/find/find-graphical-window.yml +++ b/host-interaction/gui/window/find/find-graphical-window.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/window/find authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::Application Window Discovery [T1010] examples: diff --git a/host-interaction/gui/window/get-text/get-graphical-window-text.yml b/host-interaction/gui/window/get-text/get-graphical-window-text.yml index 97dd4565..f7f25a04 100644 --- a/host-interaction/gui/window/get-text/get-graphical-window-text.yml +++ b/host-interaction/gui/window/get-text/get-graphical-window-text.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/window/get-text authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Discovery::Application Window Discovery [E1010] examples: diff --git a/host-interaction/gui/window/hide/hide-graphical-window.yml b/host-interaction/gui/window/hide/hide-graphical-window.yml index da4ae933..d0824810 100644 --- a/host-interaction/gui/window/hide/hide-graphical-window.yml +++ b/host-interaction/gui/window/hide/hide-graphical-window.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui/window/hide authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Hide Artifacts::Hidden Window [T1564.003] examples: diff --git a/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml b/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml index e1239ce6..0673777c 100644 --- a/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml +++ b/host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/cdrom authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Impact::Modify Hardware::CDROM [B0042.001] examples: diff --git a/host-interaction/hardware/cpu/get-cpu-information.yml b/host-interaction/hardware/cpu/get-cpu-information.yml index 5704b98f..653d595b 100644 --- a/host-interaction/hardware/cpu/get-cpu-information.yml +++ b/host-interaction/hardware/cpu/get-cpu-information.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Information Discovery [T1082] examples: diff --git a/host-interaction/hardware/cpu/get-number-of-processor-cores.yml b/host-interaction/hardware/cpu/get-number-of-processor-cores.yml index b8762020..73693717 100644 --- a/host-interaction/hardware/cpu/get-number-of-processor-cores.yml +++ b/host-interaction/hardware/cpu/get-number-of-processor-cores.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/cpu authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] references: diff --git a/host-interaction/hardware/cpu/get-number-of-processors.yml b/host-interaction/hardware/cpu/get-number-of-processors.yml index 4001c4c0..7499ac7c 100644 --- a/host-interaction/hardware/cpu/get-number-of-processors.yml +++ b/host-interaction/hardware/cpu/get-number-of-processors.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires property features att&ck: - Discovery::System Information Discovery [T1082] references: diff --git a/host-interaction/hardware/enumerate-devices-by-category.yml b/host-interaction/hardware/enumerate-devices-by-category.yml index 50e1b736..12b0b8a2 100644 --- a/host-interaction/hardware/enumerate-devices-by-category.yml +++ b/host-interaction/hardware/enumerate-devices-by-category.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/hardware authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features references: - https://learn.microsoft.com/en-us/windows/win32/api/strmif/nf-strmif-icreatedevenum-createclassenumerator examples: diff --git a/host-interaction/hardware/keyboard/get-keyboard-layout.yml b/host-interaction/hardware/keyboard/get-keyboard-layout.yml index 5bbc2102..b31c6141 100644 --- a/host-interaction/hardware/keyboard/get-keyboard-layout.yml +++ b/host-interaction/hardware/keyboard/get-keyboard-layout.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/keyboard authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Location Discovery::System Language Discovery [T1614.001] examples: diff --git a/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml b/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml index 2d9bf462..4264488f 100644 --- a/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml +++ b/host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - johnk3r - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Hardware::Simulate Hardware::Ctrl-Alt-Del [C0057.001] examples: diff --git a/host-interaction/hardware/memory/get-memory-capacity.yml b/host-interaction/hardware/memory/get-memory-capacity.yml index 017640ec..432cd5f0 100644 --- a/host-interaction/hardware/memory/get-memory-capacity.yml +++ b/host-interaction/hardware/memory/get-memory-capacity.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/memory authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Information Discovery [T1082] examples: diff --git a/host-interaction/hardware/memory/get-memory-information.yml b/host-interaction/hardware/memory/get-memory-information.yml index 8827b407..fcc653fe 100644 --- a/host-interaction/hardware/memory/get-memory-information.yml +++ b/host-interaction/hardware/memory/get-memory-information.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/memory authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Information Discovery [T1082] examples: diff --git a/host-interaction/hardware/mouse/swap-mouse-buttons.yml b/host-interaction/hardware/mouse/swap-mouse-buttons.yml index f5390162..bf107334 100644 --- a/host-interaction/hardware/mouse/swap-mouse-buttons.yml +++ b/host-interaction/hardware/mouse/swap-mouse-buttons.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/mouse authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Impact::Modify Hardware::Mouse [B0042.002] examples: diff --git a/host-interaction/hardware/storage/enumerate-disk-properties.yml b/host-interaction/hardware/storage/enumerate-disk-properties.yml index 90ad23d5..dfd58387 100644 --- a/host-interaction/hardware/storage/enumerate-disk-properties.yml +++ b/host-interaction/hardware/storage/enumerate-disk-properties.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/storage authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features att&ck: - Discovery::System Information Discovery [T1082] references: diff --git a/host-interaction/hardware/storage/get-disk-information.yml b/host-interaction/hardware/storage/get-disk-information.yml index 187f9899..706887ab 100644 --- a/host-interaction/hardware/storage/get-disk-information.yml +++ b/host-interaction/hardware/storage/get-disk-information.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Information Discovery [T1082] mbc: diff --git a/host-interaction/hardware/storage/get-disk-size.yml b/host-interaction/hardware/storage/get-disk-size.yml index a5a865d1..c5198c86 100644 --- a/host-interaction/hardware/storage/get-disk-size.yml +++ b/host-interaction/hardware/storage/get-disk-size.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::System Information Discovery [T1082] mbc: diff --git a/host-interaction/log/clfs/read-data-from-clfs-log-container.yml b/host-interaction/log/clfs/read-data-from-clfs-log-container.yml index 1b308263..6bc8f818 100755 --- a/host-interaction/log/clfs/read-data-from-clfs-log-container.yml +++ b/host-interaction/log/clfs/read-data-from-clfs-log-container.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/log/clfs/read authors: - blaine.stancill@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Discovery::File and Directory Discovery::Log File [E1083.m01] references: diff --git a/host-interaction/log/debug/write-event/print-debug-messages.yml b/host-interaction/log/debug/write-event/print-debug-messages.yml index 67fe5b27..43482573 100644 --- a/host-interaction/log/debug/write-event/print-debug-messages.yml +++ b/host-interaction/log/debug/write-event/print-debug-messages.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/log/debug/write-event authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call examples: - 493167E85E45363D09495D0841C30648:0x401000 features: diff --git a/host-interaction/log/winevt/access/access-the-windows-event-log.yml b/host-interaction/log/winevt/access/access-the-windows-event-log.yml index 8d86a219..2703b752 100644 --- a/host-interaction/log/winevt/access/access-the-windows-event-log.yml +++ b/host-interaction/log/winevt/access/access-the-windows-event-log.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/log/winevt/access authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Discovery::File and Directory Discovery::Log File [E1083.m01] examples: diff --git a/host-interaction/memory/create-new-application-domain-in-dotnet.yml b/host-interaction/memory/create-new-application-domain-in-dotnet.yml index 8626dfda..73e23467 100644 --- a/host-interaction/memory/create-new-application-domain-in-dotnet.yml +++ b/host-interaction/memory/create-new-application-domain-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/memory authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires class features att&ck: - Persistence::Hijack Execution Flow [T1574] mbc: diff --git a/host-interaction/mutex/check-mutex-and-exit.yml b/host-interaction/mutex/check-mutex-and-exit.yml index 37a3ba08..58a5f43d 100644 --- a/host-interaction/mutex/check-mutex-and-exit.yml +++ b/host-interaction/mutex/check-mutex-and-exit.yml @@ -5,7 +5,9 @@ rule: authors: - "@_re_fox" - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Process::Check Mutex [C0043] - Process::Terminate Process [C0018] diff --git a/host-interaction/mutex/check-mutex.yml b/host-interaction/mutex/check-mutex.yml index 21c5ac08..ff5528a6 100644 --- a/host-interaction/mutex/check-mutex.yml +++ b/host-interaction/mutex/check-mutex.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Process::Check Mutex [C0043] examples: diff --git a/host-interaction/mutex/create-mutex.yml b/host-interaction/mutex/create-mutex.yml index 7cb7472f..7858ab4e 100644 --- a/host-interaction/mutex/create-mutex.yml +++ b/host-interaction/mutex/create-mutex.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Process::Create Mutex [C0042] examples: diff --git a/host-interaction/mutex/create-semaphore-on-linux.yml b/host-interaction/mutex/create-semaphore-on-linux.yml index 1a8469d5..5adb8052 100644 --- a/host-interaction/mutex/create-semaphore-on-linux.yml +++ b/host-interaction/mutex/create-semaphore-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/mutex authors: - "@ramen0x3f" - scope: function + scopes: + static: function + dynamic: thread examples: - 294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc:0x408de0 features: diff --git a/host-interaction/mutex/lock-file.yml b/host-interaction/mutex/lock-file.yml index cac4863f..795e862c 100644 --- a/host-interaction/mutex/lock-file.yml +++ b/host-interaction/mutex/lock-file.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/mutex authors: - joakim@intezer.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Create Mutex [C0042] examples: diff --git a/host-interaction/mutex/lock-semaphore-on-linux.yml b/host-interaction/mutex/lock-semaphore-on-linux.yml index 04e10c72..30192762 100644 --- a/host-interaction/mutex/lock-semaphore-on-linux.yml +++ b/host-interaction/mutex/lock-semaphore-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/mutex authors: - "@ramen0x3f" - scope: function + scopes: + static: function + dynamic: thread examples: - 294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc:0x408e40 features: diff --git a/host-interaction/mutex/unlock-semaphore-on-linux.yml b/host-interaction/mutex/unlock-semaphore-on-linux.yml index 62ae268c..b33ff115 100644 --- a/host-interaction/mutex/unlock-semaphore-on-linux.yml +++ b/host-interaction/mutex/unlock-semaphore-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/mutex authors: - "@ramen0x3f" - scope: function + scopes: + static: function + dynamic: thread examples: - 294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc:0x408e40 features: diff --git a/host-interaction/network/address/get-local-ipv4-addresses.yml b/host-interaction/network/address/get-local-ipv4-addresses.yml index 92afbadf..4b57f8cd 100644 --- a/host-interaction/network/address/get-local-ipv4-addresses.yml +++ b/host-interaction/network/address/get-local-ipv4-addresses.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Network Configuration Discovery [T1016] examples: diff --git a/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml b/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml index 685a7e71..564aceec 100644 --- a/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml +++ b/host-interaction/network/connectivity/check-internet-connectivity-via-wininet.yml @@ -5,7 +5,9 @@ rule: authors: - matthew.williams@mandiant.com - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features att&ck: - Discovery::System Network Configuration Discovery::Internet Connection Discovery [T1016.001] examples: diff --git a/host-interaction/network/connectivity/set-tcp-connection-state.yml b/host-interaction/network/connectivity/set-tcp-connection-state.yml index 4c8d87a4..44fa848b 100644 --- a/host-interaction/network/connectivity/set-tcp-connection-state.yml +++ b/host-interaction/network/connectivity/set-tcp-connection-state.yml @@ -5,7 +5,9 @@ rule: authors: - "@johnk3r" description: The SetTcpEntry function sets the state of a TCP connection. - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Impair Defenses [T1562] references: diff --git a/host-interaction/network/domain/enumerate-domain-computers-via-ldap.yml b/host-interaction/network/domain/enumerate-domain-computers-via-ldap.yml index 2cb447de..a176f31f 100644 --- a/host-interaction/network/domain/enumerate-domain-computers-via-ldap.yml +++ b/host-interaction/network/domain/enumerate-domain-computers-via-ldap.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for an LDAP query and related Windows API calls used to enumerate other computers on the Windows domain that a computer is connected to. - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Network Configuration Discovery [T1016] references: diff --git a/host-interaction/network/domain/get-domain-controller-name.yml b/host-interaction/network/domain/get-domain-controller-name.yml index 028a9872..43768e97 100644 --- a/host-interaction/network/domain/get-domain-controller-name.yml +++ b/host-interaction/network/domain/get-domain-controller-name.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for calls to Windows APIs that can be used to determine the name of the domain controller for a Windows domain that a computer is connected to. - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Network Configuration Discovery [T1016] references: diff --git a/host-interaction/network/domain/get-domain-information.yml b/host-interaction/network/domain/get-domain-information.yml index 7e9999e7..29d43bde 100644 --- a/host-interaction/network/domain/get-domain-information.yml +++ b/host-interaction/network/domain/get-domain-information.yml @@ -7,7 +7,9 @@ rule: - anushka.virgaonkar@mandiant.com - michael.hunhoff@mandiant.com description: Detect collection of Windows domain information - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Network Configuration Discovery [T1016] examples: diff --git a/host-interaction/network/interface/get-networking-interfaces.yml b/host-interaction/network/interface/get-networking-interfaces.yml index dfcee354..b807c106 100644 --- a/host-interaction/network/interface/get-networking-interfaces.yml +++ b/host-interaction/network/interface/get-networking-interfaces.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - joakim@intezer.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Network Configuration Discovery [T1016] examples: diff --git a/host-interaction/network/traffic/copy/copy-network-traffic.yml b/host-interaction/network/traffic/copy/copy-network-traffic.yml index 0747b5c1..0267bb65 100644 --- a/host-interaction/network/traffic/copy/copy-network-traffic.yml +++ b/host-interaction/network/traffic/copy/copy-network-traffic.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/network/traffic/copy authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::Network Sniffing [T1040] examples: diff --git a/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml b/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml index 9a3a89be..d7966c00 100644 --- a/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml +++ b/host-interaction/network/traffic/filter/register-network-filter-via-wfp-api.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/network/traffic/filter authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Impact::Data Manipulation::Transmitted Data Manipulation [T1565.002] examples: diff --git a/host-interaction/os/hostname/get-hostname.yml b/host-interaction/os/hostname/get-hostname.yml index fe368145..5e225734 100644 --- a/host-interaction/os/hostname/get-hostname.yml +++ b/host-interaction/os/hostname/get-hostname.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - joakim@intezer.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Information Discovery [T1082] mbc: diff --git a/host-interaction/os/info/get-system-information-on-windows.yml b/host-interaction/os/info/get-system-information-on-windows.yml index ee8bdb49..4520cf7c 100644 --- a/host-interaction/os/info/get-system-information-on-windows.yml +++ b/host-interaction/os/info/get-system-information-on-windows.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] examples: diff --git a/host-interaction/os/shutdown-system.yml b/host-interaction/os/shutdown-system.yml index c1fa5e9a..56e14f94 100644 --- a/host-interaction/os/shutdown-system.yml +++ b/host-interaction/os/shutdown-system.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/os authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Impact::System Shutdown/Reboot [T1529] examples: diff --git a/host-interaction/os/version/check-os-version.yml b/host-interaction/os/version/check-os-version.yml index 66402d52..1f720234 100644 --- a/host-interaction/os/version/check-os-version.yml +++ b/host-interaction/os/version/check-os-version.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - johnk3r - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features att&ck: - Discovery::System Information Discovery [T1082] mbc: diff --git a/host-interaction/os/version/get-kernel-version.yml b/host-interaction/os/version/get-kernel-version.yml index cc39769b..f68f290e 100644 --- a/host-interaction/os/version/get-kernel-version.yml +++ b/host-interaction/os/version/get-kernel-version.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/os/version authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] examples: diff --git a/host-interaction/os/version/get-linux-distribution.yml b/host-interaction/os/version/get-linux-distribution.yml index a5ab0ce4..a1a02e72 100644 --- a/host-interaction/os/version/get-linux-distribution.yml +++ b/host-interaction/os/version/get-linux-distribution.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/os/version authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Information Discovery [T1082] examples: diff --git a/host-interaction/process/allocate-thread-local-storage.yml b/host-interaction/process/allocate-thread-local-storage.yml index 0313f726..fe13e83c 100644 --- a/host-interaction/process/allocate-thread-local-storage.yml +++ b/host-interaction/process/allocate-thread-local-storage.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Process::Allocate Thread Local Storage [C0040] examples: diff --git a/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml b/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml index c8a7adee..292df5a2 100644 --- a/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml +++ b/host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml @@ -5,7 +5,9 @@ rule: authors: - matthew.williams@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires property features mbc: - Process::Create Process [C0017] references: diff --git a/host-interaction/process/create/create-process-on-linux.yml b/host-interaction/process/create/create-process-on-linux.yml index 44987b88..9126da31 100644 --- a/host-interaction/process/create/create-process-on-linux.yml +++ b/host-interaction/process/create/create-process-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/create authors: - joakim@intezer.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Process::Create Process [C0017] examples: diff --git a/host-interaction/process/create/create-process-on-windows.yml b/host-interaction/process/create/create-process-on-windows.yml index 1f3dcd75..c72689fc 100644 --- a/host-interaction/process/create/create-process-on-windows.yml +++ b/host-interaction/process/create/create-process-on-windows.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/create authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Create Process [C0017] examples: diff --git a/host-interaction/process/create/create-process-suspended.yml b/host-interaction/process/create/create-process-suspended.yml index 63e50e71..92f12702 100644 --- a/host-interaction/process/create/create-process-suspended.yml +++ b/host-interaction/process/create/create-process-suspended.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/create authors: - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Process::Create Process::Create Suspended Process [C0017.003] examples: diff --git a/host-interaction/process/create/execute-command.yml b/host-interaction/process/create/execute-command.yml index 1ca1d9fd..365ed530 100644 --- a/host-interaction/process/create/execute-command.yml +++ b/host-interaction/process/create/execute-command.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/create authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: call mbc: - Process::Create Process [C0017] examples: diff --git a/host-interaction/process/dump/create-process-memory-minidump.yml b/host-interaction/process/dump/create-process-memory-minidump.yml index 14e5d39c..caf81379 100644 --- a/host-interaction/process/dump/create-process-memory-minidump.yml +++ b/host-interaction/process/dump/create-process-memory-minidump.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/process/dump authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - File System::Writes File [C0052] examples: diff --git a/host-interaction/process/get-process-heap-flags.yml b/host-interaction/process/get-process-heap-flags.yml index 8dee6840..2a097d7e 100644 --- a/host-interaction/process/get-process-heap-flags.yml +++ b/host-interaction/process/get-process-heap-flags.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::Process Discovery [T1057] references: diff --git a/host-interaction/process/get-process-heap-force-flags.yml b/host-interaction/process/get-process-heap-force-flags.yml index b2240ba6..3aac485f 100644 --- a/host-interaction/process/get-process-heap-force-flags.yml +++ b/host-interaction/process/get-process-heap-force-flags.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::Process Discovery [T1057] references: diff --git a/host-interaction/process/inject/allocate-or-change-rwx-memory.yml b/host-interaction/process/inject/allocate-or-change-rwx-memory.yml index 6e5d0684..1b5fdcb9 100644 --- a/host-interaction/process/inject/allocate-or-change-rwx-memory.yml +++ b/host-interaction/process/inject/allocate-or-change-rwx-memory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - "@mr-tz" - scope: basic block + scopes: + static: basic block + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Memory::Allocate Memory [C0007] examples: diff --git a/host-interaction/process/inject/allocate-user-process-rwx-memory.yml b/host-interaction/process/inject/allocate-user-process-rwx-memory.yml index cd2c3bda..3dc6af4c 100644 --- a/host-interaction/process/inject/allocate-user-process-rwx-memory.yml +++ b/host-interaction/process/inject/allocate-user-process-rwx-memory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection [T1055] examples: diff --git a/host-interaction/process/inject/attach-user-process-memory.yml b/host-interaction/process/inject/attach-user-process-memory.yml index 4cb52d70..4f8fa5c0 100644 --- a/host-interaction/process/inject/attach-user-process-memory.yml +++ b/host-interaction/process/inject/attach-user-process-memory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection [T1055] mbc: diff --git a/host-interaction/process/inject/free-user-process-memory.yml b/host-interaction/process/inject/free-user-process-memory.yml index eb5ec915..f42f7a3d 100644 --- a/host-interaction/process/inject/free-user-process-memory.yml +++ b/host-interaction/process/inject/free-user-process-memory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection [T1055] mbc: diff --git a/host-interaction/process/inject/hijack-thread-execution.yml b/host-interaction/process/inject/hijack-thread-execution.yml index d60daa4b..9a43ccfc 100644 --- a/host-interaction/process/inject/hijack-thread-execution.yml +++ b/host-interaction/process/inject/hijack-thread-execution.yml @@ -5,7 +5,9 @@ rule: authors: - 0x534a@mailbox.org - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection::Thread Execution Hijacking [T1055.003] - Defense Evasion::Reflective Code Loading [T1620] diff --git a/host-interaction/process/inject/inject-apc.yml b/host-interaction/process/inject/inject-apc.yml index 6f803b9d..da9102f8 100644 --- a/host-interaction/process/inject/inject-apc.yml +++ b/host-interaction/process/inject/inject-apc.