Commit graph

19 commits

Author SHA1 Message Date
Elad Levi
3bd8cf7646
Improve Accuracy of Various Detections (#1010)
* Update impersonate-user.yml

* Update enumerate-processes-on-remote-desktop-session-host.yml

* Update enumerate-processes-on-remote-desktop-session-host.yml

* Update enumerate-processes-on-remote-desktop-session-host.yml

* Update nursery/impersonate-user.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-03-10 14:19:23 -06:00
Willi Ballenthin
c1d20764ad
use "span of calls" scope (#973)
* use sequence scope instead of thread scope for "static: function" rules

* use sequence scope instead of thread scope for "static: basic block" rules

* make runtime linking rules more concise

* doc: describe sequence scope

* rename "sequence" scope to "span of calls" scope

* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/get-geographical-location.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/file-managers/gather-classicftp-information.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/wmi/reference-wmi-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/sql/reference-sql-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-01-29 10:27:13 +01:00
mr-tz
8a36231025 fix scopes for rules with subscopes 2 2023-11-24 11:35:03 +01:00
mr-tz
e18704545a fix call/thread scopes manually 2023-11-24 11:35:00 +01:00
mr-tz
784c9dca53 upgrade rules using updated script 2023-11-24 11:34:28 +01:00
Moritz
977ad92ea3
improve debug detection features (#721) 2023-03-14 19:30:12 +01:00
Anushka Virgaonkar
95dc5eb27f
Add new dotnet rules that capture capabilites typically found in backdoors. (#579) 2022-07-07 13:39:51 -06:00
Mike Hunhoff
d4af075660
dotnet rule updates (#566) 2022-06-28 15:16:24 -06:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
Moritz Raabe
25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
Moritz Raabe
d81e757728 adding rules based on more PMA labs 2021-06-30 23:38:17 +02:00
Michael Hunhoff
750e164a41 removing ntdll requirement from function features exported by both ntdll and ntoskrnl 2021-02-16 18:28:05 -07:00
William Ballenthin
f1f0b4a1b6 merge 2021-01-02 11:06:53 -07:00
William Ballenthin
d99c02aca7 update ATT&CK mappings 2021-01-02 11:06:02 -07:00
Michael Hunhoff
d569817bdf adding new rules for Gh0st 2020-12-02 08:14:20 -07:00
Michael Hunhoff
6ccc9a736f fresh rules from al-khaser project 2020-08-13 09:39:42 -06:00
William Ballenthin
1c39bd8349 graduate rules that pass the linter 2020-07-23 17:30:37 -06:00
William Ballenthin
7b4f4d10fb rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better 2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9 rules: reorganize rule names, namespaces, and ATT&CK mappings 2020-06-21 17:25:43 -06:00