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection::Asynchronous Procedure Call [T1055.004] examples: diff --git a/host-interaction/process/inject/inject-dll.yml b/host-interaction/process/inject/inject-dll.yml index d1ceb6b8..adc9c90a 100644 --- a/host-interaction/process/inject/inject-dll.yml +++ b/host-interaction/process/inject/inject-dll.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - 0x534a@mailbox.org - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection::Dynamic-link Library Injection [T1055.001] references: diff --git a/host-interaction/process/inject/inject-pe.yml b/host-interaction/process/inject/inject-pe.yml index 333f831e..5a57a520 100644 --- a/host-interaction/process/inject/inject-pe.yml +++ b/host-interaction/process/inject/inject-pe.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - 0x534a@mailbox.org - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features att&ck: - Defense Evasion::Process Injection::Portable Executable Injection [T1055.002] - Defense Evasion::Reflective Code Loading [T1620] diff --git a/host-interaction/process/inject/inject-shellcode-using-a-file-mapping-object.yml b/host-interaction/process/inject/inject-shellcode-using-a-file-mapping-object.yml index 7bf617d3..9f7be243 100644 --- a/host-interaction/process/inject/inject-shellcode-using-a-file-mapping-object.yml +++ b/host-interaction/process/inject/inject-shellcode-using-a-file-mapping-object.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection [T1055] mbc: diff --git a/host-interaction/process/inject/inject-shellcode-using-extra-window-memory.yml b/host-interaction/process/inject/inject-shellcode-using-extra-window-memory.yml index f500f3e7..3add357b 100644 --- a/host-interaction/process/inject/inject-shellcode-using-extra-window-memory.yml +++ b/host-interaction/process/inject/inject-shellcode-using-extra-window-memory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection::Extra Window Memory Injection [T1055.011] mbc: diff --git a/host-interaction/process/inject/inject-shellcode-using-window-subclass-procedure.yml b/host-interaction/process/inject/inject-shellcode-using-window-subclass-procedure.yml index ba0ebdac..2d10da4d 100644 --- a/host-interaction/process/inject/inject-shellcode-using-window-subclass-procedure.yml +++ b/host-interaction/process/inject/inject-shellcode-using-window-subclass-procedure.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection [T1055] mbc: diff --git a/host-interaction/process/inject/inject-thread.yml b/host-interaction/process/inject/inject-thread.yml index f6e25e16..b83848f2 100644 --- a/host-interaction/process/inject/inject-thread.yml +++ b/host-interaction/process/inject/inject-thread.yml @@ -5,7 +5,9 @@ rule: authors: - anamaria.martinezgom@mandiant.com - 0x534a@mailbox.org - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection::Thread Execution Hijacking [T1055.003] - Defense Evasion::Reflective Code Loading [T1620] diff --git a/host-interaction/process/inject/use-process-doppelgänging.yml b/host-interaction/process/inject/use-process-doppelgänging.yml index 866ced9b..01bd3a73 100644 --- a/host-interaction/process/inject/use-process-doppelgänging.yml +++ b/host-interaction/process/inject/use-process-doppelgänging.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Process Injection::Process Doppelgänging [T1055.013] examples: diff --git a/host-interaction/process/inject/use-process-replacement.yml b/host-interaction/process/inject/use-process-replacement.yml index 1f11157a..18e5c0c6 100644 --- a/host-interaction/process/inject/use-process-replacement.yml +++ b/host-interaction/process/inject/use-process-replacement.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Process Injection::Process Hollowing [T1055.012] - Defense Evasion::Reflective Code Loading [T1620] diff --git a/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml b/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml index 7f32dd57..a2591024 100644 --- a/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml +++ b/host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/list authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Process Discovery [T1057] examples: diff --git a/host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml b/host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml index ef325cc6..256f8fd2 100644 --- a/host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml +++ b/host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/list authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::Process Discovery [T1057] - Discovery::Software Discovery [T1518] diff --git a/host-interaction/process/list/enumerate-processes.yml b/host-interaction/process/list/enumerate-processes.yml index 59e61888..3325a93f 100644 --- a/host-interaction/process/list/enumerate-processes.yml +++ b/host-interaction/process/list/enumerate-processes.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::Process Discovery [T1057] - Discovery::Software Discovery [T1518] diff --git a/host-interaction/process/list/find-process-by-pid.yml b/host-interaction/process/list/find-process-by-pid.yml index dc33f7f5..881be3f3 100644 --- a/host-interaction/process/list/find-process-by-pid.yml +++ b/host-interaction/process/list/find-process-by-pid.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Process Discovery [T1057] examples: diff --git a/host-interaction/process/list/get-explorer-pid.yml b/host-interaction/process/list/get-explorer-pid.yml index 0d3e888e..06877e82 100644 --- a/host-interaction/process/list/get-explorer-pid.yml +++ b/host-interaction/process/list/get-explorer-pid.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/list authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Process Discovery [T1057] references: diff --git a/host-interaction/process/map-section-object.yml b/host-interaction/process/map-section-object.yml index e7681633..52fbac7a 100644 --- a/host-interaction/process/map-section-object.yml +++ b/host-interaction/process/map-section-object.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread examples: - 61908f4d70ce6f16173e76aa42a8c25a:0x4018F0 features: diff --git a/host-interaction/process/modify/acquire-debug-privileges.yml b/host-interaction/process/modify/acquire-debug-privileges.yml index 35893a61..73422e1a 100644 --- a/host-interaction/process/modify/acquire-debug-privileges.yml +++ b/host-interaction/process/modify/acquire-debug-privileges.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/modify authors: - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Privilege Escalation::Access Token Manipulation [T1134] examples: diff --git a/host-interaction/process/modify/modify-access-privileges.yml b/host-interaction/process/modify/modify-access-privileges.yml index e127f503..49f98971 100644 --- a/host-interaction/process/modify/modify-access-privileges.yml +++ b/host-interaction/process/modify/modify-access-privileges.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/modify authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Privilege Escalation::Access Token Manipulation [T1134] examples: diff --git a/host-interaction/process/modules/list/enumerate-process-modules.yml b/host-interaction/process/modules/list/enumerate-process-modules.yml index d588a51e..4a4db4e1 100644 --- a/host-interaction/process/modules/list/enumerate-process-modules.yml +++ b/host-interaction/process/modules/list/enumerate-process-modules.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::Process Discovery [T1057] examples: diff --git a/host-interaction/process/set-thread-local-storage-value.yml b/host-interaction/process/set-thread-local-storage-value.yml index edb7329a..0afad717 100644 --- a/host-interaction/process/set-thread-local-storage-value.yml +++ b/host-interaction/process/set-thread-local-storage-value.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Process::Set Thread Local Storage Value [C0041] examples: diff --git a/host-interaction/process/terminate/terminate-process-via-kill.yml b/host-interaction/process/terminate/terminate-process-via-kill.yml index b9140122..75ff517d 100644 --- a/host-interaction/process/terminate/terminate-process-via-kill.yml +++ b/host-interaction/process/terminate/terminate-process-via-kill.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/terminate authors: - joakim@intezer.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Process::Terminate Process [C0018] examples: diff --git a/host-interaction/process/terminate/terminate-process.yml b/host-interaction/process/terminate/terminate-process.yml index 6d80122f..c29a3c30 100644 --- a/host-interaction/process/terminate/terminate-process.yml +++ b/host-interaction/process/terminate/terminate-process.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Process::Terminate Process [C0018] examples: diff --git a/host-interaction/recycle-bin/empty-recycle-bin-quietly.yml b/host-interaction/recycle-bin/empty-recycle-bin-quietly.yml index 4c3c5cd8..70110f29 100644 --- a/host-interaction/recycle-bin/empty-recycle-bin-quietly.yml +++ b/host-interaction/recycle-bin/empty-recycle-bin-quietly.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/recycle-bin authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires offset, mnemonic features att&ck: - Defense Evasion::Indicator Removal [T1070] references: diff --git a/host-interaction/registry/create-registry-key-via-offline-registry-library.yml b/host-interaction/registry/create-registry-key-via-offline-registry-library.yml index 65469376..b9093d56 100644 --- a/host-interaction/registry/create-registry-key-via-offline-registry-library.yml +++ b/host-interaction/registry/create-registry-key-via-offline-registry-library.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/registry authors: - johnk3r - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Modify Registry [T1112] mbc: diff --git a/host-interaction/registry/create/set-registry-value.yml b/host-interaction/registry/create/set-registry-value.yml index 63236890..c2091ed7 100644 --- a/host-interaction/registry/create/set-registry-value.yml +++ b/host-interaction/registry/create/set-registry-value.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead mbc: - Operating System::Registry::Set Registry Key [C0036.001] examples: diff --git a/host-interaction/registry/delete/delete-registry-key.yml b/host-interaction/registry/delete/delete-registry-key.yml index f702e7a1..0760a49e 100644 --- a/host-interaction/registry/delete/delete-registry-key.yml +++ b/host-interaction/registry/delete/delete-registry-key.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - johnk3r - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Modify Registry [T1112] mbc: diff --git a/host-interaction/registry/delete/delete-registry-value.yml b/host-interaction/registry/delete/delete-registry-value.yml index f61c0461..39a77d94 100644 --- a/host-interaction/registry/delete/delete-registry-value.yml +++ b/host-interaction/registry/delete/delete-registry-value.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Modify Registry [T1112] mbc: diff --git a/host-interaction/registry/open-registry-key-via-offline-registry-library.yml b/host-interaction/registry/open-registry-key-via-offline-registry-library.yml index 7baadd03..2a8d3c01 100644 --- a/host-interaction/registry/open-registry-key-via-offline-registry-library.yml +++ b/host-interaction/registry/open-registry-key-via-offline-registry-library.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/registry authors: - johnk3r - scope: function + scopes: + static: function + dynamic: call mbc: - Operating System::Registry::Open Registry Key [C0036.003] examples: diff --git a/host-interaction/registry/query-or-enumerate-registry-key.yml b/host-interaction/registry/query-or-enumerate-registry-key.yml index 5644e643..62d672d1 100644 --- a/host-interaction/registry/query-or-enumerate-registry-key.yml +++ b/host-interaction/registry/query-or-enumerate-registry-key.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Query Registry [T1012] mbc: diff --git a/host-interaction/registry/query-or-enumerate-registry-value.yml b/host-interaction/registry/query-or-enumerate-registry-value.yml index 5eaa5b66..855da49e 100644 --- a/host-interaction/registry/query-or-enumerate-registry-value.yml +++ b/host-interaction/registry/query-or-enumerate-registry-value.yml @@ -6,7 +6,9 @@ rule: - william.ballenthin@mandiant.com - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Query Registry [T1012] mbc: diff --git a/host-interaction/registry/query-registry-key-via-offline-registry-library.yml b/host-interaction/registry/query-registry-key-via-offline-registry-library.yml index 6092ed4c..6cf99f16 100644 --- a/host-interaction/registry/query-registry-key-via-offline-registry-library.yml +++ b/host-interaction/registry/query-registry-key-via-offline-registry-library.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/registry authors: - johnk3r - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::Query Registry [T1012] mbc: diff --git a/host-interaction/registry/set-registry-key-via-offline-registry-library.yml b/host-interaction/registry/set-registry-key-via-offline-registry-library.yml index dc1e8438..66b1a58d 100644 --- a/host-interaction/registry/set-registry-key-via-offline-registry-library.yml +++ b/host-interaction/registry/set-registry-key-via-offline-registry-library.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/registry authors: - johnk3r - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Modify Registry [T1112] mbc: diff --git a/host-interaction/service/continue-service.yml b/host-interaction/service/continue-service.yml index dd481e8b..2d1e5f62 100644 --- a/host-interaction/service/continue-service.yml +++ b/host-interaction/service/continue-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] examples: diff --git a/host-interaction/service/create/create-service.yml b/host-interaction/service/create/create-service.yml index 5987994d..6358c083 100644 --- a/host-interaction/service/create/create-service.yml +++ b/host-interaction/service/create/create-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service/create authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] - Execution::System Services::Service Execution [T1569.002] diff --git a/host-interaction/service/delete/delete-service.yml b/host-interaction/service/delete/delete-service.yml index b704dd52..6aa8fe16 100644 --- a/host-interaction/service/delete/delete-service.yml +++ b/host-interaction/service/delete/delete-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service/delete authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] examples: diff --git a/host-interaction/service/list/enumerate-services.yml b/host-interaction/service/list/enumerate-services.yml index 6c4bd7c6..d35e4a12 100644 --- a/host-interaction/service/list/enumerate-services.yml +++ b/host-interaction/service/list/enumerate-services.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Service Discovery [T1007] examples: diff --git a/host-interaction/service/modify/modify-service.yml b/host-interaction/service/modify/modify-service.yml index 2ada512e..18297751 100644 --- a/host-interaction/service/modify/modify-service.yml +++ b/host-interaction/service/modify/modify-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service/modify authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] - Execution::System Services::Service Execution [T1569.002] diff --git a/host-interaction/service/pause-service.yml b/host-interaction/service/pause-service.yml index 91bbafe9..9a0350dd 100644 --- a/host-interaction/service/pause-service.yml +++ b/host-interaction/service/pause-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] examples: diff --git a/host-interaction/service/query-service-configuration.yml b/host-interaction/service/query-service-configuration.yml index 539aab63..c77b5f8f 100644 --- a/host-interaction/service/query-service-configuration.yml +++ b/host-interaction/service/query-service-configuration.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Service Discovery [T1007] examples: diff --git a/host-interaction/service/query-service-status.yml b/host-interaction/service/query-service-status.yml index 0d729310..ed2eccb2 100644 --- a/host-interaction/service/query-service-status.yml +++ b/host-interaction/service/query-service-status.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Service Discovery [T1007] examples: diff --git a/host-interaction/service/run-as-service.yml b/host-interaction/service/run-as-service.yml index d2fa5d42..a20c9c33 100644 --- a/host-interaction/service/run-as-service.yml +++ b/host-interaction/service/run-as-service.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Anti-Behavioral Analysis::Conditional Execution::Runs as Service [B0025.007] examples: diff --git a/host-interaction/service/start/start-service.yml b/host-interaction/service/start/start-service.yml index a8ff5f63..33d110b9 100644 --- a/host-interaction/service/start/start-service.yml +++ b/host-interaction/service/start/start-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service/start authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] examples: diff --git a/host-interaction/service/stop/stop-service.yml b/host-interaction/service/stop/stop-service.yml index d1426f20..9caa6d57 100644 --- a/host-interaction/service/stop/stop-service.yml +++ b/host-interaction/service/stop/stop-service.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/service/stop authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] - Impact::Service Stop [T1489] diff --git a/host-interaction/session/get-current-user-on-linux.yml b/host-interaction/session/get-current-user-on-linux.yml index 06a668db..29f7a424 100644 --- a/host-interaction/session/get-current-user-on-linux.yml +++ b/host-interaction/session/get-current-user-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/session authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Owner/User Discovery [T1033] examples: diff --git a/host-interaction/session/get-logon-sessions.yml b/host-interaction/session/get-logon-sessions.yml index 22795918..70956342 100644 --- a/host-interaction/session/get-logon-sessions.yml +++ b/host-interaction/session/get-logon-sessions.yml @@ -5,7 +5,9 @@ rule: authors: - awillia2@cisco.com description: Looks for imported Windows APIs being called to enumerate user sessions. - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Account Discovery [T1087] examples: diff --git a/host-interaction/session/get-session-integrity-level.yml b/host-interaction/session/get-session-integrity-level.yml index 7a5cd2a5..a07c7a25 100644 --- a/host-interaction/session/get-session-integrity-level.yml +++ b/host-interaction/session/get-session-integrity-level.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Owner/User Discovery [T1033] examples: diff --git a/host-interaction/session/get-session-user-name.yml b/host-interaction/session/get-session-user-name.yml index 4938f799..685652d1 100644 --- a/host-interaction/session/get-session-user-name.yml +++ b/host-interaction/session/get-session-user-name.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::System Owner/User Discovery [T1033] - Discovery::Account Discovery [T1087] diff --git a/host-interaction/session/get-token-membership.yml b/host-interaction/session/get-token-membership.yml index 731a695d..54b399b1 100644 --- a/host-interaction/session/get-token-membership.yml +++ b/host-interaction/session/get-token-membership.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/session authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Owner/User Discovery [T1033] examples: diff --git a/host-interaction/session/get-user-security-identifier.yml b/host-interaction/session/get-user-security-identifier.yml index 587c114f..bf2c6ea4 100644 --- a/host-interaction/session/get-user-security-identifier.yml +++ b/host-interaction/session/get-user-security-identifier.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/session authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Account Discovery [T1087] examples: diff --git a/host-interaction/software/get-installed-programs.yml b/host-interaction/software/get-installed-programs.yml index a9182767..cab7d83d 100644 --- a/host-interaction/software/get-installed-programs.yml +++ b/host-interaction/software/get-installed-programs.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features att&ck: - Discovery::Software Discovery [T1518] examples: diff --git a/host-interaction/thread/create/create-thread.yml b/host-interaction/thread/create/create-thread.yml index bba2ea2e..3351bfb4 100644 --- a/host-interaction/thread/create/create-thread.yml +++ b/host-interaction/thread/create/create-thread.yml @@ -7,7 +7,9 @@ rule: - michael.hunhoff@mandiant.com - joakim@intezer.com - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Process::Create Thread [C0038] examples: diff --git a/host-interaction/thread/list/enumerate-threads.yml b/host-interaction/thread/list/enumerate-threads.yml index 5b375764..c445f568 100644 --- a/host-interaction/thread/list/enumerate-threads.yml +++ b/host-interaction/thread/list/enumerate-threads.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/thread/list authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Discovery::Process Discovery [T1057] mbc: diff --git a/host-interaction/thread/resume/resume-thread.yml b/host-interaction/thread/resume/resume-thread.yml index 2fa1c118..26a4ee93 100644 --- a/host-interaction/thread/resume/resume-thread.yml +++ b/host-interaction/thread/resume/resume-thread.yml @@ -5,7 +5,9 @@ rule: authors: - 0x534a@mailbox.org - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Resume Thread [C0054] examples: diff --git a/host-interaction/thread/suspend/suspend-thread.yml b/host-interaction/thread/suspend/suspend-thread.yml index 563591c5..f3edf003 100644 --- a/host-interaction/thread/suspend/suspend-thread.yml +++ b/host-interaction/thread/suspend/suspend-thread.yml @@ -5,7 +5,9 @@ rule: authors: - 0x534a@mailbox.org - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Suspend Thread [C0055] examples: diff --git a/host-interaction/thread/terminate/terminate-thread.yml b/host-interaction/thread/terminate/terminate-thread.yml index cfc7e63c..3bf7356c 100644 --- a/host-interaction/thread/terminate/terminate-thread.yml +++ b/host-interaction/thread/terminate/terminate-thread.yml @@ -6,7 +6,9 @@ rule: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Terminate Thread [C0039] examples: diff --git a/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml b/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml index 83748e71..7ffef285 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/uac/bypass authors: - richard.cole@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] references: diff --git a/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml b/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml index 2b1b3a3f..7e90cb1b 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-icmluautil.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/uac/bypass authors: - anamaria.martinezgom@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] references: diff --git a/host-interaction/uac/bypass/bypass-uac-via-rpc.yml b/host-interaction/uac/bypass/bypass-uac-via-rpc.yml index e8d34bf7..27fcaf27 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-rpc.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-rpc.yml @@ -5,7 +5,9 @@ rule: authors: - david.cannings@pwc.com - david@edeca.net - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] references: diff --git a/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml b/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml index 24117556..7a9795b1 100644 --- a/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml +++ b/host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml @@ -5,7 +5,9 @@ rule: authors: - richard.cole@mandiant.com - david.cannings@pwc.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] references: diff --git a/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml b/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml index 2aac4279..4f5c52d6 100644 --- a/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml +++ b/host-interaction/wmi/connect-to-wmi-namespace-via-wbemlocator.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/wmi authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features att&ck: - Execution::Windows Management Instrumentation [T1047] examples: diff --git a/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml b/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml index 47db03ce..3f09f537 100644 --- a/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml +++ b/impact/inhibit-system-recovery/delete-volume-shadow-copies.yml @@ -4,7 +4,9 @@ rule: namespace: impact/inhibit-system-recovery authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Impact::Inhibit System Recovery [T1490] - Defense Evasion::Indicator Removal::File Deletion [T1070.004] diff --git a/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml b/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml index 7fd1819f..3257c3f0 100644 --- a/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml +++ b/impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml @@ -4,7 +4,9 @@ rule: namespace: impact/wipe-disk/wipe-mbr authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Impact::Disk Wipe::Disk Structure Wipe [T1561.002] mbc: diff --git a/internal/limitation/file/internal-autohotkey-file-limitation.yml b/internal/limitation/file/internal-autohotkey-file-limitation.yml index 3a82e33d..e68932da 100644 --- a/internal/limitation/file/internal-autohotkey-file-limitation.yml +++ b/internal/limitation/file/internal-autohotkey-file-limitation.yml @@ -11,7 +11,9 @@ rule: AutoHotkey was developed from AutoIT and the scripts may be similar. capa cannot handle AutoHotkey scripts. This means that the results will be misleading or incomplete. You may have to analyze the file manually, using a tool like the AutoIt decompiler MyAut2Exe. - scope: file + scopes: + static: file + dynamic: file examples: - 92D8EA10EA30E8B534334A1C9857A455 features: diff --git a/internal/limitation/file/internal-autoit-file-limitation.yml b/internal/limitation/file/internal-autoit-file-limitation.yml index 1d11979c..c687e4c8 100644 --- a/internal/limitation/file/internal-autoit-file-limitation.yml +++ b/internal/limitation/file/internal-autoit-file-limitation.yml @@ -13,7 +13,9 @@ rule: AutoIt is a freeware BASIC-like scripting language designed for automating the Windows GUI. capa cannot handle AutoIt scripts. This means that the results will be misleading or incomplete. You may have to analyze the file manually, using a tool like the AutoIt decompiler MyAut2Exe. - scope: file + scopes: + static: file + dynamic: file examples: - 55D77AB16377A8A314982F723FCC6FAE features: diff --git a/internal/limitation/file/internal-installer-file-limitation.yml b/internal/limitation/file/internal-installer-file-limitation.yml index c12eaed2..0499a138 100644 --- a/internal/limitation/file/internal-installer-file-limitation.yml +++ b/internal/limitation/file/internal-installer-file-limitation.yml @@ -11,7 +11,9 @@ rule: capa cannot handle installers well. This means the results may be misleading or incomplete. You should try to understand the install mechanism and analyze created files with capa. - scope: file + scopes: + static: file + dynamic: file examples: - 70FD3347786ED7A4A43910E6778EF296 features: diff --git a/internal/limitation/file/internal-packer-file-limitation.yml b/internal/limitation/file/internal-packer-file-limitation.yml index 9789d54e..5e87b7e5 100644 --- a/internal/limitation/file/internal-packer-file-limitation.yml +++ b/internal/limitation/file/internal-packer-file-limitation.yml @@ -10,7 +10,9 @@ rule: Packed samples have often been obfuscated to hide their logic. capa cannot handle obfuscation well. This means the results may be misleading or incomplete. If possible, you should try to unpack this input file before analyzing it with capa. - scope: file + scopes: + static: file + dynamic: file examples: - CD2CBA9E6313E8DF2C1273593E649682 features: diff --git a/internal/limitation/file/internal-visual-basic-file-limitation.yml b/internal/limitation/file/internal-visual-basic-file-limitation.yml index 20cc6dc4..2eba6c04 100644 --- a/internal/limitation/file/internal-visual-basic-file-limitation.yml +++ b/internal/limitation/file/internal-visual-basic-file-limitation.yml @@ -11,7 +11,9 @@ rule: representation called P-Code. capa cannot handle Visual Basic executables well. This means that the results will be misleading or incomplete. You may have to analyze the file manually, for example using a tool like VB Decompiler. - scope: file + scopes: + static: file + dynamic: file examples: - 9bca6b99e7981208af4c7925b96fb9cf features: diff --git a/lib/allocate-memory.yml b/lib/allocate-memory.yml index 13c2dde1..729b15d5 100644 --- a/lib/allocate-memory.yml +++ b/lib/allocate-memory.yml @@ -5,7 +5,9 @@ rule: - 0x534a@mailbox.org - "@mr-tz" lib: true - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Memory::Allocate Memory [C0007] examples: diff --git a/lib/allocate-or-change-rw-memory.yml b/lib/allocate-or-change-rw-memory.yml index b67f25c3..bd304b72 100644 --- a/lib/allocate-or-change-rw-memory.yml +++ b/lib/allocate-or-change-rw-memory.yml @@ -5,7 +5,9 @@ rule: - 0x534a@mailbox.org - "@mr-tz" lib: true - scope: basic block + scopes: + static: basic block + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Memory::Allocate Memory [C0007] examples: diff --git a/lib/calculate-modulo-256-via-x86-assembly.yml b/lib/calculate-modulo-256-via-x86-assembly.yml index 694a307d..d089e144 100644 --- a/lib/calculate-modulo-256-via-x86-assembly.yml +++ b/lib/calculate-modulo-256-via-x86-assembly.yml @@ -4,7 +4,9 @@ rule: authors: - moritz.raabe@mandiant.com lib: true - scope: instruction + scopes: + static: instruction + dynamic: unsupported # requires mnemonic features mbc: - Data::Modulo [C0058] examples: diff --git a/lib/change-memory-protection.yml b/lib/change-memory-protection.yml index 05301e1a..3544fefa 100644 --- a/lib/change-memory-protection.yml +++ b/lib/change-memory-protection.yml @@ -4,7 +4,9 @@ rule: authors: - "@mr-tz" lib: true - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Memory::Change Memory Protection [C0008] examples: diff --git a/lib/contain-loop.yml b/lib/contain-loop.yml index 6dcf5fda..05db4465 100644 --- a/lib/contain-loop.yml +++ b/lib/contain-loop.yml @@ -4,7 +4,9 @@ rule: authors: - moritz.raabe@mandiant.com lib: true - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features examples: - 08AC667C65D36D6542917655571E61C8:0x406EAA features: diff --git a/lib/contain-pusha-popa-sequence.yml b/lib/contain-pusha-popa-sequence.yml index 1fbe9b25..1c368029 100644 --- a/lib/contain-pusha-popa-sequence.yml +++ b/lib/contain-pusha-popa-sequence.yml @@ -4,7 +4,9 @@ rule: authors: - moritz.raabe@mandiant.com lib: true - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features examples: - a5c70086b3bc4fe64f4e7a0aa452e620:0x35007200 features: diff --git a/lib/create-or-open-file.yml b/lib/create-or-open-file.yml index 8cbc7f30..def162e8 100644 --- a/lib/create-or-open-file.yml +++ b/lib/create-or-open-file.yml @@ -5,7 +5,9 @@ rule: - michael.hunhoff@mandiant.com - joakim@intezer.com lib: true - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - File System::Create File [C0016] examples: diff --git a/lib/create-or-open-registry-key.yml b/lib/create-or-open-registry-key.yml index 3c2f6d56..58c2a143 100644 --- a/lib/create-or-open-registry-key.yml +++ b/lib/create-or-open-registry-key.yml @@ -5,7 +5,9 @@ rule: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com lib: true - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Operating System::Registry::Create Registry Key [C0036.004] - Operating System::Registry::Open Registry Key [C0036.003] diff --git a/lib/create-or-open-section-object.yml b/lib/create-or-open-section-object.yml index 75968e98..6def76ae 100644 --- a/lib/create-or-open-section-object.yml +++ b/lib/create-or-open-section-object.yml @@ -4,7 +4,9 @@ rule: authors: - william.ballenthin@mandiant.com lib: true - scope: function + scopes: + static: function + dynamic: thread examples: - daa13ae302fe8b618ddbf590537443ef:0x401116 features: diff --git a/lib/delay-execution.yml b/lib/delay-execution.yml index 14448a5b..35079b7f 100644 --- a/lib/delay-execution.yml +++ b/lib/delay-execution.yml @@ -5,7 +5,9 @@ rule: - michael.hunhoff@mandiant.com - "@ramen0x3f" lib: true - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed Execution [B0003.003] references: diff --git a/lib/duplicate-stdin-and-stdout.yml b/lib/duplicate-stdin-and-stdout.yml index ed94dbf6..84091724 100644 --- a/lib/duplicate-stdin-and-stdout.yml +++ b/lib/duplicate-stdin-and-stdout.yml @@ -4,7 +4,9 @@ rule: authors: - joakim@intezer.com lib: true - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead examples: - 7351f8a40c5450557b24622417fc478d:0x40236D features: diff --git a/lib/get-os-version.yml b/lib/get-os-version.yml index 4ef45d0c..ffae798c 100644 --- a/lib/get-os-version.yml +++ b/lib/get-os-version.yml @@ -4,7 +4,9 @@ rule: authors: - "@mr-tz" lib: true - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead examples: - 493167E85E45363D09495D0841C30648:0x401000 - 5f66b82558ca92e54e77f216ef4c066c:0x44580A diff --git a/lib/get-service-handle.yml b/lib/get-service-handle.yml index 703555c7..55aacba8 100644 --- a/lib/get-service-handle.yml +++ b/lib/get-service-handle.yml @@ -4,7 +4,9 @@ rule: authors: - moritz.raabe@mandiant.com lib: true - scope: function + scopes: + static: function + dynamic: call examples: - Practical Malware Analysis Lab 03-02.dll_:0x10004706 features: diff --git a/lib/open-process.yml b/lib/open-process.yml index 684fc4fa..7981b689 100644 --- a/lib/open-process.yml +++ b/lib/open-process.yml @@ -4,7 +4,9 @@ rule: authors: - 0x534a@mailbox.org lib: true - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Open Process [C0065] examples: diff --git a/lib/open-thread.yml b/lib/open-thread.yml index 60b0aca5..a08e99ca 100644 --- a/lib/open-thread.yml +++ b/lib/open-thread.yml @@ -4,7 +4,9 @@ rule: authors: - 0x534a@mailbox.org lib: true - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Process::Open Thread [C0066] examples: diff --git a/lib/peb-access.yml b/lib/peb-access.yml index 00a76905..1490de8c 100644 --- a/lib/peb-access.yml +++ b/lib/peb-access.yml @@ -4,7 +4,9 @@ rule: authors: - michael.hunhoff@mandiant.com lib: true - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, offset, mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::Process Environment Block [B0001.019] references: diff --git a/lib/validate-payment-card-number-using-luhn-algorithm-with-lookup-table.yml b/lib/validate-payment-card-number-using-luhn-algorithm-with-lookup-table.yml index df9a211a..a498fafc 100644 --- a/lib/validate-payment-card-number-using-luhn-algorithm-with-lookup-table.yml +++ b/lib/validate-payment-card-number-using-luhn-algorithm-with-lookup-table.yml @@ -4,7 +4,9 @@ rule: authors: - "@_re_fox" lib: true - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, offset, mnemonic, Not features mbc: - Data::Checksum::Luhn [C0032.002] examples: diff --git a/lib/validate-payment-card-number-using-luhn-algorithm-with-no-lookup-table.yml b/lib/validate-payment-card-number-using-luhn-algorithm-with-no-lookup-table.yml index 576ba2e5..c190adaa 100644 --- a/lib/validate-payment-card-number-using-luhn-algorithm-with-no-lookup-table.yml +++ b/lib/validate-payment-card-number-using-luhn-algorithm-with-no-lookup-table.yml @@ -4,7 +4,9 @@ rule: authors: - "@_re_fox" lib: true - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, offset, mnemonic features mbc: - Data::Checksum::Luhn [C0032.002] examples: diff --git a/lib/write-process-memory.yml b/lib/write-process-memory.yml index e5e2dd36..54690c30 100644 --- a/lib/write-process-memory.yml +++ b/lib/write-process-memory.yml @@ -4,7 +4,9 @@ rule: authors: - moritz.raabe@mandiant.com lib: true - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Process Injection [T1055] examples: diff --git a/linking/runtime-linking/access-peb-ldr_data.yml b/linking/runtime-linking/access-peb-ldr_data.yml index 1dbce3e2..3fa40062 100644 --- a/linking/runtime-linking/access-peb-ldr_data.yml +++ b/linking/runtime-linking/access-peb-ldr_data.yml @@ -4,7 +4,9 @@ rule: namespace: linking/runtime-linking authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires offset features att&ck: - Execution::Shared Modules [T1129] references: diff --git a/linking/runtime-linking/get-kernel32-base-address.yml b/linking/runtime-linking/get-kernel32-base-address.yml index c8d89557..e897783f 100644 --- a/linking/runtime-linking/get-kernel32-base-address.yml +++ b/linking/runtime-linking/get-kernel32-base-address.yml @@ -4,7 +4,9 @@ rule: namespace: linking/runtime-linking authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires offset features att&ck: - Execution::Shared Modules [T1129] references: diff --git a/linking/runtime-linking/get-ntdll-base-address.yml b/linking/runtime-linking/get-ntdll-base-address.yml index bddd293c..74106ccf 100644 --- a/linking/runtime-linking/get-ntdll-base-address.yml +++ b/linking/runtime-linking/get-ntdll-base-address.yml @@ -4,7 +4,9 @@ rule: namespace: linking/runtime-linking authors: - moritz.raabe@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires offset features att&ck: - Execution::Shared Modules [T1129] references: diff --git a/linking/runtime-linking/link-function-at-runtime-on-windows.yml b/linking/runtime-linking/link-function-at-runtime-on-windows.yml index fabedd42..58846573 100644 --- a/linking/runtime-linking/link-function-at-runtime-on-windows.yml +++ b/linking/runtime-linking/link-function-at-runtime-on-windows.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features att&ck: - Execution::Shared Modules [T1129] examples: diff --git a/linking/runtime-linking/link-many-functions-at-runtime.yml b/linking/runtime-linking/link-many-functions-at-runtime.yml index b5b76591..2e14ff7f 100644 --- a/linking/runtime-linking/link-many-functions-at-runtime.yml +++ b/linking/runtime-linking/link-many-functions-at-runtime.yml @@ -5,7 +5,9 @@ rule: authors: - moritz.raabe@mandiant.com - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Execution::Shared Modules [T1129] examples: diff --git a/linking/runtime-linking/resolve-function-by-brute-ratel-badger-hash.yml b/linking/runtime-linking/resolve-function-by-brute-ratel-badger-hash.yml index f7a79c99..e55293a6 100644 --- a/linking/runtime-linking/resolve-function-by-brute-ratel-badger-hash.yml +++ b/linking/runtime-linking/resolve-function-by-brute-ratel-badger-hash.yml @@ -5,7 +5,9 @@ rule: authors: - jakub.jozwiak@mandiant.com description: Custom API hashing algorithm used in Brute Ratel Badger (version 1.3 or higher) - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Defense Evasion::Obfuscated Files or Information::Dynamic API Resolution [T1027.007] mbc: diff --git a/linking/runtime-linking/resolve-function-by-fin8-fasthash.yml b/linking/runtime-linking/resolve-function-by-fin8-fasthash.yml index 6b9a3a71..a181ce87 100644 --- a/linking/runtime-linking/resolve-function-by-fin8-fasthash.yml +++ b/linking/runtime-linking/resolve-function-by-fin8-fasthash.yml @@ -5,7 +5,9 @@ rule: authors: - "@r3c0nst (Frank Boldewin)" description: APIHashing algorithm derived from a fasthash implementation in OpenCPN using seeds - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Cryptography::Cryptographic Hash [C0029] references: diff --git a/linking/static/aplib/linked-against-aplib.yml b/linking/static/aplib/linked-against-aplib.yml index 481c8c2a..c0198168 100644 --- a/linking/static/aplib/linked-against-aplib.yml +++ b/linking/static/aplib/linked-against-aplib.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/aplib authors: - still@teamt5.org - scope: file + scopes: + static: file + dynamic: file mbc: - Data::Compression Library [C0060] examples: diff --git a/linking/static/cryptopp/linked-against-crypto.yml b/linking/static/cryptopp/linked-against-crypto.yml index 3e021972..9de6aada 100644 --- a/linking/static/cryptopp/linked-against-crypto.yml +++ b/linking/static/cryptopp/linked-against-crypto.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/cryptopp authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Cryptography::Crypto Library [C0059] examples: diff --git a/linking/static/libcurl/linked-against-libcurl.yml b/linking/static/libcurl/linked-against-libcurl.yml index d6dcbaca..6f1bfc0a 100644 --- a/linking/static/libcurl/linked-against-libcurl.yml +++ b/linking/static/libcurl/linked-against-libcurl.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/libcurl authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - A90E5B3454AA71D9700B2EA54615F44B features: diff --git a/linking/static/linked-against-cpp-standard-library.yml b/linking/static/linked-against-cpp-standard-library.yml index e7682397..cb889b5a 100644 --- a/linking/static/linked-against-cpp-standard-library.yml +++ b/linking/static/linked-against-cpp-standard-library.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static authors: - "@mr-tz" - scope: file + scopes: + static: file + dynamic: file references: - https://en.wikipedia.org/wiki/P._J._Plauger - https://www.dinkumware.com/ diff --git a/linking/static/msdetours/linked-against-microsoft-detours.yml b/linking/static/msdetours/linked-against-microsoft-detours.yml index 7b3fee0d..41b7ae5f 100644 --- a/linking/static/msdetours/linked-against-microsoft-detours.yml +++ b/linking/static/msdetours/linked-against-microsoft-detours.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/msdetours authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Hijack Execution Flow [T1574] references: diff --git a/linking/static/openssl/linked-against-openssl.yml b/linking/static/openssl/linked-against-openssl.yml index 49519126..4f49aea8 100644 --- a/linking/static/openssl/linked-against-openssl.yml +++ b/linking/static/openssl/linked-against-openssl.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Cryptography::Crypto Library [C0059] examples: diff --git a/linking/static/polarssl/linked-against-polarsslmbed-tls.yml b/linking/static/polarssl/linked-against-polarsslmbed-tls.yml index 6d2fa7e1..59e0fb72 100644 --- a/linking/static/polarssl/linked-against-polarsslmbed-tls.yml +++ b/linking/static/polarssl/linked-against-polarsslmbed-tls.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/polarssl authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Cryptography::Crypto Library [C0059] examples: diff --git a/linking/static/sqlite3/linked-against-cppsqlite3.yml b/linking/static/sqlite3/linked-against-cppsqlite3.yml index 43d3c5f6..4ecd5860 100644 --- a/linking/static/sqlite3/linked-against-cppsqlite3.yml +++ b/linking/static/sqlite3/linked-against-cppsqlite3.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/sqlite3 authors: - still@teamt5.org - scope: file + scopes: + static: file + dynamic: file examples: - 253309d8b3675d3cc61d4bf23aa15d4b features: diff --git a/linking/static/sqlite3/linked-against-sqlite3.yml b/linking/static/sqlite3/linked-against-sqlite3.yml index ee20789b..71512cf7 100644 --- a/linking/static/sqlite3/linked-against-sqlite3.yml +++ b/linking/static/sqlite3/linked-against-sqlite3.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/sqlite3 authors: - still@teamt5.org - scope: file + scopes: + static: file + dynamic: file examples: - 253309d8b3675d3cc61d4bf23aa15d4b features: diff --git a/linking/static/wolfcrypt/linked-against-wolfcrypt.yml b/linking/static/wolfcrypt/linked-against-wolfcrypt.yml index fb869029..c5b84f04 100644 --- a/linking/static/wolfcrypt/linked-against-wolfcrypt.yml +++ b/linking/static/wolfcrypt/linked-against-wolfcrypt.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/wolfcrypt authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Cryptography::Crypto Library [C0059] references: diff --git a/linking/static/wolfssl/linked-against-wolfssl.yml b/linking/static/wolfssl/linked-against-wolfssl.yml index f520af08..b27f0495 100644 --- a/linking/static/wolfssl/linked-against-wolfssl.yml +++ b/linking/static/wolfssl/linked-against-wolfssl.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/wolfssl authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Cryptography::Crypto Library [C0059] references: diff --git a/linking/static/zlib/linked-against-zlib.yml b/linking/static/zlib/linked-against-zlib.yml index 072a489b..e4a0ce80 100644 --- a/linking/static/zlib/linked-against-zlib.yml +++ b/linking/static/zlib/linked-against-zlib.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/zlib authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Data::Compression Library [C0060] examples: diff --git a/load-code/dotnet/load-windows-common-language-runtime.yml b/load-code/dotnet/load-windows-common-language-runtime.yml index de821ea1..2dae108e 100644 --- a/load-code/dotnet/load-windows-common-language-runtime.yml +++ b/load-code/dotnet/load-windows-common-language-runtime.yml @@ -7,7 +7,9 @@ rule: - michael.hunhoff@mandiant.com - blas.kojusner@mandiant.com - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead references: - https://modexp.wordpress.com/2019/05/10/dotnet-loader-shellcode/ - https://github.com/TheWover/donut/blob/master/loader/inmem_dotnet.c diff --git a/load-code/execute-vbscript-javascript-or-jscript-in-memory.yml b/load-code/execute-vbscript-javascript-or-jscript-in-memory.yml index 0c157efb..52640f99 100644 --- a/load-code/execute-vbscript-javascript-or-jscript-in-memory.yml +++ b/load-code/execute-vbscript-javascript-or-jscript-in-memory.yml @@ -6,7 +6,9 @@ rule: authors: - blas.kojusner@mandiant.com description: the sample may execute 32-bit VBScript, JavaScript, or JScript (32-bit) - scope: function + scopes: + static: function + dynamic: unsupported # requires operand[0].number, bytes, operand[1].offset features references: - https://gist.github.com/odzhan/d18145b9538a3653be2f9a580b53b063 examples: diff --git a/load-code/pe/access-pe-header.yml b/load-code/pe/access-pe-header.yml index 25976dad..926024df 100644 --- a/load-code/pe/access-pe-header.yml +++ b/load-code/pe/access-pe-header.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/pe authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Shared Modules [T1129] examples: diff --git a/load-code/pe/enumerate-pe-sections.yml b/load-code/pe/enumerate-pe-sections.yml index f9cc1eb0..d2d4c2f4 100644 --- a/load-code/pe/enumerate-pe-sections.yml +++ b/load-code/pe/enumerate-pe-sections.yml @@ -5,7 +5,9 @@ rule: authors: - "@Ana06" - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, Not, operand[1].offset, characteristic, mnemonic, basicblock features mbc: - Discovery::Code Discovery::Enumerate PE Sections [B0046.001] references: diff --git a/load-code/pe/inject-dll-reflectively.yml b/load-code/pe/inject-dll-reflectively.yml index 210a16d6..04160ab1 100644 --- a/load-code/pe/inject-dll-reflectively.yml +++ b/load-code/pe/inject-dll-reflectively.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/pe authors: - "@Ana06" - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, offset features att&ck: - Defense Evasion::Process Injection::Dynamic-link Library Injection [T1055.001] - Defense Evasion::Reflective Code Loading [T1620] diff --git a/load-code/pe/inspect-section-memory-permissions.yml b/load-code/pe/inspect-section-memory-permissions.yml index 499d334d..1c5383ad 100644 --- a/load-code/pe/inspect-section-memory-permissions.yml +++ b/load-code/pe/inspect-section-memory-permissions.yml @@ -5,7 +5,9 @@ rule: authors: - "@Ana06" description: "translate section memory permissions (specified in the 'Characteristics' field of the image section header) into page protection constants" - scope: function + scopes: + static: function + dynamic: thread mbc: - Discovery::Code Discovery::Inspect Section Memory Permissions [B0046.002] examples: diff --git a/load-code/pe/parse-pe-header.yml b/load-code/pe/parse-pe-header.yml index 5820c0a3..20dc691b 100644 --- a/load-code/pe/parse-pe-header.yml +++ b/load-code/pe/parse-pe-header.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/pe authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic, operand[1].offset features att&ck: - Execution::Shared Modules [T1129] examples: diff --git a/load-code/pe/rebuild-import-table.yml b/load-code/pe/rebuild-import-table.yml index 93782a13..8dd4eae1 100644 --- a/load-code/pe/rebuild-import-table.yml +++ b/load-code/pe/rebuild-import-table.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/pe authors: - "@Ana06" - scope: function + scopes: + static: function + dynamic: unsupported # requires offset features mbc: - Defense Evasion::Hijack Execution Flow::Import Address Table Hooking [F0015.003] references: diff --git a/load-code/pe/resolve-function-by-parsing-pe-exports.yml b/load-code/pe/resolve-function-by-parsing-pe-exports.yml index f5b15bf7..a3297849 100755 --- a/load-code/pe/resolve-function-by-parsing-pe-exports.yml +++ b/load-code/pe/resolve-function-by-parsing-pe-exports.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/pe authors: - sara-rn - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, offset, mnemonic features examples: - 73CE04892E5F39EC82B00C02FC04C70F:0x406BA1 features: diff --git a/load-code/powershell/run-powershell-expression.yml b/load-code/powershell/run-powershell-expression.yml index 00d86d98..1c35b86d 100644 --- a/load-code/powershell/run-powershell-expression.yml +++ b/load-code/powershell/run-powershell-expression.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/powershell/ authors: - anamaria.martinezgom@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Command and Scripting Interpreter::PowerShell [T1059.001] mbc: diff --git a/load-code/shellcode/execute-shellcode-via-copyfile2.yml b/load-code/shellcode/execute-shellcode-via-copyfile2.yml index ffd16299..023c4958 100644 --- a/load-code/shellcode/execute-shellcode-via-copyfile2.yml +++ b/load-code/shellcode/execute-shellcode-via-copyfile2.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/shellcode authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://github.com/S4R1N/AlternativeShellcodeExec/blob/master/CopyFile2/CopyFile2.cpp examples: diff --git a/load-code/shellcode/execute-shellcode-via-createthreadpoolwait.yml b/load-code/shellcode/execute-shellcode-via-createthreadpoolwait.yml index 063c5249..70006b7d 100644 --- a/load-code/shellcode/execute-shellcode-via-createthreadpoolwait.yml +++ b/load-code/shellcode/execute-shellcode-via-createthreadpoolwait.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/shellcode authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://github.com/S4R1N/AlternativeShellcodeExec/blob/master/CreateThreadPoolWait/CreateThreadPoolWait.cpp examples: diff --git a/load-code/shellcode/execute-shellcode-via-windows-callback-function.yml b/load-code/shellcode/execute-shellcode-via-windows-callback-function.yml index bd012419..108db0b3 100644 --- a/load-code/shellcode/execute-shellcode-via-windows-callback-function.yml +++ b/load-code/shellcode/execute-shellcode-via-windows-callback-function.yml @@ -6,7 +6,9 @@ rule: - ervin.ocampo@mandiant.com - jakub.jozwiak@mandiant.com description: Detect usage of various WinAPI functions that accept callback functions as parameters in order to execute arbitrary shellcode - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Reflective Code Loading [T1620] mbc: diff --git a/load-code/shellcode/execute-shellcode-via-windows-fibers.yml b/load-code/shellcode/execute-shellcode-via-windows-fibers.yml index 7ff68d7d..5dbb1f4c 100644 --- a/load-code/shellcode/execute-shellcode-via-windows-fibers.yml +++ b/load-code/shellcode/execute-shellcode-via-windows-fibers.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/shellcode authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Defense Evasion::Process Injection::Injection via Windows Fibers [E1055.m05] references: diff --git a/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml b/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml index 3bdd878b..d165499a 100644 --- a/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml +++ b/load-code/shellcode/spawn-thread-to-rwx-shellcode.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/shellcode authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread mbc: - Memory::Allocate Memory [C0007] - Process::Create Thread [C0038] diff --git a/malware-family/plugx/match-known-plugx-module.yml b/malware-family/plugx/match-known-plugx-module.yml index 27808736..a0acd251 100644 --- a/malware-family/plugx/match-known-plugx-module.yml +++ b/malware-family/plugx/match-known-plugx-module.yml @@ -6,7 +6,9 @@ rule: authors: - still@teamt5.org description: the sample references known PlugX watermarks (hexified YYYYMMDD + command opcode) - scope: basic block + scopes: + static: function + dynamic: thread references: - https://circl.lu/assets/files/tr-12/tr-12-circl-plugx-analysis-v1.pdf - https://www.fireeye.com/blog/threat-research/2014/07/pacific-ring-of-fire-plugx-kaba.html diff --git a/nursery/access-wmi-data-in-dotnet.yml b/nursery/access-wmi-data-in-dotnet.yml index 589a18b0..1ea66ad5 100644 --- a/nursery/access-wmi-data-in-dotnet.yml +++ b/nursery/access-wmi-data-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/wmi authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Windows Management Instrumentation [T1047] features: diff --git a/nursery/add-file-to-cabinet-file.yml b/nursery/add-file-to-cabinet-file.yml index 5988a518..aafd5c23 100644 --- a/nursery/add-file-to-cabinet-file.yml +++ b/nursery/add-file-to-cabinet-file.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call references: - https://docs.microsoft.com/en-us/windows/win32/msi/cabinet-files features: diff --git a/nursery/add-user-account-group.yml b/nursery/add-user-account-group.yml index 3e2da64b..cd994eeb 100644 --- a/nursery/add-user-account-group.yml +++ b/nursery/add-user-account-group.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Account Manipulation [T1098] features: diff --git a/nursery/add-user-account-to-group.yml b/nursery/add-user-account-to-group.yml index 22082075..e3f1bf24 100644 --- a/nursery/add-user-account-to-group.yml +++ b/nursery/add-user-account-to-group.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Account Manipulation [T1098] features: diff --git a/nursery/add-user-account.yml b/nursery/add-user-account.yml index a1941a4e..75ddd15f 100644 --- a/nursery/add-user-account.yml +++ b/nursery/add-user-account.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Create Account [T1136] features: diff --git a/nursery/add-value-to-global-atom-table.yml b/nursery/add-value-to-global-atom-table.yml index 2cc527b5..9e338a0b 100644 --- a/nursery/add-value-to-global-atom-table.yml +++ b/nursery/add-value-to-global-atom-table.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/inject authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread references: - https://www.fortinet.com/blog/threat-research/atombombing-brand-new-code-injection-technique-for-windows - https://github.com/BreakingMalwareResearch/atom-bombing diff --git a/nursery/allocate-unmanaged-memory-in-dotnet.yml b/nursery/allocate-unmanaged-memory-in-dotnet.yml index fc9042fa..5a0f1c19 100644 --- a/nursery/allocate-unmanaged-memory-in-dotnet.yml +++ b/nursery/allocate-unmanaged-memory-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/memory authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Runtime.InteropServices.Marshal::AllocHGlobal diff --git a/nursery/append-data-to-clfs-log-container.yml b/nursery/append-data-to-clfs-log-container.yml index 10d585e0..07ecd9e5 100755 --- a/nursery/append-data-to-clfs-log-container.yml +++ b/nursery/append-data-to-clfs-log-container.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/log/clfs/append authors: - blaine.stancill@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/windows/win32/api/clfsw32/ - https://github.com/libyal/libfsclfs/blob/main/documenation/Common%20Log%20File%20System%20(CLFS).asciidoc diff --git a/nursery/authenticate-data-with-md5-mac.yml b/nursery/authenticate-data-with-md5-mac.yml index 78766a9f..161c7067 100644 --- a/nursery/authenticate-data-with-md5-mac.yml +++ b/nursery/authenticate-data-with-md5-mac.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/md5 authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features mbc: - Cryptography::Cryptographic Hash::MD5 [C0029.001] references: diff --git a/nursery/build-docker-image.yml b/nursery/build-docker-image.yml index 2a20b4cd..7616ae77 100644 --- a/nursery/build-docker-image.yml +++ b/nursery/build-docker-image.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/container/docker authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Build Image on Host [T1612] references: diff --git a/nursery/bypass-uac-via-scheduled-task-environment-variable.yml b/nursery/bypass-uac-via-scheduled-task-environment-variable.yml index ffe9bdf6..ec31d517 100644 --- a/nursery/bypass-uac-via-scheduled-task-environment-variable.yml +++ b/nursery/bypass-uac-via-scheduled-task-environment-variable.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/uac/bypass authors: - anamaria.martinezgom@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] references: diff --git a/nursery/capture-network-configuration-via-ifconfig.yml b/nursery/capture-network-configuration-via-ifconfig.yml index e6a073cf..42db889c 100644 --- a/nursery/capture-network-configuration-via-ifconfig.yml +++ b/nursery/capture-network-configuration-via-ifconfig.yml @@ -4,7 +4,9 @@ rule: namespace: collection/network authors: - joakim@intezeer.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::System Network Configuration Discovery [T1016] features: diff --git a/nursery/capture-process-snapshot-data.yml b/nursery/capture-process-snapshot-data.yml index 526aa109..17fee289 100644 --- a/nursery/capture-process-snapshot-data.yml +++ b/nursery/capture-process-snapshot-data.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/dump authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: call features: - or: - api: PssCaptureSnapshot diff --git a/nursery/capture-screenshot-in-go.yml b/nursery/capture-screenshot-in-go.yml index 7dca50c9..84fd7d17 100644 --- a/nursery/capture-screenshot-in-go.yml +++ b/nursery/capture-screenshot-in-go.yml @@ -5,7 +5,9 @@ rule: authors: - joakim@intezer.com description: Detects screenshot capability via WinAPI for Go files. - scope: file + scopes: + static: file + dynamic: file att&ck: - Collection::Screen Capture [T1113] mbc: diff --git a/nursery/capture-webcam-video.yml b/nursery/capture-webcam-video.yml index e41a3ad3..5f25248b 100644 --- a/nursery/capture-webcam-video.yml +++ b/nursery/capture-webcam-video.yml @@ -5,7 +5,9 @@ rule: authors: - "@johnk3r" description: Rule that detects a system's webcam being used to capture video - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Collection::Video Capture [T1125] features: diff --git a/nursery/change-user-account-password.yml b/nursery/change-user-account-password.yml index 1de2ea6b..613c92d7 100644 --- a/nursery/change-user-account-password.yml +++ b/nursery/change-user-account-password.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Account Manipulation [T1098] features: diff --git a/nursery/check-clipboard-data.yml b/nursery/check-clipboard-data.yml index b3c00610..5759df25 100644 --- a/nursery/check-clipboard-data.yml +++ b/nursery/check-clipboard-data.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/clipboard authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Collection::Clipboard Data [T1115] features: diff --git a/nursery/check-file-extension-in-dotnet.yml b/nursery/check-file-extension-in-dotnet.yml index 0b9b4811..7941725d 100644 --- a/nursery/check-file-extension-in-dotnet.yml +++ b/nursery/check-file-extension-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.IO.Path::GetExtension diff --git a/nursery/check-for-minimum-number-of-windows-on-screen.yml b/nursery/check-for-minimum-number-of-windows-on-screen.yml index cc986f1b..25d5a879 100644 --- a/nursery/check-for-minimum-number-of-windows-on-screen.yml +++ b/nursery/check-for-minimum-number-of-windows-on-screen.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - echernofsky@google.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] references: diff --git a/nursery/check-for-process-debug-object.yml b/nursery/check-for-process-debug-object.yml index 17d51481..2b1c941a 100644 --- a/nursery/check-for-process-debug-object.yml +++ b/nursery/check-for-process-debug-object.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope mbc: - Anti-Behavioral Analysis::Debugger Detection::NtQueryInformationProcess [B0001.012] references: diff --git a/nursery/check-for-sandbox-via-mac-address-ouis-in-dotnet.yml b/nursery/check-for-sandbox-via-mac-address-ouis-in-dotnet.yml index 20a59382..e18528f9 100644 --- a/nursery/check-for-sandbox-via-mac-address-ouis-in-dotnet.yml +++ b/nursery/check-for-sandbox-via-mac-address-ouis-in-dotnet.yml @@ -5,7 +5,9 @@ rule: authors: - jonathanlepore@google.com description: detects sandbox detection via mac address organizationally unique identifiers (OUIs). Based off publicly available CSharpShooter/CheckPlease.cs - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/nursery/check-for-vm-using-instruction-vpcext.yml b/nursery/check-for-vm-using-instruction-vpcext.yml index 619dd454..a51332e9 100644 --- a/nursery/check-for-vm-using-instruction-vpcext.yml +++ b/nursery/check-for-vm-using-instruction-vpcext.yml @@ -6,7 +6,9 @@ rule: authors: - richard.weiss@mandiant.com description: Detects virtualization using VPCEXT (visual property container extender) instruction. Execution of this instruction will cause an illegal instruction exception outside of a virtual environment otherwise return 0 - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Virtualization/Sandbox Evasion [T1497] mbc: diff --git a/nursery/check-for-windows-sandbox-via-mutex.yml b/nursery/check-for-windows-sandbox-via-mutex.yml index 0e6fe3ac..ea7c20da 100644 --- a/nursery/check-for-windows-sandbox-via-mutex.yml +++ b/nursery/check-for-windows-sandbox-via-mutex.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/nursery/check-for-windows-sandbox-via-subdirectory.yml b/nursery/check-for-windows-sandbox-via-subdirectory.yml index d073f445..6fd4a564 100644 --- a/nursery/check-for-windows-sandbox-via-subdirectory.yml +++ b/nursery/check-for-windows-sandbox-via-subdirectory.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - "echernofsky@google.com" - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/nursery/check-if-directory-exists.yml b/nursery/check-if-directory-exists.yml index 8cc5b3ac..411e277f 100644 --- a/nursery/check-if-directory-exists.yml +++ b/nursery/check-if-directory-exists.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/exists authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::File and Directory Discovery [T1083] features: diff --git a/nursery/check-license-value.yml b/nursery/check-license-value.yml index e6d979ee..bcf84c1e 100644 --- a/nursery/check-license-value.yml +++ b/nursery/check-license-value.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] references: diff --git a/nursery/check-processdebugflags.yml b/nursery/check-processdebugflags.yml index e9989d6d..da33fa7d 100644 --- a/nursery/check-processdebugflags.yml +++ b/nursery/check-processdebugflags.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Anti-Behavioral Analysis::Debugger Detection::NtQueryInformationProcess [B0001.012] references: diff --git a/nursery/check-systemkerneldebuggerinformation.yml b/nursery/check-systemkerneldebuggerinformation.yml index 5d5c7282..6efbce87 100644 --- a/nursery/check-systemkerneldebuggerinformation.yml +++ b/nursery/check-systemkerneldebuggerinformation.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead mbc: - Anti-Behavioral Analysis::Debugger Detection [B0001] references: diff --git a/nursery/check-thread-yield-allowed.yml b/nursery/check-thread-yield-allowed.yml index c13f61a8..2528c6ac 100644 --- a/nursery/check-thread-yield-allowed.yml +++ b/nursery/check-thread-yield-allowed.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging/debugger-detection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features mbc: - Anti-Behavioral Analysis::Debugger Detection::NtYieldExecution/SwitchToThread [B0001.015] references: diff --git a/nursery/clear-clipboard-data.yml b/nursery/clear-clipboard-data.yml index dba3bbbc..2cf49a02 100644 --- a/nursery/clear-clipboard-data.yml +++ b/nursery/clear-clipboard-data.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/clipboard authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Collection::Clipboard Data [T1115] features: diff --git a/nursery/collect-ssh-keys.yml b/nursery/collect-ssh-keys.yml index 0001f929..f388e18f 100644 --- a/nursery/collect-ssh-keys.yml +++ b/nursery/collect-ssh-keys.yml @@ -4,7 +4,9 @@ rule: namespace: collection authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Credential Access::Unsecured Credentials::Private Keys [T1552.004] features: diff --git a/nursery/communicate-with-kernel-module-via-netlink-socket-on-linux.yml b/nursery/communicate-with-kernel-module-via-netlink-socket-on-linux.yml index 1c0b9f1a..76f9cbd9 100644 --- a/nursery/communicate-with-kernel-module-via-netlink-socket-on-linux.yml +++ b/nursery/communicate-with-kernel-module-via-netlink-socket-on-linux.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: Netlink is used to transfer information between the kernel and user-space processes (https://man7.org/linux/man-pages/man7/netlink.7.html) - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - and: - os: linux diff --git a/nursery/compare-security-identifiers.yml b/nursery/compare-security-identifiers.yml index 4da0abd3..31e8aec8 100644 --- a/nursery/compare-security-identifiers.yml +++ b/nursery/compare-security-identifiers.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/sid authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: advapi32.EqualSid diff --git a/nursery/compile-csharp-in-dotnet.yml b/nursery/compile-csharp-in-dotnet.yml index e910bc3a..e9b1ae93 100644 --- a/nursery/compile-csharp-in-dotnet.yml +++ b/nursery/compile-csharp-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/dotnet/csharp authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information::Compile After Delivery [T1027.004] features: diff --git a/nursery/compile-dotnet-assembly.yml b/nursery/compile-dotnet-assembly.yml index c26b5cd9..20ad425c 100644 --- a/nursery/compile-dotnet-assembly.yml +++ b/nursery/compile-dotnet-assembly.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/dotnet authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Obfuscated Files or Information::Compile After Delivery [T1027.004] features: diff --git a/nursery/compile-visual-basic-in-dotnet.yml b/nursery/compile-visual-basic-in-dotnet.yml index 4958676d..d14c489a 100644 --- a/nursery/compile-visual-basic-in-dotnet.yml +++ b/nursery/compile-visual-basic-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/dotnet/vb authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information::Compile After Delivery [T1027.004] features: diff --git a/nursery/compiled-from-epl.yml b/nursery/compiled-from-epl.yml index e9a8f3b9..b3db95f3 100644 --- a/nursery/compiled-from-epl.yml +++ b/nursery/compiled-from-epl.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/epl authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.hexacorn.com/blog/2019/02/13/pe-files-and-the-easy-programming-language-epl/ features: diff --git a/nursery/compiled-with-exescript.yml b/nursery/compiled-with-exescript.yml index 4a50df49..4acb9ddb 100644 --- a/nursery/compiled-with-exescript.yml +++ b/nursery/compiled-with-exescript.yml @@ -4,7 +4,9 @@ rule: namespace: compiler/exescript authors: - jonathanlepore@google.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.hide-folder.com/overview/hf_7.html features: diff --git a/nursery/compress-data-using-gzip-in-dotnet.yml b/nursery/compress-data-using-gzip-in-dotnet.yml index ad9b473a..af27bb18 100644 --- a/nursery/compress-data-using-gzip-in-dotnet.yml +++ b/nursery/compress-data-using-gzip-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/compression authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Collection::Archive Collected Data::Archive via Library [T1560.002] mbc: diff --git a/nursery/connect-network-resource.yml b/nursery/connect-network-resource.yml index d8bf343c..2394a08a 100644 --- a/nursery/connect-network-resource.yml +++ b/nursery/connect-network-resource.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: connect to disk or print resource - scope: function + scopes: + static: function + dynamic: thread features: - and: - or: diff --git a/nursery/contain-a-thread-local-storage-tls-section-in-dotnet.yml b/nursery/contain-a-thread-local-storage-tls-section-in-dotnet.yml index 76bec757..ede0fc8d 100644 --- a/nursery/contain-a-thread-local-storage-tls-section-in-dotnet.yml +++ b/nursery/contain-a-thread-local-storage-tls-section-in-dotnet.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: .NET file contains uncommon TLS section - scope: file + scopes: + static: file + dynamic: file references: - https://washi.dev/blog/posts/entry-points/ features: diff --git a/nursery/covertly-decode-and-write-data-to-windows-directory-using-indirect-calls.yml b/nursery/covertly-decode-and-write-data-to-windows-directory-using-indirect-calls.yml index 03ff6129..20e41ef8 100644 --- a/nursery/covertly-decode-and-write-data-to-windows-directory-using-indirect-calls.yml +++ b/nursery/covertly-decode-and-write-data-to-windows-directory-using-indirect-calls.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/xor authors: - dan.kelly@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/create-container.yml b/nursery/create-container.yml index 52a025f1..8198ff92 100644 --- a/nursery/create-container.yml +++ b/nursery/create-container.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/container/docker authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Execution::Deploy Container [T1610] references: diff --git a/nursery/create-process-via-wmi-in-dotnet.yml b/nursery/create-process-via-wmi-in-dotnet.yml index d03178ec..92d4d776 100644 --- a/nursery/create-process-via-wmi-in-dotnet.yml +++ b/nursery/create-process-via-wmi-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/wmi authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Windows Management Instrumentation [T1047] features: diff --git a/nursery/create-registry-key-via-stdregprov.yml b/nursery/create-registry-key-via-stdregprov.yml index c5b7558d..41d27b5b 100644 --- a/nursery/create-registry-key-via-stdregprov.yml +++ b/nursery/create-registry-key-via-stdregprov.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/previous-versions/windows/desktop/regprov/stdregprov#methods features: diff --git a/nursery/create-restart-manager-session.yml b/nursery/create-restart-manager-session.yml index 434c2e27..3204b777 100644 --- a/nursery/create-restart-manager-session.yml +++ b/nursery/create-restart-manager-session.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: Windows Restart Manager can be used to close/unlock specific files, often abused by Ransomware - scope: function + scopes: + static: function + dynamic: call references: - https://www.carbonblack.com/blog/tau-threat-discovery-conti-ransomware/ features: diff --git a/nursery/create-zip-archive-in-dotnet.yml b/nursery/create-zip-archive-in-dotnet.yml index 3025a14b..e2ab4ca8 100644 --- a/nursery/create-zip-archive-in-dotnet.yml +++ b/nursery/create-zip-archive-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/compression authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead features: - and: - optional: diff --git a/nursery/debug-build.yml b/nursery/debug-build.yml index 020d6f82..e3cd54cf 100644 --- a/nursery/debug-build.yml +++ b/nursery/debug-build.yml @@ -4,7 +4,9 @@ rule: namespace: executable/pe/debug authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file features: - or: - string: "Assertion failed!" diff --git a/nursery/decode-data-using-base64-in-dotnet.yml b/nursery/decode-data-using-base64-in-dotnet.yml index 4037304f..cafc25c2 100644 --- a/nursery/decode-data-using-base64-in-dotnet.yml +++ b/nursery/decode-data-using-base64-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/base64 authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] mbc: diff --git a/nursery/decode-data-using-url-encoding.yml b/nursery/decode-data-using-url-encoding.yml index 87d9e45e..4d9ad47a 100644 --- a/nursery/decode-data-using-url-encoding.yml +++ b/nursery/decode-data-using-url-encoding.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encoding/url authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/decrypt-data-using-rsa.yml b/nursery/decrypt-data-using-rsa.yml index 63e3fde9..9c89b255 100644 --- a/nursery/decrypt-data-using-rsa.yml +++ b/nursery/decrypt-data-using-rsa.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rsa authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] mbc: diff --git a/nursery/decrypt-data-via-sspi.yml b/nursery/decrypt-data-via-sspi.yml index 4d343505..acf79c52 100644 --- a/nursery/decrypt-data-via-sspi.yml +++ b/nursery/decrypt-data-via-sspi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] references: diff --git a/nursery/delete-internet-cache.yml b/nursery/delete-internet-cache.yml index e7e96112..47ac9b54 100644 --- a/nursery/delete-internet-cache.yml +++ b/nursery/delete-internet-cache.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/internet/cache authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - match: enumerate internet cache diff --git a/nursery/delete-registry-key-via-offline-registry-library.yml b/nursery/delete-registry-key-via-offline-registry-library.yml index ce67f0ff..eb5cd820 100644 --- a/nursery/delete-registry-key-via-offline-registry-library.yml +++ b/nursery/delete-registry-key-via-offline-registry-library.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/registry authors: - johnk3r - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Modify Registry [T1112] mbc: diff --git a/nursery/delete-registry-key-via-stdregprov.yml b/nursery/delete-registry-key-via-stdregprov.yml index 93f218fe..2db744a1 100644 --- a/nursery/delete-registry-key-via-stdregprov.yml +++ b/nursery/delete-registry-key-via-stdregprov.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/previous-versions/windows/desktop/regprov/stdregprov#methods features: diff --git a/nursery/delete-registry-value-via-stdregprov.yml b/nursery/delete-registry-value-via-stdregprov.yml index 946da742..3ac76ac5 100644 --- a/nursery/delete-registry-value-via-stdregprov.yml +++ b/nursery/delete-registry-value-via-stdregprov.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/previous-versions/windows/desktop/regprov/stdregprov#methods features: diff --git a/nursery/delete-user-account-from-group.yml b/nursery/delete-user-account-from-group.yml index 6b503871..fbe55d0b 100644 --- a/nursery/delete-user-account-from-group.yml +++ b/nursery/delete-user-account-from-group.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Account Manipulation [T1098] features: diff --git a/nursery/delete-user-account-group.yml b/nursery/delete-user-account-group.yml index 4cec4502..29a88fe3 100644 --- a/nursery/delete-user-account-group.yml +++ b/nursery/delete-user-account-group.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Persistence::Account Manipulation [T1098] features: diff --git a/nursery/delete-user-account.yml b/nursery/delete-user-account.yml index 0c924281..7c7756a8 100644 --- a/nursery/delete-user-account.yml +++ b/nursery/delete-user-account.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Impact::Account Access Removal [T1531] features: diff --git a/nursery/delete-windows-backup-catalog.yml b/nursery/delete-windows-backup-catalog.yml index 96498473..a2b5955e 100644 --- a/nursery/delete-windows-backup-catalog.yml +++ b/nursery/delete-windows-backup-catalog.yml @@ -4,7 +4,9 @@ rule: namespace: impact/inhibit-system-recovery authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Impact::Inhibit System Recovery [T1490] features: diff --git a/nursery/deserialize-json-in-dotnet.yml b/nursery/deserialize-json-in-dotnet.yml index e9f45898..b93e225e 100644 --- a/nursery/deserialize-json-in-dotnet.yml +++ b/nursery/deserialize-json-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/json authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Web.Script.Serialization.JavaScriptSerializer::Deserialize diff --git a/nursery/destroy-software-breakpoint-capability.yml b/nursery/destroy-software-breakpoint-capability.yml index 3a6499bc..dca3106c 100644 --- a/nursery/destroy-software-breakpoint-capability.yml +++ b/nursery/destroy-software-breakpoint-capability.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-debugging authors: - echernofsky@google.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.microsoft.com/en-us/security/blog/2018/03/01/finfisher-exposed-a-researchers-tale-of-defeating-traps-tricks-and-complex-virtual-machines/ - https://anti-debug.checkpoint.com/techniques/assembly.html diff --git a/nursery/disable-automatic-windows-recovery-features.yml b/nursery/disable-automatic-windows-recovery-features.yml index d58513dd..7b09ae60 100644 --- a/nursery/disable-automatic-windows-recovery-features.yml +++ b/nursery/disable-automatic-windows-recovery-features.yml @@ -4,7 +4,9 @@ rule: namespace: impact/inhibit-system-recovery authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Impact::Inhibit System Recovery [T1490] features: diff --git a/nursery/display-service-notification-message-box.yml b/nursery/display-service-notification-message-box.yml index ae3ca40a..7bf65439 100644 --- a/nursery/display-service-notification-message-box.yml +++ b/nursery/display-service-notification-message-box.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - number: 0x200000 = service notification diff --git a/nursery/empty-the-recycle-bin.yml b/nursery/empty-the-recycle-bin.yml index 051486aa..70712af0 100644 --- a/nursery/empty-the-recycle-bin.yml +++ b/nursery/empty-the-recycle-bin.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/recycle-bin authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: SHEmptyRecycleBin diff --git a/nursery/enable-safe-mode-boot.yml b/nursery/enable-safe-mode-boot.yml index 7fea1795..1807ee02 100644 --- a/nursery/enable-safe-mode-boot.yml +++ b/nursery/enable-safe-mode-boot.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/bootloader authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Impair Defenses::Safe Mode Boot [T1562.009] features: diff --git a/nursery/encrypt-data-using-aes-via-x86-extensions.yml b/nursery/encrypt-data-using-aes-via-x86-extensions.yml index 778dfabb..f00a55ce 100644 --- a/nursery/encrypt-data-using-aes-via-x86-extensions.yml +++ b/nursery/encrypt-data-using-aes-via-x86-extensions.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/encrypt-data-using-aes.yml b/nursery/encrypt-data-using-aes.yml index db463bee..9a595b07 100644 --- a/nursery/encrypt-data-using-aes.yml +++ b/nursery/encrypt-data-using-aes.yml @@ -6,7 +6,9 @@ rule: authors: - william.ballenthin@mandiant.com - Ivan Kwiatkowski (@JusticeRage) - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/encrypt-data-using-fakem-cipher.yml b/nursery/encrypt-data-using-fakem-cipher.yml index af5189ef..b859a864 100644 --- a/nursery/encrypt-data-using-fakem-cipher.yml +++ b/nursery/encrypt-data-using-fakem-cipher.yml @@ -6,7 +6,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: Detect custom encryption cipher used by FAKEM malware family - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires characteristic, mnemonic features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/encrypt-data-using-openssl-dsa.yml b/nursery/encrypt-data-using-openssl-dsa.yml index cbb259b8..56f9a253 100644 --- a/nursery/encrypt-data-using-openssl-dsa.yml +++ b/nursery/encrypt-data-using-openssl-dsa.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/dsa authors: - "Ana06" - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features references: - https://github.com/openssl/openssl/blob/fdc5043d58900663b493147298e64f11353b35fe/crypto/objects/obj_dat.h features: diff --git a/nursery/encrypt-data-using-openssl-ecdsa.yml b/nursery/encrypt-data-using-openssl-ecdsa.yml index 141c9a5f..4c944b75 100644 --- a/nursery/encrypt-data-using-openssl-ecdsa.yml +++ b/nursery/encrypt-data-using-openssl-ecdsa.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/ecdsa authors: - "Ana06" - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features references: - https://github.com/openssl/openssl/blob/fdc5043d58900663b493147298e64f11353b35fe/crypto/objects/obj_dat.h features: diff --git a/nursery/encrypt-data-using-openssl-rsa.yml b/nursery/encrypt-data-using-openssl-rsa.yml index 9821861a..07f8d742 100644 --- a/nursery/encrypt-data-using-openssl-rsa.yml +++ b/nursery/encrypt-data-using-openssl-rsa.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rsa authors: - "Ana06" - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features mbc: - Cryptography::Encrypt Data::RSA [C0027.011] references: diff --git a/nursery/encrypt-data-using-rc4-via-systemfunction032.yml b/nursery/encrypt-data-using-rc4-via-systemfunction032.yml index ffa79dd0..5339b2fa 100644 --- a/nursery/encrypt-data-using-rc4-via-systemfunction032.yml +++ b/nursery/encrypt-data-using-rc4-via-systemfunction032.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rc4 authors: - richard.weiss@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/encrypt-data-using-rsa.yml b/nursery/encrypt-data-using-rsa.yml index 39d06b37..a54e898a 100644 --- a/nursery/encrypt-data-using-rsa.yml +++ b/nursery/encrypt-data-using-rsa.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/rsa authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/encrypt-data-using-salsa20-or-chacha.yml b/nursery/encrypt-data-using-salsa20-or-chacha.yml index 44df19d4..09322591 100644 --- a/nursery/encrypt-data-using-salsa20-or-chacha.yml +++ b/nursery/encrypt-data-using-salsa20-or-chacha.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/salsa20 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] references: diff --git a/nursery/encrypt-data-via-sspi.yml b/nursery/encrypt-data-via-sspi.yml index c9dd53d9..74f97995 100644 --- a/nursery/encrypt-data-via-sspi.yml +++ b/nursery/encrypt-data-via-sspi.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] references: diff --git a/nursery/encrypt-or-decrypt-data-via-bcrypt.yml b/nursery/encrypt-or-decrypt-data-via-bcrypt.yml index 635cb53f..02fb47b4 100644 --- a/nursery/encrypt-or-decrypt-data-via-bcrypt.yml +++ b/nursery/encrypt-or-decrypt-data-via-bcrypt.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/enumerate-browser-history.yml b/nursery/enumerate-browser-history.yml index f9044e90..4118baeb 100644 --- a/nursery/enumerate-browser-history.yml +++ b/nursery/enumerate-browser-history.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/browser/history/list authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features features: - and: - api: ole32.CoCreateInstance diff --git a/nursery/enumerate-device-drivers-on-linux.yml b/nursery/enumerate-device-drivers-on-linux.yml index 481f5dd4..c73df788 100644 --- a/nursery/enumerate-device-drivers-on-linux.yml +++ b/nursery/enumerate-device-drivers-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: collection authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Device Driver Discovery [T1652] features: diff --git a/nursery/enumerate-device-drivers-on-windows.yml b/nursery/enumerate-device-drivers-on-windows.yml index ad159db1..2c74149d 100644 --- a/nursery/enumerate-device-drivers-on-windows.yml +++ b/nursery/enumerate-device-drivers-on-windows.yml @@ -4,7 +4,9 @@ rule: namespace: collection authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::Device Driver Discovery [T1652] references: diff --git a/nursery/enumerate-disk-volumes.yml b/nursery/enumerate-disk-volumes.yml index cca3030a..c8c8c085 100644 --- a/nursery/enumerate-disk-volumes.yml +++ b/nursery/enumerate-disk-volumes.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/storage authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] features: diff --git a/nursery/enumerate-drives.yml b/nursery/enumerate-drives.yml index 451f443f..f10e7b63 100644 --- a/nursery/enumerate-drives.yml +++ b/nursery/enumerate-drives.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.IO.DriveInfo::GetDrives diff --git a/nursery/enumerate-internet-cache.yml b/nursery/enumerate-internet-cache.yml index c9d22bb2..759366dd 100644 --- a/nursery/enumerate-internet-cache.yml +++ b/nursery/enumerate-internet-cache.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/internet/cache authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - api: wininet.FindFirstUrlCacheEntry diff --git a/nursery/enumerate-network-shares.yml b/nursery/enumerate-network-shares.yml index bb06b367..25f5e92b 100644 --- a/nursery/enumerate-network-shares.yml +++ b/nursery/enumerate-network-shares.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/network authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::Network Share Discovery [T1135] features: diff --git a/nursery/enumerate-pe-sections-in-dotnet.yml b/nursery/enumerate-pe-sections-in-dotnet.yml index bd5becad..a03750bd 100644 --- a/nursery/enumerate-pe-sections-in-dotnet.yml +++ b/nursery/enumerate-pe-sections-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/pe authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires property features mbc: - Discovery::Code Discovery::Enumerate PE Sections [B0046.001] features: diff --git a/nursery/enumerate-processes-that-use-resource.yml b/nursery/enumerate-processes-that-use-resource.yml index 41a3d5cf..4b9f3033 100644 --- a/nursery/enumerate-processes-that-use-resource.yml +++ b/nursery/enumerate-processes-that-use-resource.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - "@Ana06" - scope: function + scopes: + static: function + dynamic: thread references: - https://www.malwarebytes.com/blog/threat-intelligence/2021/07/avoslocker-enters-the-ransomware-scene-asks-for-partners # examples: diff --git a/nursery/enumerate-processes-via-procfs.yml b/nursery/enumerate-processes-via-procfs.yml index fe738045..91f9e8ba 100644 --- a/nursery/enumerate-processes-via-procfs.yml +++ b/nursery/enumerate-processes-via-procfs.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/list authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::Process Discovery [T1057] - Discovery::Software Discovery [T1518] diff --git a/nursery/enumerate-system-firmware-tables.yml b/nursery/enumerate-system-firmware-tables.yml index 414592e9..9d6b41be 100644 --- a/nursery/enumerate-system-firmware-tables.yml +++ b/nursery/enumerate-system-firmware-tables.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/firmware authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call references: - https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/Shared/Utils.cpp#L843 features: diff --git a/nursery/execute-dotnet-assembly.yml b/nursery/execute-dotnet-assembly.yml index 9c10ded2..44b6e3d5 100644 --- a/nursery/execute-dotnet-assembly.yml +++ b/nursery/execute-dotnet-assembly.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/dotnet authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Reflective Code Loading [T1620] features: diff --git a/nursery/execute-shell-command-via-windows-remote-management.yml b/nursery/execute-shell-command-via-windows-remote-management.yml index 8f69608a..b5281be3 100644 --- a/nursery/execute-shell-command-via-windows-remote-management.yml +++ b/nursery/execute-shell-command-via-windows-remote-management.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/process/create authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - or: diff --git a/nursery/execute-shellcode-via-indirect-call.yml b/nursery/execute-shellcode-via-indirect-call.yml index b2a39fe2..818dd7cd 100644 --- a/nursery/execute-shellcode-via-indirect-call.yml +++ b/nursery/execute-shellcode-via-indirect-call.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/shellcode authors: - ronnie.salomonsen@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features mbc: - Memory::Allocate Memory [C0007] features: diff --git a/nursery/execute-sqlite-statement-in-dotnet.yml b/nursery/execute-sqlite-statement-in-dotnet.yml index 02263b3c..72533ea8 100644 --- a/nursery/execute-sqlite-statement-in-dotnet.yml +++ b/nursery/execute-sqlite-statement-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/database/sql authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - or: diff --git a/nursery/execute-syscall-instruction.yml b/nursery/execute-syscall-instruction.yml index cba27d2c..fa284e5d 100644 --- a/nursery/execute-syscall-instruction.yml +++ b/nursery/execute-syscall-instruction.yml @@ -6,7 +6,9 @@ rule: - "@kulinacs" - "@mr-tz" description: may be used to evade hooks or hinder analysis - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features references: - https://github.com/j00ru/windows-syscalls features: diff --git a/nursery/execute-via-asynchronous-task-in-dotnet.yml b/nursery/execute-via-asynchronous-task-in-dotnet.yml index 729b451d..3a7a1cef 100644 --- a/nursery/execute-via-asynchronous-task-in-dotnet.yml +++ b/nursery/execute-via-asynchronous-task-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/thread/task authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Threading.Tasks.Task::ctor diff --git a/nursery/execute-via-timer-in-dotnet.yml b/nursery/execute-via-timer-in-dotnet.yml index 494d98cc..c0c60b66 100644 --- a/nursery/execute-via-timer-in-dotnet.yml +++ b/nursery/execute-via-timer-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/thread/timer authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Threading.Timer::ctor diff --git a/nursery/extract-zip-archive-in-dotnet.yml b/nursery/extract-zip-archive-in-dotnet.yml index ccdefd42..383bc490 100644 --- a/nursery/extract-zip-archive-in-dotnet.yml +++ b/nursery/extract-zip-archive-in-dotnet.yml @@ -5,7 +5,9 @@ rule: authors: - anushka.virgaonkar@mandiant.com - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Deobfuscate/Decode Files or Information [T1140] features: diff --git a/nursery/find-data-using-regex-in-dotnet.yml b/nursery/find-data-using-regex-in-dotnet.yml index 7345f166..8fd2619b 100644 --- a/nursery/find-data-using-regex-in-dotnet.yml +++ b/nursery/find-data-using-regex-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/regex authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Text.RegularExpressions.Regex::Matches diff --git a/nursery/find-process-by-name.yml b/nursery/find-process-by-name.yml index a6f6ddee..b92ea116 100644 --- a/nursery/find-process-by-name.yml +++ b/nursery/find-process-by-name.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/list authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::Process Discovery [T1057] features: diff --git a/nursery/flush-cabinet-file.yml b/nursery/flush-cabinet-file.yml index b75ec4f6..26182c06 100644 --- a/nursery/flush-cabinet-file.yml +++ b/nursery/flush-cabinet-file.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call references: - https://docs.microsoft.com/en-us/windows/win32/msi/cabinet-files features: diff --git a/nursery/generate-method-via-reflection-in-dotnet.yml b/nursery/generate-method-via-reflection-in-dotnet.yml index 7eb4e893..47bfd90a 100644 --- a/nursery/generate-method-via-reflection-in-dotnet.yml +++ b/nursery/generate-method-via-reflection-in-dotnet.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: https://github.com/bohops/DynamicDotNet/blob/main/assembly_loader/DynamicAssemblyLoader.cs - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Reflection.Emit.DynamicMethod::ctor diff --git a/nursery/generate-random-bytes-in-dotnet.yml b/nursery/generate-random-bytes-in-dotnet.yml index 02788ba1..49ef0492 100644 --- a/nursery/generate-random-bytes-in-dotnet.yml +++ b/nursery/generate-random-bytes-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/prng authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003] features: diff --git a/nursery/generate-random-filename-in-dotnet.yml b/nursery/generate-random-filename-in-dotnet.yml index 6d81c837..8bf08afd 100644 --- a/nursery/generate-random-filename-in-dotnet.yml +++ b/nursery/generate-random-filename-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.IO.Path::GetRandomFileName diff --git a/nursery/generate-random-numbers-in-dotnet.yml b/nursery/generate-random-numbers-in-dotnet.yml index 732ccf70..564d85b4 100644 --- a/nursery/generate-random-numbers-in-dotnet.yml +++ b/nursery/generate-random-numbers-in-dotnet.yml @@ -5,7 +5,9 @@ rule: authors: - anushka.virgaonkar@mandiant.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003] features: diff --git a/nursery/generate-random-numbers-using-the-delphi-lcg.yml b/nursery/generate-random-numbers-using-the-delphi-lcg.yml index 75ae1fd6..0822f01a 100644 --- a/nursery/generate-random-numbers-using-the-delphi-lcg.yml +++ b/nursery/generate-random-numbers-using-the-delphi-lcg.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/prng/lcg authors: - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features mbc: - Cryptography::Generate Pseudo-random Sequence [C0021] references: diff --git a/nursery/get-client-handle-via-schannel.yml b/nursery/get-client-handle-via-schannel.yml index b90b27c7..e51616f2 100644 --- a/nursery/get-client-handle-via-schannel.yml +++ b/nursery/get-client-handle-via-schannel.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] references: diff --git a/nursery/get-current-pid-on-linux.yml b/nursery/get-current-pid-on-linux.yml index 7694d69c..407dba18 100644 --- a/nursery/get-current-pid-on-linux.yml +++ b/nursery/get-current-pid-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead features: - and: - os: linux diff --git a/nursery/get-file-system-information-on-linux.yml b/nursery/get-file-system-information-on-linux.yml index 1893ef42..0e8c1d51 100644 --- a/nursery/get-file-system-information-on-linux.yml +++ b/nursery/get-file-system-information-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead features: - and: - os: linux diff --git a/nursery/get-http-request-uri.yml b/nursery/get-http-request-uri.yml index 1be9fc1f..2cc5d889 100644 --- a/nursery/get-http-request-uri.yml +++ b/nursery/get-http-request-uri.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - william.ballenthin@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead mbc: - Communication::HTTP Communication [C0002] features: diff --git a/nursery/get-inbound-credentials-handle-via-credssp.yml b/nursery/get-inbound-credentials-handle-via-credssp.yml index c948dc8d..7f32cc04 100644 --- a/nursery/get-inbound-credentials-handle-via-credssp.yml +++ b/nursery/get-inbound-credentials-handle-via-credssp.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] references: diff --git a/nursery/get-mac-address-on-linux.yml b/nursery/get-mac-address-on-linux.yml index 93d9b023..daebee53 100644 --- a/nursery/get-mac-address-on-linux.yml +++ b/nursery/get-mac-address-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: collection/network authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Information Discovery [T1082] features: diff --git a/nursery/get-networking-parameters.yml b/nursery/get-networking-parameters.yml index ff45d172..6dbb13cb 100644 --- a/nursery/get-networking-parameters.yml +++ b/nursery/get-networking-parameters.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/network authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Network Configuration Discovery [T1016] features: diff --git a/nursery/get-ntoskrnl-base-address.yml b/nursery/get-ntoskrnl-base-address.yml index 0f2686ab..157d9bc9 100644 --- a/nursery/get-ntoskrnl-base-address.yml +++ b/nursery/get-ntoskrnl-base-address.yml @@ -4,7 +4,9 @@ rule: namespace: linking/runtime-linking authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires offset features att&ck: - Execution::Shared Modules [T1129] references: diff --git a/nursery/get-os-information-via-kuser_shared_data.yml b/nursery/get-os-information-via-kuser_shared_data.yml index c2a690e2..ed0d6f8f 100644 --- a/nursery/get-os-information-via-kuser_shared_data.yml +++ b/nursery/get-os-information-via-kuser_shared_data.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/os/version authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] references: diff --git a/nursery/get-os-version-in-dotnet.yml b/nursery/get-os-version-in-dotnet.yml index fc9f4cf8..eb7b2d02 100644 --- a/nursery/get-os-version-in-dotnet.yml +++ b/nursery/get-os-version-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/os/version authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires property features att&ck: - Discovery::System Information Discovery [T1082] features: diff --git a/nursery/get-password-database-entry-on-linux.yml b/nursery/get-password-database-entry-on-linux.yml index e776243f..ec53699e 100644 --- a/nursery/get-password-database-entry-on-linux.yml +++ b/nursery/get-password-database-entry-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/session authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead features: - and: - os: linux diff --git a/nursery/get-process-image-filename.yml b/nursery/get-process-image-filename.yml index 97a33a93..9b7d2f52 100644 --- a/nursery/get-process-image-filename.yml +++ b/nursery/get-process-image-filename.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead features: - or: - and: diff --git a/nursery/get-proxy.yml b/nursery/get-proxy.yml index a4bb4dfc..cf9d556a 100644 --- a/nursery/get-proxy.yml +++ b/nursery/get-proxy.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/network/proxy authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::System Network Configuration Discovery [T1016] features: diff --git a/nursery/get-remote-cert-context-via-schannel.yml b/nursery/get-remote-cert-context-via-schannel.yml index a45e4fdf..28cd7243 100644 --- a/nursery/get-remote-cert-context-via-schannel.yml +++ b/nursery/get-remote-cert-context-via-schannel.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] references: diff --git a/nursery/get-routing-table.yml b/nursery/get-routing-table.yml index d6302cb7..16314c05 100644 --- a/nursery/get-routing-table.yml +++ b/nursery/get-routing-table.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/network/routing-table authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Network Configuration Discovery [T1016] features: diff --git a/nursery/get-session-information.yml b/nursery/get-session-information.yml index 714bebe7..23d33682 100644 --- a/nursery/get-session-information.yml +++ b/nursery/get-session-information.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/session authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Owner/User Discovery [T1033] features: diff --git a/nursery/get-socket-information.yml b/nursery/get-socket-information.yml index 7e9ad1e1..68ce590c 100644 --- a/nursery/get-socket-information.yml +++ b/nursery/get-socket-information.yml @@ -4,7 +4,9 @@ rule: namespace: communication/socket authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Network Configuration Discovery [T1016] features: diff --git a/nursery/get-storage-device-properties.yml b/nursery/get-storage-device-properties.yml index e95eb85e..dac25951 100644 --- a/nursery/get-storage-device-properties.yml +++ b/nursery/get-storage-device-properties.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/hardware/storage authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead references: - https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-winioctl-ioctl_storage_query_property features: diff --git a/nursery/get-system-firmware-table.yml b/nursery/get-system-firmware-table.yml index 31584390..717a987f 100644 --- a/nursery/get-system-firmware-table.yml +++ b/nursery/get-system-firmware-table.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/firmware authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call references: - https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/Shared/Utils.cpp#L854 features: diff --git a/nursery/get-system-information-on-linux.yml b/nursery/get-system-information-on-linux.yml index dcdf9369..3d829469 100644 --- a/nursery/get-system-information-on-linux.yml +++ b/nursery/get-system-information-on-linux.yml @@ -5,7 +5,9 @@ rule: authors: - joakim@intezer.com - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Information Discovery [T1082] features: diff --git a/nursery/get-system-web-proxy.yml b/nursery/get-system-web-proxy.yml index dae32257..ed6329f9 100644 --- a/nursery/get-system-web-proxy.yml +++ b/nursery/get-system-web-proxy.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Discovery::System Network Configuration Discovery [T1016] references: diff --git a/nursery/get-thread-local-storage-value.yml b/nursery/get-thread-local-storage-value.yml index 20ea67fd..d2c824d4 100644 --- a/nursery/get-thread-local-storage-value.yml +++ b/nursery/get-thread-local-storage-value.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - and: - api: kernel32.TlsGetValue diff --git a/nursery/get-token-privileges.yml b/nursery/get-token-privileges.yml index d1c6c7ea..6029ebd4 100644 --- a/nursery/get-token-privileges.yml +++ b/nursery/get-token-privileges.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/session authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope features: - and: - basic block: diff --git a/nursery/hash-data-using-aphash.yml b/nursery/hash-data-using-aphash.yml index 513577ed..40cca7dc 100644 --- a/nursery/hash-data-using-aphash.yml +++ b/nursery/hash-data-using-aphash.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/aphash authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Data::Non-Cryptographic Hash [C0030] references: diff --git a/nursery/hash-data-using-crc32b.yml b/nursery/hash-data-using-crc32b.yml index b39e8c44..1bd8e147 100644 --- a/nursery/hash-data-using-crc32b.yml +++ b/nursery/hash-data-using-crc32b.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/checksum/crc32 authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features features: - and: - number: 0x4C11DB7 diff --git a/nursery/hash-data-using-jshash.yml b/nursery/hash-data-using-jshash.yml index ccdd0fb9..e4f9ea50 100644 --- a/nursery/hash-data-using-jshash.yml +++ b/nursery/hash-data-using-jshash.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/jshash authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic, mnemonic features mbc: - Data::Non-Cryptographic Hash [C0030] references: diff --git a/nursery/hash-data-using-md4.yml b/nursery/hash-data-using-md4.yml index ef482ce4..54bc2151 100644 --- a/nursery/hash-data-using-md4.yml +++ b/nursery/hash-data-using-md4.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/md4 authors: - anamaria.martinezgom@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - and: - number: 0x8002 = CALG_MD4 diff --git a/nursery/hash-data-using-murmur2.yml b/nursery/hash-data-using-murmur2.yml index 0cec679a..c13a6545 100644 --- a/nursery/hash-data-using-murmur2.yml +++ b/nursery/hash-data-using-murmur2.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/murmur authors: - william.ballenthin@mandiant.com - scope: instruction + scopes: + static: instruction + dynamic: unsupported # requires mnemonic features references: - https://github.com/abrandoned/murmur2/blob/master/MurmurHash2.c features: diff --git a/nursery/hash-data-using-ripemd128.yml b/nursery/hash-data-using-ripemd128.yml index cd3035fb..74773635 100755 --- a/nursery/hash-data-using-ripemd128.yml +++ b/nursery/hash-data-using-ripemd128.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/ripemd128 authors: - raymond.leong@mandiant.com - scope: file + scopes: + static: file + dynamic: unspecified # TODO upgrade manually, contains subscope references: - https://en.wikipedia.org/wiki/RIPEMD-128 features: diff --git a/nursery/hash-data-using-ripemd256.yml b/nursery/hash-data-using-ripemd256.yml index 5353fb9e..6cc08aaf 100755 --- a/nursery/hash-data-using-ripemd256.yml +++ b/nursery/hash-data-using-ripemd256.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/ripemd256 authors: - raymond.leong@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://en.wikipedia.org/wiki/RIPEMD-256 features: diff --git a/nursery/hash-data-using-ripemd320.yml b/nursery/hash-data-using-ripemd320.yml index 0b537a12..a8fc6f67 100755 --- a/nursery/hash-data-using-ripemd320.yml +++ b/nursery/hash-data-using-ripemd320.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/ripemd320 authors: - raymond.leong@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://en.wikipedia.org/wiki/RIPEMD-320 features: diff --git a/nursery/hash-data-using-rshash.yml b/nursery/hash-data-using-rshash.yml index a8da14a3..7afc52f4 100644 --- a/nursery/hash-data-using-rshash.yml +++ b/nursery/hash-data-using-rshash.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/rshash authors: - "@_re_fox" - scope: function + scopes: + static: function + dynamic: unsupported # requires characteristic features mbc: - Data::Non-Cryptographic Hash [C0030] references: diff --git a/nursery/hash-data-using-sha1-via-wincrypt.yml b/nursery/hash-data-using-sha1-via-wincrypt.yml index 7df3f5b0..821a368a 100644 --- a/nursery/hash-data-using-sha1-via-wincrypt.yml +++ b/nursery/hash-data-using-sha1-via-wincrypt.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha1 authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead features: - or: - and: diff --git a/nursery/hash-data-using-sha1-via-x86-extensions.yml b/nursery/hash-data-using-sha1-via-x86-extensions.yml index 34e22fbe..95cb78fb 100644 --- a/nursery/hash-data-using-sha1-via-x86-extensions.yml +++ b/nursery/hash-data-using-sha1-via-x86-extensions.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha1 authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features features: - or: - mnemonic: sha1rnds4 = Perform Four Rounds of SHA1 Operation diff --git a/nursery/hash-data-using-sha256-via-x86-extensions.yml b/nursery/hash-data-using-sha256-via-x86-extensions.yml index 8c6b5045..08cec0f1 100644 --- a/nursery/hash-data-using-sha256-via-x86-extensions.yml +++ b/nursery/hash-data-using-sha256-via-x86-extensions.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha256 authors: - "@_re_fox" - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features features: - or: - mnemonic: sha256rnds2 = Perform Two Rounds of SHA256 Operation diff --git a/nursery/hash-data-using-sha512managed-in-dotnet.yml b/nursery/hash-data-using-sha512managed-in-dotnet.yml index b2fb012b..16886f25 100644 --- a/nursery/hash-data-using-sha512managed-in-dotnet.yml +++ b/nursery/hash-data-using-sha512managed-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/sha512 authors: - jonathanlepore@google.com - scope: function + scopes: + static: function + dynamic: thread references: - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.sha512managed features: diff --git a/nursery/hash-data-using-whirlpool.yml b/nursery/hash-data-using-whirlpool.yml index 22a11905..39072774 100644 --- a/nursery/hash-data-using-whirlpool.yml +++ b/nursery/hash-data-using-whirlpool.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing/whirlpool authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features mbc: - Cryptography::Cryptographic Hash [C0029] references: diff --git a/nursery/hash-data-via-bcrypt.yml b/nursery/hash-data-via-bcrypt.yml index bb87c81e..34e14c97 100644 --- a/nursery/hash-data-via-bcrypt.yml +++ b/nursery/hash-data-via-bcrypt.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/hook-routines-via-microsoft-detours.yml b/nursery/hook-routines-via-microsoft-detours.yml index b00acc30..b9398046 100644 --- a/nursery/hook-routines-via-microsoft-detours.yml +++ b/nursery/hook-routines-via-microsoft-detours.yml @@ -4,7 +4,9 @@ rule: # namespace: linking/hooking authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.fireeye.com/content/dam/fireeye-www/global/en/blog/threat-research/Flare-On%202017/Challenge7.pdf features: diff --git a/nursery/hooked-by-api-override.yml b/nursery/hooked-by-api-override.yml index a7832c0f..24d63b6c 100644 --- a/nursery/hooked-by-api-override.yml +++ b/nursery/hooked-by-api-override.yml @@ -4,7 +4,9 @@ rule: namespace: executable/hooked/api-override authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/ - http://jacquelin.potier.free.fr/winapioverride32/ diff --git a/nursery/impersonate-user.yml b/nursery/impersonate-user.yml index dd9286c3..c6f6f451 100644 --- a/nursery/impersonate-user.yml +++ b/nursery/impersonate-user.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/user authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Privilege Escalation::Access Token Manipulation::Token Impersonation/Theft [T1134.001] features: diff --git a/nursery/implement-com-dll.yml b/nursery/implement-com-dll.yml index 9cf2167b..15bb3452 100644 --- a/nursery/implement-com-dll.yml +++ b/nursery/implement-com-dll.yml @@ -4,7 +4,9 @@ rule: namespace: executable/pe authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features references: - https://learn.microsoft.com/en-us/windows/win32/api/combaseapi/nf-combaseapi-dllgetclassobject features: diff --git a/nursery/initialize-hashing-via-wincrypt.yml b/nursery/initialize-hashing-via-wincrypt.yml index cbd1b389..b5797530 100644 --- a/nursery/initialize-hashing-via-wincrypt.yml +++ b/nursery/initialize-hashing-via-wincrypt.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/hashing authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - api: advapi32.CryptCreateHash diff --git a/nursery/inspect-load-icon-resource.yml b/nursery/inspect-load-icon-resource.yml index afa1ad45..eecd9f1f 100644 --- a/nursery/inspect-load-icon-resource.yml +++ b/nursery/inspect-load-icon-resource.yml @@ -5,7 +5,9 @@ rule: namespace: anti-analysis authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires Not, mnemonic features features: # check if call to LoadIcon fails when first argument is NULL # and second argument is not a valid predefined icon - LoadIcon diff --git a/nursery/interact-with-iptables.yml b/nursery/interact-with-iptables.yml index fefe3475..f60567e8 100644 --- a/nursery/interact-with-iptables.yml +++ b/nursery/interact-with-iptables.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/firewall authors: - joakim@intezer.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Software Discovery::Security Software Discovery [T1518.001] - Defense Evasion::Impair Defenses::Disable or Modify System Firewall [T1562.004] diff --git a/nursery/invoke-dotnet-assembly-method.yml b/nursery/invoke-dotnet-assembly-method.yml index ccee9d26..c33dc398 100644 --- a/nursery/invoke-dotnet-assembly-method.yml +++ b/nursery/invoke-dotnet-assembly-method.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/dotnet authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Reflective Code Loading [T1620] features: diff --git a/nursery/link-function-at-runtime-on-linux.yml b/nursery/link-function-at-runtime-on-linux.yml index db6acb21..62c383a9 100644 --- a/nursery/link-function-at-runtime-on-linux.yml +++ b/nursery/link-function-at-runtime-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: linking/runtime-linking authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Execution::Shared Modules [T1129] features: diff --git a/nursery/linked-against-cpp-http-library.yml b/nursery/linked-against-cpp-http-library.yml index 0f248f14..8a3ca603 100644 --- a/nursery/linked-against-cpp-http-library.yml +++ b/nursery/linked-against-cpp-http-library.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/httplib authors: - "@mr-tz" - scope: file + scopes: + static: file + dynamic: file references: - https://github.com/yhirose/cpp-httplib features: diff --git a/nursery/linked-against-cpp-json-library.yml b/nursery/linked-against-cpp-json-library.yml index 44ed90e7..580373db 100644 --- a/nursery/linked-against-cpp-json-library.yml +++ b/nursery/linked-against-cpp-json-library.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/jsoncpp authors: - "@mr-tz" - scope: file + scopes: + static: file + dynamic: file references: - https://github.com/open-source-parsers/jsoncpp features: diff --git a/nursery/linked-against-cpp-regex-library.yml b/nursery/linked-against-cpp-regex-library.yml index 90748198..9fbea2e2 100644 --- a/nursery/linked-against-cpp-regex-library.yml +++ b/nursery/linked-against-cpp-regex-library.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/cppregex authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - http://www.cplusplus.com/reference/regex/regex_error/ features: diff --git a/nursery/linked-against-go-process-enumeration-library.yml b/nursery/linked-against-go-process-enumeration-library.yml index c50655cb..3a2d54bc 100644 --- a/nursery/linked-against-go-process-enumeration-library.yml +++ b/nursery/linked-against-go-process-enumeration-library.yml @@ -5,7 +5,9 @@ rule: authors: - joakim@intezer.com description: Enumerating processes using a Go library - scope: file + scopes: + static: file + dynamic: file att&ck: - Discovery::Process Discovery [T1057] - Discovery::Software Discovery [T1518] diff --git a/nursery/linked-against-go-registry-library.yml b/nursery/linked-against-go-registry-library.yml index eb7ed878..d79ab7d3 100644 --- a/nursery/linked-against-go-registry-library.yml +++ b/nursery/linked-against-go-registry-library.yml @@ -5,7 +5,9 @@ rule: authors: - joakim@intezer.com description: Uses a Go library for interacting with the Windows registry. - scope: file + scopes: + static: file + dynamic: file references: - https://github.com/golang/sys features: diff --git a/nursery/linked-against-go-static-asset-library.yml b/nursery/linked-against-go-static-asset-library.yml index 060d2ce8..097030db 100644 --- a/nursery/linked-against-go-static-asset-library.yml +++ b/nursery/linked-against-go-static-asset-library.yml @@ -5,7 +5,9 @@ rule: authors: - joakim@intezer.com description: Detects if the Go file includes an static assets. - scope: file + scopes: + static: file + dynamic: file references: - https://github.com/rakyll/statik - https://github.com/gobuffalo/packr diff --git a/nursery/linked-against-go-wmi-library.yml b/nursery/linked-against-go-wmi-library.yml index 1e635c0f..52a869c3 100644 --- a/nursery/linked-against-go-wmi-library.yml +++ b/nursery/linked-against-go-wmi-library.yml @@ -5,7 +5,9 @@ rule: authors: - joakim@intezer.com description: StackExchange's WMI library is used to interact with WMI. - scope: file + scopes: + static: file + dynamic: file att&ck: - Collection::Data from Information Repositories [T1213] references: diff --git a/nursery/linked-against-libsodium.yml b/nursery/linked-against-libsodium.yml index 81b0539b..9782dc64 100644 --- a/nursery/linked-against-libsodium.yml +++ b/nursery/linked-against-libsodium.yml @@ -5,7 +5,9 @@ rule: authors: - "@mr-tz" description: Sodium is a software library for encryption, decryption, signatures, password hashing and more. - scope: file + scopes: + static: file + dynamic: file mbc: - Cryptography::Crypto Library [C0059] features: diff --git a/nursery/linked-against-xzip.yml b/nursery/linked-against-xzip.yml index 1b9b5c66..5d17ae09 100644 --- a/nursery/linked-against-xzip.yml +++ b/nursery/linked-against-xzip.yml @@ -4,7 +4,9 @@ rule: namespace: linking/static/xzip authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file mbc: - Data::Compression Library [C0060] references: diff --git a/nursery/list-containers.yml b/nursery/list-containers.yml index 198beb43..98e11cc4 100644 --- a/nursery/list-containers.yml +++ b/nursery/list-containers.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/container/docker authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Discovery::Container and Resource Discovery [T1613] references: diff --git a/nursery/list-domain-servers.yml b/nursery/list-domain-servers.yml index 73f89366..11030930 100644 --- a/nursery/list-domain-servers.yml +++ b/nursery/list-domain-servers.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/domain authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::System Network Configuration Discovery::Internet Connection Discovery [T1016.001] features: diff --git a/nursery/list-drag-and-drop-files.yml b/nursery/list-drag-and-drop-files.yml index b726f961..f9b0dfe4 100644 --- a/nursery/list-drag-and-drop-files.yml +++ b/nursery/list-drag-and-drop-files.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/clipboard authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Collection::Clipboard Data [T1115] features: diff --git a/nursery/list-groups-for-user-account.yml b/nursery/list-groups-for-user-account.yml index 3e0c06e9..c9c0c0da 100644 --- a/nursery/list-groups-for-user-account.yml +++ b/nursery/list-groups-for-user-account.yml @@ -6,7 +6,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: enumerates all the groups to which a user account belongs - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Account Discovery [T1087] features: diff --git a/nursery/list-tcp-connections-and-listeners.yml b/nursery/list-tcp-connections-and-listeners.yml index 356c2079..04cef09d 100644 --- a/nursery/list-tcp-connections-and-listeners.yml +++ b/nursery/list-tcp-connections-and-listeners.yml @@ -5,7 +5,9 @@ rule: namespace: collection/network authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: iphlpapi.GetExtendedTcpTable diff --git a/nursery/list-udp-connections-and-listeners.yml b/nursery/list-udp-connections-and-listeners.yml index b975e818..20d50cc2 100644 --- a/nursery/list-udp-connections-and-listeners.yml +++ b/nursery/list-udp-connections-and-listeners.yml @@ -5,7 +5,9 @@ rule: namespace: collection/network authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: iphlpapi.GetExtendedUdpTable diff --git a/nursery/list-user-account-groups.yml b/nursery/list-user-account-groups.yml index 3e4040e8..918fedaf 100644 --- a/nursery/list-user-account-groups.yml +++ b/nursery/list-user-account-groups.yml @@ -6,7 +6,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: enumerates all the groups present on the system/domain - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Permission Groups Discovery [T1069] features: diff --git a/nursery/list-user-accounts-for-group.yml b/nursery/list-user-accounts-for-group.yml index 172b6a93..4c76247b 100644 --- a/nursery/list-user-accounts-for-group.yml +++ b/nursery/list-user-accounts-for-group.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Permission Groups Discovery [T1069] features: diff --git a/nursery/list-user-accounts.yml b/nursery/list-user-accounts.yml index 066f2328..ea41e4cd 100644 --- a/nursery/list-user-accounts.yml +++ b/nursery/list-user-accounts.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/accounts authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::Account Discovery [T1087] features: diff --git a/nursery/listen-for-remote-procedure-calls.yml b/nursery/listen-for-remote-procedure-calls.yml index e32f0e88..c5449d2e 100644 --- a/nursery/listen-for-remote-procedure-calls.yml +++ b/nursery/listen-for-remote-procedure-calls.yml @@ -5,7 +5,9 @@ rule: namespace: communication/rpc/server authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: rpcrt4.RpcServerListen diff --git a/nursery/load-dotnet-assembly.yml b/nursery/load-dotnet-assembly.yml index efc65e13..82deea7d 100644 --- a/nursery/load-dotnet-assembly.yml +++ b/nursery/load-dotnet-assembly.yml @@ -4,7 +4,9 @@ rule: namespace: load-code/dotnet authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Defense Evasion::Reflective Code Loading [T1620] features: diff --git a/nursery/load-xml-in-dotnet.yml b/nursery/load-xml-in-dotnet.yml index 5c3e8528..c4e34ccb 100644 --- a/nursery/load-xml-in-dotnet.yml +++ b/nursery/load-xml-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/xml authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Xml.XmlDocument::Load diff --git a/nursery/log-keystrokes-via-input-method-manager.yml b/nursery/log-keystrokes-via-input-method-manager.yml index 0a266d23..ef23de6e 100644 --- a/nursery/log-keystrokes-via-input-method-manager.yml +++ b/nursery/log-keystrokes-via-input-method-manager.yml @@ -5,7 +5,9 @@ rule: namespace: collection/keylog authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: thread features: - and: - or: diff --git a/nursery/log-keystrokes-via-raw-input-data.yml b/nursery/log-keystrokes-via-raw-input-data.yml index 8a98532d..d3508c6e 100644 --- a/nursery/log-keystrokes-via-raw-input-data.yml +++ b/nursery/log-keystrokes-via-raw-input-data.yml @@ -5,7 +5,9 @@ rule: namespace: collection/keylog authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, mnemonic features att&ck: - Collection::Input Capture::Keylogging [T1056.001] features: diff --git a/nursery/make-an-http-request-with-a-cookie.yml b/nursery/make-an-http-request-with-a-cookie.yml index f5f4c83a..3bbd2229 100644 --- a/nursery/make-an-http-request-with-a-cookie.yml +++ b/nursery/make-an-http-request-with-a-cookie.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - anamaria.martinezgom@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead features: - and: - match: send HTTP request diff --git a/nursery/manipulate-console-window.yml b/nursery/manipulate-console-window.yml index 0a272ee6..0f042bdd 100644 --- a/nursery/manipulate-console-window.yml +++ b/nursery/manipulate-console-window.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/console authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call mbc: - Operating System::Console [C0033] features: diff --git a/nursery/manipulate-network-credentials-in-dotnet.yml b/nursery/manipulate-network-credentials-in-dotnet.yml index 38a2df96..b14ca77e 100644 --- a/nursery/manipulate-network-credentials-in-dotnet.yml +++ b/nursery/manipulate-network-credentials-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: communication/authentication authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - and: - api: System.Net.NetworkCredential::ctor diff --git a/nursery/manipulate-unmanaged-memory-in-dotnet.yml b/nursery/manipulate-unmanaged-memory-in-dotnet.yml index a754e369..ab56f4ea 100644 --- a/nursery/manipulate-unmanaged-memory-in-dotnet.yml +++ b/nursery/manipulate-unmanaged-memory-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/memory authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires class features features: - or: - class: System.Runtime.InteropServices.Marshal diff --git a/nursery/manipulate-user-privileges.yml b/nursery/manipulate-user-privileges.yml index d1745f9a..125c5138 100644 --- a/nursery/manipulate-user-privileges.yml +++ b/nursery/manipulate-user-privileges.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/user authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - and: - api: advapi32.LsaAddAccountRights diff --git a/nursery/mark-thread-detached-on-linux.yml b/nursery/mark-thread-detached-on-linux.yml index 3eb0e5f5..2ab087a1 100644 --- a/nursery/mark-thread-detached-on-linux.yml +++ b/nursery/mark-thread-detached-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/thread authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - and: - os: linux diff --git a/nursery/migrate-process-to-active-window-station.yml b/nursery/migrate-process-to-active-window-station.yml index 3c22d61e..541b4a68 100644 --- a/nursery/migrate-process-to-active-window-station.yml +++ b/nursery/migrate-process-to-active-window-station.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com description: set process to the active window station so it can receive GUI events. commonly seen in keyloggers. - scope: function + scopes: + static: function + dynamic: thread references: - https://www.installsetupconfig.com/win32programming/windowstationsdesktops13_1.html - https://brianbondy.com/blog/100/understanding-windows-at-a-deeper-level-sessions-window-stations-and-desktops diff --git a/nursery/mixed-mode.yml b/nursery/mixed-mode.yml index fb328ae8..d0e31b15 100644 --- a/nursery/mixed-mode.yml +++ b/nursery/mixed-mode.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: file contains managed and unmanaged (native) code, often seen in .NET - scope: file + scopes: + static: file + dynamic: unsupported # requires characteristic features features: - or: - characteristic: mixed mode diff --git a/nursery/monitor-clipboard-content.yml b/nursery/monitor-clipboard-content.yml index 7dafdb82..8ff22f39 100644 --- a/nursery/monitor-clipboard-content.yml +++ b/nursery/monitor-clipboard-content.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/clipboard authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Collection::Clipboard Data [T1115] features: diff --git a/nursery/monitor-local-ipv4-address-changes.yml b/nursery/monitor-local-ipv4-address-changes.yml index fdcab2c2..f95169c9 100644 --- a/nursery/monitor-local-ipv4-address-changes.yml +++ b/nursery/monitor-local-ipv4-address-changes.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/network/address authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead att&ck: - Discovery::System Network Configuration Discovery [T1016] features: diff --git a/nursery/move-directory.yml b/nursery/move-directory.yml index 469200c4..45385e19 100644 --- a/nursery/move-directory.yml +++ b/nursery/move-directory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system/move authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.IO.DirectoryInfo::MoveTo diff --git a/nursery/obfuscated-with-koivm.yml b/nursery/obfuscated-with-koivm.yml index bbbe82ed..7e7edb7b 100644 --- a/nursery/obfuscated-with-koivm.yml +++ b/nursery/obfuscated-with-koivm.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/obfuscation authors: - michael.hunhoff@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires namespace, class features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/open-cabinet-file.yml b/nursery/open-cabinet-file.yml index 2ee425ee..1e0ac407 100644 --- a/nursery/open-cabinet-file.yml +++ b/nursery/open-cabinet-file.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call references: - https://docs.microsoft.com/en-us/windows/win32/msi/cabinet-files features: diff --git a/nursery/packaged-as-a-createinstall-installer.yml b/nursery/packaged-as-a-createinstall-installer.yml index 6a4e4af5..e9d13018 100644 --- a/nursery/packaged-as-a-createinstall-installer.yml +++ b/nursery/packaged-as-a-createinstall-installer.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/createinstall authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.createinstall.com/ - https://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/ diff --git a/nursery/packaged-as-a-nsis-installer.yml b/nursery/packaged-as-a-nsis-installer.yml index ed7518dc..825d120b 100644 --- a/nursery/packaged-as-a-nsis-installer.yml +++ b/nursery/packaged-as-a-nsis-installer.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/nsis authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://nsis.sourceforge.io/Main_Page features: diff --git a/nursery/packaged-as-a-pintool.yml b/nursery/packaged-as-a-pintool.yml index 5c890341..8f75ad93 100644 --- a/nursery/packaged-as-a-pintool.yml +++ b/nursery/packaged-as-a-pintool.yml @@ -4,7 +4,9 @@ rule: namespace: executable/pintool authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://software.intel.com/content/www/us/en/develop/articles/pin-a-dynamic-binary-instrumentation-tool.html - https://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/ diff --git a/nursery/packaged-as-a-winzip-self-extracting-archive.yml b/nursery/packaged-as-a-winzip-self-extracting-archive.yml index 1282614d..b3b7313a 100644 --- a/nursery/packaged-as-a-winzip-self-extracting-archive.yml +++ b/nursery/packaged-as-a-winzip-self-extracting-archive.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/winzip authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.hexacorn.com/blog/2016/12/15/pe-section-names-re-visited/ features: diff --git a/nursery/packaged-as-a-wise-installer.yml b/nursery/packaged-as-a-wise-installer.yml index 1faf43be..ff81ba78 100644 --- a/nursery/packaged-as-a-wise-installer.yml +++ b/nursery/packaged-as-a-wise-installer.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/wiseinstall authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file features: - or: - string: "WiseMain" diff --git a/nursery/packaged-as-an-installshield-installer.yml b/nursery/packaged-as-an-installshield-installer.yml index e2cd630f..a3e07e12 100644 --- a/nursery/packaged-as-an-installshield-installer.yml +++ b/nursery/packaged-as-an-installshield-installer.yml @@ -4,7 +4,9 @@ rule: namespace: executable/installer/installshield authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file features: - or: # AppHelp has an export ApphelpCheckInstallShieldPackage, diff --git a/nursery/packed-with-ccg.yml b/nursery/packed-with-ccg.yml index e2e9ef89..553dcb36 100644 --- a/nursery/packed-with-ccg.yml +++ b/nursery/packed-with-ccg.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/ccg authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-crunch.yml b/nursery/packed-with-crunch.yml index 1e53d754..db8391f8 100644 --- a/nursery/packed-with-crunch.yml +++ b/nursery/packed-with-crunch.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/crunch authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-dragon-armor.yml b/nursery/packed-with-dragon-armor.yml index 8999d02f..8794419a 100644 --- a/nursery/packed-with-dragon-armor.yml +++ b/nursery/packed-with-dragon-armor.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/dragon-armor authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-enigma.yml b/nursery/packed-with-enigma.yml index 2428c6dc..026aa523 100644 --- a/nursery/packed-with-enigma.yml +++ b/nursery/packed-with-enigma.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/enigma authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-epack.yml b/nursery/packed-with-epack.yml index b6740954..4ac81187 100644 --- a/nursery/packed-with-epack.yml +++ b/nursery/packed-with-epack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/epack authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-maskpe.yml b/nursery/packed-with-maskpe.yml index 22031915..cbacd782 100644 --- a/nursery/packed-with-maskpe.yml +++ b/nursery/packed-with-maskpe.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/maskpe authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-mew.yml b/nursery/packed-with-mew.yml index c5a180e7..a4fd10a8 100644 --- a/nursery/packed-with-mew.yml +++ b/nursery/packed-with-mew.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/mew authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-mpress.yml b/nursery/packed-with-mpress.yml index f2427db9..0ee836c3 100644 --- a/nursery/packed-with-mpress.yml +++ b/nursery/packed-with-mpress.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/mpress authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-neolite.yml b/nursery/packed-with-neolite.yml index aa707a90..5c468568 100644 --- a/nursery/packed-with-neolite.yml +++ b/nursery/packed-with-neolite.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/neolite authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-pepack.yml b/nursery/packed-with-pepack.yml index 5f7d607d..29a81731 100644 --- a/nursery/packed-with-pepack.yml +++ b/nursery/packed-with-pepack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/pepack authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-perplex.yml b/nursery/packed-with-perplex.yml index bffad089..ed883ddf 100644 --- a/nursery/packed-with-perplex.yml +++ b/nursery/packed-with-perplex.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/perplex authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-procrypt.yml b/nursery/packed-with-procrypt.yml index f843bbbe..2d6e1cf9 100644 --- a/nursery/packed-with-procrypt.yml +++ b/nursery/packed-with-procrypt.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/procrypt authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-rpcrypt.yml b/nursery/packed-with-rpcrypt.yml index fbe023f6..2571e3fe 100644 --- a/nursery/packed-with-rpcrypt.yml +++ b/nursery/packed-with-rpcrypt.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/rpcrypt authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-seausfx.yml b/nursery/packed-with-seausfx.yml index a2fb371b..e11fb96f 100644 --- a/nursery/packed-with-seausfx.yml +++ b/nursery/packed-with-seausfx.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/seausfx authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-shrinker.yml b/nursery/packed-with-shrinker.yml index 00d0c48e..ecd1fca5 100644 --- a/nursery/packed-with-shrinker.yml +++ b/nursery/packed-with-shrinker.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/shrinker authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-simple-pack.yml b/nursery/packed-with-simple-pack.yml index 2c55466f..6fa09cc6 100644 --- a/nursery/packed-with-simple-pack.yml +++ b/nursery/packed-with-simple-pack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/simple-pack authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-starforce.yml b/nursery/packed-with-starforce.yml index 4eccdc8d..3f57a90f 100644 --- a/nursery/packed-with-starforce.yml +++ b/nursery/packed-with-starforce.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/starforce authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-svkp.yml b/nursery/packed-with-svkp.yml index 5630dec5..7af4feda 100644 --- a/nursery/packed-with-svkp.yml +++ b/nursery/packed-with-svkp.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/svkp authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-tsuloader.yml b/nursery/packed-with-tsuloader.yml index 16f17549..289bb3a2 100644 --- a/nursery/packed-with-tsuloader.yml +++ b/nursery/packed-with-tsuloader.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/tsuloader authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-vprotect.yml b/nursery/packed-with-vprotect.yml index 284ba054..5fedd981 100644 --- a/nursery/packed-with-vprotect.yml +++ b/nursery/packed-with-vprotect.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/vprotect authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/packed-with-wwpack.yml b/nursery/packed-with-wwpack.yml index 2228228e..88dd88a4 100644 --- a/nursery/packed-with-wwpack.yml +++ b/nursery/packed-with-wwpack.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/packer/wwpack authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Defense Evasion::Obfuscated Files or Information::Software Packing [T1027.002] mbc: diff --git a/nursery/parse-url.yml b/nursery/parse-url.yml index 4e1577d1..82c81fcf 100644 --- a/nursery/parse-url.yml +++ b/nursery/parse-url.yml @@ -5,7 +5,9 @@ rule: namespace: communication/http authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: wininet.InternetCrackUrl diff --git a/nursery/persist-via-gnome-autostart-on-linux.yml b/nursery/persist-via-gnome-autostart-on-linux.yml index 74f3cc92..80a712f8 100644 --- a/nursery/persist-via-gnome-autostart-on-linux.yml +++ b/nursery/persist-via-gnome-autostart-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: persistence authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead features: - and: - os: linux diff --git a/nursery/power-down-monitor.yml b/nursery/power-down-monitor.yml index 4522e9be..fdcf13ee 100644 --- a/nursery/power-down-monitor.yml +++ b/nursery/power-down-monitor.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/monitor authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - and: - api: user32.SendMessage diff --git a/nursery/prompt-user-for-credentials.yml b/nursery/prompt-user-for-credentials.yml index 7fc786ec..303c4ced 100644 --- a/nursery/prompt-user-for-credentials.yml +++ b/nursery/prompt-user-for-credentials.yml @@ -5,7 +5,9 @@ rule: namespace: collection/credentials authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.ired.team/offensive-security/credential-access-and-credential-dumping/credentials-collection-via-creduipromptforcredentials features: diff --git a/nursery/query-or-enumerate-registry-key-via-stdregprov.yml b/nursery/query-or-enumerate-registry-key-via-stdregprov.yml index 25c1472f..1dc167b9 100644 --- a/nursery/query-or-enumerate-registry-key-via-stdregprov.yml +++ b/nursery/query-or-enumerate-registry-key-via-stdregprov.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/previous-versions/windows/desktop/regprov/stdregprov#methods features: diff --git a/nursery/query-or-enumerate-registry-value-via-stdregprov.yml b/nursery/query-or-enumerate-registry-value-via-stdregprov.yml index 36308468..063f4234 100644 --- a/nursery/query-or-enumerate-registry-value-via-stdregprov.yml +++ b/nursery/query-or-enumerate-registry-value-via-stdregprov.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/previous-versions/windows/desktop/regprov/stdregprov#methods features: diff --git a/nursery/query-remote-server-for-available-data.yml b/nursery/query-remote-server-for-available-data.yml index af757da5..cf98c8bc 100644 --- a/nursery/query-remote-server-for-available-data.yml +++ b/nursery/query-remote-server-for-available-data.yml @@ -5,7 +5,9 @@ rule: namespace: communication authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: wininet.InternetQueryDataAvailable diff --git a/nursery/read-and-send-data-from-client-to-server.yml b/nursery/read-and-send-data-from-client-to-server.yml index 7b2d870b..6d181534 100644 --- a/nursery/read-and-send-data-from-client-to-server.yml +++ b/nursery/read-and-send-data-from-client-to-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/c2/file-transfer authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - match: host-interaction/file-system/read diff --git a/nursery/read-process-memory.yml b/nursery/read-process-memory.yml index 4796d5f5..db460b90 100644 --- a/nursery/read-process-memory.yml +++ b/nursery/read-process-memory.yml @@ -6,7 +6,9 @@ rule: - matthew.williams@mandiant.com - "@_re_fox" - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - api: kernel32.ReadProcessMemory diff --git a/nursery/read-raw-disk-data.yml b/nursery/read-raw-disk-data.yml index 8a4d1a4b..91b92874 100644 --- a/nursery/read-raw-disk-data.yml +++ b/nursery/read-raw-disk-data.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file features: - or: - string: "\\\\.\\PhysicalDrive0" diff --git a/nursery/rebuilt-by-imprec.yml b/nursery/rebuilt-by-imprec.yml index 6afe346a..5fd0b9a0 100644 --- a/nursery/rebuilt-by-imprec.yml +++ b/nursery/rebuilt-by-imprec.yml @@ -4,7 +4,9 @@ rule: namespace: executable/imprec authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.hexacorn.com/blog/2012/10/14/random-stats-from-1-2m-samples-pe-section-names/ features: diff --git a/nursery/receive-and-write-data-from-server-to-client.yml b/nursery/receive-and-write-data-from-server-to-client.yml index 09e72dbb..369dbf19 100644 --- a/nursery/receive-and-write-data-from-server-to-client.yml +++ b/nursery/receive-and-write-data-from-server-to-client.yml @@ -4,7 +4,9 @@ rule: namespace: communication/c2/file-transfer authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - match: receive data diff --git a/nursery/reference-114dns-dns-server.yml b/nursery/reference-114dns-dns-server.yml index 276169dd..c1ac922a 100644 --- a/nursery/reference-114dns-dns-server.yml +++ b/nursery/reference-114dns-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.114dns.com/ - https://www.amazon.com/ask/questions/Tx27CUHKMM403NP diff --git a/nursery/reference-aes-constants.yml b/nursery/reference-aes-constants.yml index f523e98d..3240fb62 100644 --- a/nursery/reference-aes-constants.yml +++ b/nursery/reference-aes-constants.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/encryption/aes authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires bytes features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] features: diff --git a/nursery/reference-alidns-dns-server.yml b/nursery/reference-alidns-dns-server.yml index 45f30f1b..1a35101a 100644 --- a/nursery/reference-alidns-dns-server.yml +++ b/nursery/reference-alidns-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.alidns.com/ # examples: diff --git a/nursery/reference-base58-string.yml b/nursery/reference-base58-string.yml index f1d2e324..60837678 100644 --- a/nursery/reference-base58-string.yml +++ b/nursery/reference-base58-string.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com description: Similar to Base64, but modified to avoid both non-alphanumeric characters (+ and /) and letters that might look ambiguous when printed (0, I, O, and l). Base58 is used to represent bitcoin addresses. - scope: file + scopes: + static: file + dynamic: unsupported # requires features att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: diff --git a/nursery/reference-cloudflare-dns-server.yml b/nursery/reference-cloudflare-dns-server.yml index e3db3800..dd7e512c 100644 --- a/nursery/reference-cloudflare-dns-server.yml +++ b/nursery/reference-cloudflare-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.techradar.com/news/best-dns-server features: diff --git a/nursery/reference-comodo-secure-dns-server.yml b/nursery/reference-comodo-secure-dns-server.yml index af5beb86..b7664ff2 100644 --- a/nursery/reference-comodo-secure-dns-server.yml +++ b/nursery/reference-comodo-secure-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.techradar.com/news/best-dns-server features: diff --git a/nursery/reference-cryptocurrency-strings.yml b/nursery/reference-cryptocurrency-strings.yml index 3d0f2c63..f727819f 100644 --- a/nursery/reference-cryptocurrency-strings.yml +++ b/nursery/reference-cryptocurrency-strings.yml @@ -4,7 +4,9 @@ rule: namespace: impact/cryptocurrency authors: - moritz.raabe@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Impact::Resource Hijacking [T1496] references: diff --git a/nursery/reference-google-public-dns-server.yml b/nursery/reference-google-public-dns-server.yml index ea5d54ea..fccdc8e7 100644 --- a/nursery/reference-google-public-dns-server.yml +++ b/nursery/reference-google-public-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.techradar.com/news/best-dns-server - https://developers.google.com/speed/public-dns/docs/using diff --git a/nursery/reference-hurricane-electric-dns-server.yml b/nursery/reference-hurricane-electric-dns-server.yml index bb772d8a..c90176fe 100644 --- a/nursery/reference-hurricane-electric-dns-server.yml +++ b/nursery/reference-hurricane-electric-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://dns.he.net/ - https://dnslytics.com/ip/216.66.1.2 diff --git a/nursery/reference-kornet-dns-server.yml b/nursery/reference-kornet-dns-server.yml index e02deda0..f08d6b3c 100644 --- a/nursery/reference-kornet-dns-server.yml +++ b/nursery/reference-kornet-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://whatismyipaddress.com/ip/168.126.63.1 # examples: diff --git a/nursery/reference-l3-dns-server.yml b/nursery/reference-l3-dns-server.yml index b570ed36..0a0f1f98 100644 --- a/nursery/reference-l3-dns-server.yml +++ b/nursery/reference-l3-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.quora.com/What-is-a-4-2-2-1-DNS-server features: diff --git a/nursery/reference-opendns-dns-server.yml b/nursery/reference-opendns-dns-server.yml index 02f1449c..128ed617 100644 --- a/nursery/reference-opendns-dns-server.yml +++ b/nursery/reference-opendns-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.techradar.com/news/best-dns-server features: diff --git a/nursery/reference-processor-manufacturer-constants.yml b/nursery/reference-processor-manufacturer-constants.yml index 34aef0c9..1002ba4c 100644 --- a/nursery/reference-processor-manufacturer-constants.yml +++ b/nursery/reference-processor-manufacturer-constants.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/nursery/reference-quad9-dns-server.yml b/nursery/reference-quad9-dns-server.yml index c1b715bc..74188a33 100644 --- a/nursery/reference-quad9-dns-server.yml +++ b/nursery/reference-quad9-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.techradar.com/news/best-dns-server features: diff --git a/nursery/reference-screen-saver-executable.yml b/nursery/reference-screen-saver-executable.yml index 5c3ffe4c..35cd13b0 100644 --- a/nursery/reference-screen-saver-executable.yml +++ b/nursery/reference-screen-saver-executable.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: SCRNSAVE.EXE registry value specifies the name of the screen saver executable file - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Event Triggered Execution::Screensaver [T1546.002] features: diff --git a/nursery/reference-startup-folder.yml b/nursery/reference-startup-folder.yml index bdc762f6..1ea42544 100644 --- a/nursery/reference-startup-folder.yml +++ b/nursery/reference-startup-folder.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/startup-folder authors: - matthew.williams@mandiant.com - scope: file + scopes: + static: file + dynamic: file att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] features: diff --git a/nursery/reference-the-vmware-io-port.yml b/nursery/reference-the-vmware-io-port.yml index 668ee70f..3c111813 100644 --- a/nursery/reference-the-vmware-io-port.yml +++ b/nursery/reference-the-vmware-io-port.yml @@ -4,7 +4,9 @@ rule: namespace: anti-analysis/anti-vm/vm-detection authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features att&ck: - Defense Evasion::Virtualization/Sandbox Evasion::System Checks [T1497.001] mbc: diff --git a/nursery/reference-verisign-dns-server.yml b/nursery/reference-verisign-dns-server.yml index 721abdc2..626ae4b9 100644 --- a/nursery/reference-verisign-dns-server.yml +++ b/nursery/reference-verisign-dns-server.yml @@ -4,7 +4,9 @@ rule: namespace: communication/dns authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.techradar.com/news/best-dns-server features: diff --git a/nursery/register-http-server-url.yml b/nursery/register-http-server-url.yml index 241cff21..7eec08e4 100644 --- a/nursery/register-http-server-url.yml +++ b/nursery/register-http-server-url.yml @@ -5,7 +5,9 @@ rule: namespace: communication/http/server authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: httpapi.HttpAddUrl diff --git a/nursery/register-raw-input-devices.yml b/nursery/register-raw-input-devices.yml index 90dc25fe..ddfed489 100644 --- a/nursery/register-raw-input-devices.yml +++ b/nursery/register-raw-input-devices.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/hardware authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - or: - api: user32.RegisterRawInputDevices diff --git a/nursery/resize-volume-shadow-copy-storage.yml b/nursery/resize-volume-shadow-copy-storage.yml index e22bf7db..13c39075 100644 --- a/nursery/resize-volume-shadow-copy-storage.yml +++ b/nursery/resize-volume-shadow-copy-storage.yml @@ -5,7 +5,9 @@ rule: namespace: impact/inhibit-system-recovery authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - and: - api: kernel32.DeviceIoControl diff --git a/nursery/resolve-function-by-djb2-hash.yml b/nursery/resolve-function-by-djb2-hash.yml index 744e3edf..49d40508 100644 --- a/nursery/resolve-function-by-djb2-hash.yml +++ b/nursery/resolve-function-by-djb2-hash.yml @@ -5,7 +5,9 @@ rule: authors: - still@teamt5.org description: known import name hashes calculated using the non-cryptographic djb2 hashing algorithm - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] mbc: diff --git a/nursery/resolve-function-by-fnv-1a-hash.yml b/nursery/resolve-function-by-fnv-1a-hash.yml index 4973735e..7f323956 100644 --- a/nursery/resolve-function-by-fnv-1a-hash.yml +++ b/nursery/resolve-function-by-fnv-1a-hash.yml @@ -5,7 +5,9 @@ rule: authors: - still@teamt5.org description: known import name hashes calculated using the non-cryptographic FNV-1a hashing algorithm - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] references: diff --git a/nursery/resolve-function-by-hash.yml b/nursery/resolve-function-by-hash.yml index 61bcc2f9..9e84d6a6 100644 --- a/nursery/resolve-function-by-hash.yml +++ b/nursery/resolve-function-by-hash.yml @@ -4,7 +4,9 @@ rule: namespace: linking/runtime-linking authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Defense Evasion::Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] references: diff --git a/nursery/run-in-container.yml b/nursery/run-in-container.yml index 374d4b2c..2f8a096c 100644 --- a/nursery/run-in-container.yml +++ b/nursery/run-in-container.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/container/docker authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Execution::Container Administration Command [T1609] references: diff --git a/nursery/save-image-in-dotnet.yml b/nursery/save-image-in-dotnet.yml index 7cedd61a..b00b38ed 100644 --- a/nursery/save-image-in-dotnet.yml +++ b/nursery/save-image-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: collection authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires class features features: - and: - api: System.Drawing.Image::Save diff --git a/nursery/schedule-task-via-itaskservice.yml b/nursery/schedule-task-via-itaskservice.yml index 09c84745..919ee97c 100644 --- a/nursery/schedule-task-via-itaskservice.yml +++ b/nursery/schedule-task-via-itaskservice.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/scheduled-tasks authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features att&ck: - Persistence::Scheduled Task/Job::Scheduled Task [T1053.005] features: diff --git a/nursery/search-for-credit-card-data.yml b/nursery/search-for-credit-card-data.yml index 1c90a194..6d183270 100644 --- a/nursery/search-for-credit-card-data.yml +++ b/nursery/search-for-credit-card-data.yml @@ -4,7 +4,9 @@ rule: namespace: collection/credit-card authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires mnemonic features features: - and: - instruction: diff --git a/nursery/send-data-to-internet.yml b/nursery/send-data-to-internet.yml index 899ade40..44e1a3a6 100644 --- a/nursery/send-data-to-internet.yml +++ b/nursery/send-data-to-internet.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - optional: diff --git a/nursery/send-email-in-dotnet.yml b/nursery/send-email-in-dotnet.yml index 4576c725..39cba591 100644 --- a/nursery/send-email-in-dotnet.yml +++ b/nursery/send-email-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: communication/smtp/send authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Web.Mail.SmtpMail::Send diff --git a/nursery/send-http-request-with-host-header.yml b/nursery/send-http-request-with-host-header.yml index 4646f893..6a63cbd3 100644 --- a/nursery/send-http-request-with-host-header.yml +++ b/nursery/send-http-request-with-host-header.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - anamaria.martinezgom@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead features: - and: - match: send HTTP request diff --git a/nursery/send-keystrokes.yml b/nursery/send-keystrokes.yml index 0fc5eea3..8d449c4b 100644 --- a/nursery/send-keystrokes.yml +++ b/nursery/send-keystrokes.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/hardware/keyboard authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Windows.Forms.SendKeys::Send diff --git a/nursery/send-request-in-dotnet.yml b/nursery/send-request-in-dotnet.yml index b186b92a..9c66ac39 100644 --- a/nursery/send-request-in-dotnet.yml +++ b/nursery/send-request-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http/client authors: - anushka.virgaonakr@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Command and Control::Application Layer Protocol::Web Protocols [T1071.001] mbc: diff --git a/nursery/send-sms-on-android.yml b/nursery/send-sms-on-android.yml index 82543275..1d47168d 100644 --- a/nursery/send-sms-on-android.yml +++ b/nursery/send-sms-on-android.yml @@ -4,7 +4,9 @@ rule: namespace: communication/sms authors: - "@mr-tz" - scope: function + scopes: + static: function + dynamic: unsupported # requires offset features # att&ck: # - Mobile::SMS Control [T1582] features: diff --git a/nursery/serialize-json-in-dotnet.yml b/nursery/serialize-json-in-dotnet.yml index b23f85ed..930f19a9 100644 --- a/nursery/serialize-json-in-dotnet.yml +++ b/nursery/serialize-json-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: data-manipulation/json authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.Web.Script.Serialization.JavaScriptSerializer::Serialize diff --git a/nursery/set-current-directory.yml b/nursery/set-current-directory.yml index 6102bd4e..d1f55eed 100644 --- a/nursery/set-current-directory.yml +++ b/nursery/set-current-directory.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/file-system authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: call features: - or: - api: System.IO.Directory::SetCurrentDirectory diff --git a/nursery/set-global-application-hook.yml b/nursery/set-global-application-hook.yml index d634231c..c4fe5961 100644 --- a/nursery/set-global-application-hook.yml +++ b/nursery/set-global-application-hook.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/gui authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: call # TODO check if scope thread instead features: - and: - api: user32.SetWindowsHookEx diff --git a/nursery/set-http-cookie.yml b/nursery/set-http-cookie.yml index 91cc5844..66740c19 100644 --- a/nursery/set-http-cookie.yml +++ b/nursery/set-http-cookie.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: call att&ck: - Command and Control::Application Layer Protocol::Web Protocols [T1071.001] references: diff --git a/nursery/set-http-user-agent-in-dotnet.yml b/nursery/set-http-user-agent-in-dotnet.yml index 8634da64..90bb3bae 100644 --- a/nursery/set-http-user-agent-in-dotnet.yml +++ b/nursery/set-http-user-agent-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires property features features: - or: - property/write: System.Net.HttpWebRequest::UserAgent diff --git a/nursery/set-registry-value-via-stdregprov.yml b/nursery/set-registry-value-via-stdregprov.yml index 1f194339..ecc12bb5 100644 --- a/nursery/set-registry-value-via-stdregprov.yml +++ b/nursery/set-registry-value-via-stdregprov.yml @@ -5,7 +5,9 @@ rule: namespace: host-interaction/registry authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://docs.microsoft.com/en-us/previous-versions/windows/desktop/regprov/stdregprov#methods features: diff --git a/nursery/set-thread-name-on-linux.yml b/nursery/set-thread-name-on-linux.yml index 9c9694da..24aebf61 100644 --- a/nursery/set-thread-name-on-linux.yml +++ b/nursery/set-thread-name-on-linux.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/thread authors: - michael.hunhoff@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead features: - and: - os: linux diff --git a/nursery/set-web-proxy-in-dotnet.yml b/nursery/set-web-proxy-in-dotnet.yml index 415c5b60..e0bdc2df 100644 --- a/nursery/set-web-proxy-in-dotnet.yml +++ b/nursery/set-web-proxy-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: communication/http authors: - michael.hunhoff@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires property features features: - and: - property/write: System.Net.WebRequest::Proxy diff --git a/nursery/terminate-process-by-name-in-dotnet.yml b/nursery/terminate-process-by-name-in-dotnet.yml index 4dbeeb16..d54e5029 100644 --- a/nursery/terminate-process-by-name-in-dotnet.yml +++ b/nursery/terminate-process-by-name-in-dotnet.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/terminate authors: - anushka.virgaonkar@mandiant.com - scope: function + scopes: + static: function + dynamic: thread features: - and: - api: System.Diagnostics.Process::GetProcessesByName diff --git a/nursery/terminate-process-by-name.yml b/nursery/terminate-process-by-name.yml index 7b0df849..e7180052 100644 --- a/nursery/terminate-process-by-name.yml +++ b/nursery/terminate-process-by-name.yml @@ -4,7 +4,9 @@ rule: namespace: host-interaction/process/terminate authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset features # examples: # - unpacked Cl0p ransomware features: diff --git a/nursery/unmanaged-call-via-dynamic-pinvoke-in-dotnet.yml b/nursery/unmanaged-call-via-dynamic-pinvoke-in-dotnet.yml index bb317854..2f5426f2 100644 --- a/nursery/unmanaged-call-via-dynamic-pinvoke-in-dotnet.yml +++ b/nursery/unmanaged-call-via-dynamic-pinvoke-in-dotnet.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: https://github.com/bohops/DynamicDotNet/blob/main/dynamic_pinvoke/dynamic_pinvoke_definepinvokemethod_shellcode_runner.cs - scope: function + scopes: + static: function + dynamic: thread features: - and: - or: diff --git a/nursery/unmanaged-call.yml b/nursery/unmanaged-call.yml index bb07ed99..32b0069a 100644 --- a/nursery/unmanaged-call.yml +++ b/nursery/unmanaged-call.yml @@ -5,7 +5,9 @@ rule: authors: - michael.hunhoff@mandiant.com description: managed code calls unmanaged (native) code, often seen in .NET - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead features: - or: - characteristic: unmanaged call diff --git a/persistence/act-as-dhcp-server-callout-dll.yml b/persistence/act-as-dhcp-server-callout-dll.yml index 4a309632..854058a4 100644 --- a/persistence/act-as-dhcp-server-callout-dll.yml +++ b/persistence/act-as-dhcp-server-callout-dll.yml @@ -4,7 +4,9 @@ rule: namespace: persistence authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Server Software Component [T1505] references: diff --git a/persistence/act-as-dns-server-plugin-dll.yml b/persistence/act-as-dns-server-plugin-dll.yml index b458b41e..b827b222 100644 --- a/persistence/act-as-dns-server-plugin-dll.yml +++ b/persistence/act-as-dns-server-plugin-dll.yml @@ -4,7 +4,9 @@ rule: namespace: persistence authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Server Software Component [T1505] references: diff --git a/persistence/authentication-process/act-as-credential-manager-dll.yml b/persistence/authentication-process/act-as-credential-manager-dll.yml index 476b650c..720198bf 100644 --- a/persistence/authentication-process/act-as-credential-manager-dll.yml +++ b/persistence/authentication-process/act-as-credential-manager-dll.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/authentication-process authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Modify Authentication Process::Network Provider DLL [T1556.008] examples: diff --git a/persistence/authentication-process/act-as-password-filter-dll.yml b/persistence/authentication-process/act-as-password-filter-dll.yml index a8cbeeb1..9524402b 100644 --- a/persistence/authentication-process/act-as-password-filter-dll.yml +++ b/persistence/authentication-process/act-as-password-filter-dll.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/authentication-process authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Modify Authentication Process::Password Filter DLL [T1556.002] examples: diff --git a/persistence/authentication-process/act-as-security-support-provider-dll.yml b/persistence/authentication-process/act-as-security-support-provider-dll.yml index 9776f1f0..81200674 100644 --- a/persistence/authentication-process/act-as-security-support-provider-dll.yml +++ b/persistence/authentication-process/act-as-security-support-provider-dll.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/authentication-process authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Boot or Logon Autostart Execution::Security Support Provider [T1547.005] references: diff --git a/persistence/authentication-process/act-as-subauthentication-package-dll.yml b/persistence/authentication-process/act-as-subauthentication-package-dll.yml index c0def1dd..e27f1753 100644 --- a/persistence/authentication-process/act-as-subauthentication-package-dll.yml +++ b/persistence/authentication-process/act-as-subauthentication-package-dll.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/authentication-process authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Boot or Logon Autostart Execution::Authentication Package [T1547.002] references: diff --git a/persistence/create-shortcut-via-ishelllink.yml b/persistence/create-shortcut-via-ishelllink.yml index 94c2cbda..e102cdc2 100644 --- a/persistence/create-shortcut-via-ishelllink.yml +++ b/persistence/create-shortcut-via-ishelllink.yml @@ -4,7 +4,9 @@ rule: namespace: persistence authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features att&ck: - Persistence::Boot or Logon Autostart Execution::Shortcut Modification [T1547.009] references: diff --git a/persistence/exchange/act-as-exchange-transport-agent.yml b/persistence/exchange/act-as-exchange-transport-agent.yml index ae24c809..e6148126 100644 --- a/persistence/exchange/act-as-exchange-transport-agent.yml +++ b/persistence/exchange/act-as-exchange-transport-agent.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/exchange authors: - jakub.jozwiak@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Persistence::Server Software Component::Transport Agent [T1505.002] references: diff --git a/persistence/iis/persist-via-iis-module.yml b/persistence/iis/persist-via-iis-module.yml index cee74ded..6e5f0f91 100644 --- a/persistence/iis/persist-via-iis-module.yml +++ b/persistence/iis/persist-via-iis-module.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com description: IIS 7.0 introduced modules that provide the same unrestricted access to HTTP requests and responses as ISAPI extensions and filters. - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Server Software Component::IIS Components [T1505.004] examples: diff --git a/persistence/iis/persist-via-isapi-extension.yml b/persistence/iis/persist-via-isapi-extension.yml index 89230c9b..36ab99e5 100644 --- a/persistence/iis/persist-via-isapi-extension.yml +++ b/persistence/iis/persist-via-isapi-extension.yml @@ -5,7 +5,9 @@ rule: authors: - william.ballenthin@mandiant.com description: Internet Server Application Programming Interface (ISAPI) extensions and filters can be installed to examine and/or modify incoming and outgoing IIS web requests. - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Server Software Component::IIS Components [T1505.004] examples: diff --git a/persistence/office/act-as-excel-xll-add-in.yml b/persistence/office/act-as-excel-xll-add-in.yml index 446bdcb9..e08ca0ba 100644 --- a/persistence/office/act-as-excel-xll-add-in.yml +++ b/persistence/office/act-as-excel-xll-add-in.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/office authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Office Application Startup::Add-ins [T1137.006] references: diff --git a/persistence/office/act-as-office-com-add-in.yml b/persistence/office/act-as-office-com-add-in.yml index bfb1dd09..d5004be9 100644 --- a/persistence/office/act-as-office-com-add-in.yml +++ b/persistence/office/act-as-office-com-add-in.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/office authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires class features att&ck: - Persistence::Office Application Startup::Add-ins [T1137.006] references: diff --git a/persistence/office/act-as-word-wll-add-in.yml b/persistence/office/act-as-word-wll-add-in.yml index 74bebc56..17e31d3b 100644 --- a/persistence/office/act-as-word-wll-add-in.yml +++ b/persistence/office/act-as-word-wll-add-in.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/office authors: - jakub.jozwiak@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires export features att&ck: - Persistence::Office Application Startup::Add-ins [T1137.006] references: diff --git a/persistence/persist-via-desktop-autostart.yml b/persistence/persist-via-desktop-autostart.yml index 3a1ed342..801c1f05 100644 --- a/persistence/persist-via-desktop-autostart.yml +++ b/persistence/persist-via-desktop-autostart.yml @@ -4,7 +4,9 @@ rule: namespace: persistence authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Boot or Logon Autostart Execution::XDG Autostart Entries [T1547.013] examples: diff --git a/persistence/persist-via-shell-profile-or-rc-file.yml b/persistence/persist-via-shell-profile-or-rc-file.yml index 73ecb0f2..1032e253 100644 --- a/persistence/persist-via-shell-profile-or-rc-file.yml +++ b/persistence/persist-via-shell-profile-or-rc-file.yml @@ -4,7 +4,9 @@ rule: namespace: persistence authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Event Triggered Execution::Unix Shell Configuration Modification [T1546.004] examples: diff --git a/persistence/registry/appinitdlls/disable-appinit_dlls-code-signature-enforcement.yml b/persistence/registry/appinitdlls/disable-appinit_dlls-code-signature-enforcement.yml index 42872d58..148fe4b1 100644 --- a/persistence/registry/appinitdlls/disable-appinit_dlls-code-signature-enforcement.yml +++ b/persistence/registry/appinitdlls/disable-appinit_dlls-code-signature-enforcement.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/registry/appinitdlls authors: - william.ballenthin@fireye.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Event Triggered Execution::AppInit DLLs [T1546.010] - Defense Evasion::Subvert Trust Controls::Code Signing Policy Modification [T1553.006] diff --git a/persistence/registry/appinitdlls/persist-via-appinit_dlls-registry-key.yml b/persistence/registry/appinitdlls/persist-via-appinit_dlls-registry-key.yml index 69863387..cfb1434d 100644 --- a/persistence/registry/appinitdlls/persist-via-appinit_dlls-registry-key.yml +++ b/persistence/registry/appinitdlls/persist-via-appinit_dlls-registry-key.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/registry/appinitdlls authors: - michael.hunhoff@fireye.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Event Triggered Execution::AppInit DLLs [T1546.010] references: diff --git a/persistence/registry/ginadll/persist-via-ginadll-registry-key.yml b/persistence/registry/ginadll/persist-via-ginadll-registry-key.yml index 0ae9335e..baefc359 100644 --- a/persistence/registry/ginadll/persist-via-ginadll-registry-key.yml +++ b/persistence/registry/ginadll/persist-via-ginadll-registry-key.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/registry/ginadll authors: - michael.hunhoff@fireye.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Event Triggered Execution [T1546] examples: diff --git a/persistence/registry/persist-via-active-setup-registry-key.yml b/persistence/registry/persist-via-active-setup-registry-key.yml index 64628d2a..ea62c753 100644 --- a/persistence/registry/persist-via-active-setup-registry-key.yml +++ b/persistence/registry/persist-via-active-setup-registry-key.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/registry authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Boot or Logon Autostart Execution::Active Setup [T1547.014] references: diff --git a/persistence/registry/run/persist-via-run-registry-key.yml b/persistence/registry/run/persist-via-run-registry-key.yml index 0f11f522..57810493 100644 --- a/persistence/registry/run/persist-via-run-registry-key.yml +++ b/persistence/registry/run/persist-via-run-registry-key.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/registry/run authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] mbc: diff --git a/persistence/registry/winlogon-helper/persist-via-winlogon-helper-dll-registry-key.yml b/persistence/registry/winlogon-helper/persist-via-winlogon-helper-dll-registry-key.yml index b11e8819..57d7e4cf 100644 --- a/persistence/registry/winlogon-helper/persist-via-winlogon-helper-dll-registry-key.yml +++ b/persistence/registry/winlogon-helper/persist-via-winlogon-helper-dll-registry-key.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/registry/winlogon-helper authors: - 0x534a@mailbox.org - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Boot or Logon Autostart Execution::Winlogon Helper DLL [T1547.004] examples: diff --git a/persistence/scheduled-tasks/schedule-task-via-at.yml b/persistence/scheduled-tasks/schedule-task-via-at.yml index ad25216e..612feb84 100644 --- a/persistence/scheduled-tasks/schedule-task-via-at.yml +++ b/persistence/scheduled-tasks/schedule-task-via-at.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/scheduled-tasks authors: - joren485 - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Scheduled Task/Job::At [T1053.002] examples: diff --git a/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml b/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml index 5c20d31d..b7dccb4c 100644 --- a/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml +++ b/persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/scheduled-tasks authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unsupported # requires offset, bytes features att&ck: - Persistence::Scheduled Task/Job::Scheduled Task [T1053.005] examples: diff --git a/persistence/scheduled-tasks/schedule-task-via-schtasks.yml b/persistence/scheduled-tasks/schedule-task-via-schtasks.yml index da75b2be..a6f22980 100644 --- a/persistence/scheduled-tasks/schedule-task-via-schtasks.yml +++ b/persistence/scheduled-tasks/schedule-task-via-schtasks.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/scheduled-tasks authors: - 0x534a@mailbox.org - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Scheduled Task/Job::Scheduled Task [T1053.005] examples: diff --git a/persistence/service/persist-via-rc-script.yml b/persistence/service/persist-via-rc-script.yml index 1d4c6b0a..c4b87720 100644 --- a/persistence/service/persist-via-rc-script.yml +++ b/persistence/service/persist-via-rc-script.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/service authors: - joakim@intezer.com - scope: function + scopes: + static: function + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Boot or Logon Initialization Scripts::RC Scripts [T1037.004] examples: diff --git a/persistence/service/persist-via-windows-service.yml b/persistence/service/persist-via-windows-service.yml index a7b30786..f9fb7484 100644 --- a/persistence/service/persist-via-windows-service.yml +++ b/persistence/service/persist-via-windows-service.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/service authors: - moritz.raabe@mandiant.com - scope: function + scopes: + static: function + dynamic: unspecified # TODO upgrade manually, contains subscope att&ck: - Persistence::Create or Modify System Process::Windows Service [T1543.003] - Execution::System Services::Service Execution [T1569.002] diff --git a/persistence/startup-folder/get-startup-folder.yml b/persistence/startup-folder/get-startup-folder.yml index bc671794..a2bf3100 100644 --- a/persistence/startup-folder/get-startup-folder.yml +++ b/persistence/startup-folder/get-startup-folder.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/startup-folder authors: - matthew.williams@mandiant.com - scope: basic block + scopes: + static: basic block + dynamic: thread # TODO check if scope call instead att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] examples: diff --git a/persistence/startup-folder/write-file-to-startup-folder.yml b/persistence/startup-folder/write-file-to-startup-folder.yml index 7ac1c059..88a64959 100644 --- a/persistence/startup-folder/write-file-to-startup-folder.yml +++ b/persistence/startup-folder/write-file-to-startup-folder.yml @@ -4,7 +4,9 @@ rule: namespace: persistence/startup-folder authors: - matthew.williams@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] examples: diff --git a/runtime/dotnet/compiled-to-the-dotnet-platform.yml b/runtime/dotnet/compiled-to-the-dotnet-platform.yml index 661c7fa6..869a0918 100644 --- a/runtime/dotnet/compiled-to-the-dotnet-platform.yml +++ b/runtime/dotnet/compiled-to-the-dotnet-platform.yml @@ -4,7 +4,9 @@ rule: namespace: runtime/dotnet authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file examples: - b9f5bd514485fb06da39beff051b9fdc features: diff --git a/runtime/dotnet/execute-via-dotnet-startup-hook.yml b/runtime/dotnet/execute-via-dotnet-startup-hook.yml index f3e1b6bb..ad5e3cd8 100644 --- a/runtime/dotnet/execute-via-dotnet-startup-hook.yml +++ b/runtime/dotnet/execute-via-dotnet-startup-hook.yml @@ -4,7 +4,9 @@ rule: namespace: runtime/dotnet authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: unsupported # requires function-name features references: - https://rastamouse.me/net-startup-hooks/ - https://github.com/dotnet/runtime/blob/main/docs/design/features/host-startup-hook.md diff --git a/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml b/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml index 2d150e12..d82caa4a 100644 --- a/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml +++ b/targeting/automated-teller-machine/diebold-nixdorf/load-diebold-nixdorf-atm-library.yml @@ -4,7 +4,9 @@ rule: namespace: targeting/automated-teller-machine/diebold-nixdorf authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.vkremez.com/2017/12/lets-learn-cutlet-atm-malware-internals.html examples: diff --git a/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml b/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml index 4d455449..5988d1b1 100644 --- a/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml +++ b/targeting/automated-teller-machine/diebold-nixdorf/reference-diebold-atm-routines.yml @@ -4,7 +4,9 @@ rule: namespace: targeting/automated-teller-machine/diebold-nixdorf authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.mandiant.com/resources/new-ploutus-variant examples: diff --git a/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml b/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml index 4c8b495a..52cea495 100644 --- a/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml +++ b/targeting/automated-teller-machine/identify-atm-dispenser-service-provider.yml @@ -4,7 +4,9 @@ rule: namespace: targeting/automated-teller-machine authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://doc.axxonsoft.com/confluence/display/atm70en/Configuring+the+connection+to+the+dispenser+service+provider examples: diff --git a/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml b/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml index bd47629a..5d733dd4 100644 --- a/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml +++ b/targeting/automated-teller-machine/ncr/load-ncr-atm-library.yml @@ -4,7 +4,9 @@ rule: namespace: targeting/automated-teller-machine/ncr authors: - william.ballenthin@mandiant.com - scope: file + scopes: + static: file + dynamic: file references: - https://www.pcworld.com/article/2824572/leaked-programming-manual-may-help-criminals-develop-more-atm-malware.html examples: diff --git a/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml b/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml index a0973a99..7354fd6e 100644 --- a/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml +++ b/targeting/automated-teller-machine/ncr/reference-ncr-atm-library-routines.yml @@ -4,7 +4,9 @@ rule: namespace: targeting/automated-teller-machine/ncr authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread references: - https://www.pcworld.com/article/2824572/leaked-programming-manual-may-help-criminals-develop-more-atm-malware.html examples: diff --git a/targeting/language/identify-system-language-via-api.yml b/targeting/language/identify-system-language-via-api.yml index 6645fc32..7ba9a0a2 100644 --- a/targeting/language/identify-system-language-via-api.yml +++ b/targeting/language/identify-system-language-via-api.yml @@ -4,7 +4,9 @@ rule: namespace: targeting/language authors: - william.ballenthin@mandiant.com - scope: function + scopes: + static: function + dynamic: thread att&ck: - Discovery::System Location Discovery::System Language Discovery [T1614.001] examples: