| .. |
|
access-aws-credentials.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
access-camera-in-dotnet-on-android.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
access-cloudflare-credentials.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
access-docker-credentials.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
access-gcp-credentials.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
access-kubernetes-credentials.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
access-unmanaged-com-objects-in-dotnet.yml
|
rules: dotnet: adding new .NET rules
|
2024-09-20 16:13:55 -06:00 |
|
access-wmi-data-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
acquire-load-driver-privileges.yml
|
new/updated rules from recent malware samples (#1063)
|
2025-08-12 10:21:05 -06:00 |
|
add-user-account-group.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
add-user-account-to-group.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
add-user-account.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
add-value-to-global-atom-table.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
allocate-unmanaged-memory-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
append-data-to-clfs-log-container.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
authenticate-data-with-md5-mac.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
build-docker-image.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
bypass-hidden-api-restrictions-via-jni-on-android.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
bypass-uac-via-scheduled-task-environment-variable.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
capture-microphone-audio-in-dotnet-on-android.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
capture-network-configuration-via-ifconfig.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
capture-process-snapshot-data.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
capture-screenshot-in-dotnet-on-android.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
capture-screenshot-in-go.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
capture-webcam-video.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
change-memory-permission-on-linux.yml
|
adding new and updating linux / android rules (#903)
|
2024-05-31 13:24:19 -04:00 |
|
change-user-account-password.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
check-clipboard-data.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
check-file-extension-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
check-file-permission-on-linux.yml
|
adding new and updating linux / android rules (#903)
|
2024-05-31 13:24:19 -04:00 |
|
check-for-incoming-call-in-dotnet-on-android.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
check-for-minimum-number-of-windows-on-screen.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
check-for-outgoing-call-in-dotnet-on-android.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
check-for-process-debug-object.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
check-for-sandbox-via-mac-address-ouis-in-dotnet.yml
|
fix scopes for rules with subscopes 2
|
2023-11-24 11:35:03 +01:00 |
|
check-for-vm-using-instruction-vpcext.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
check-for-windows-sandbox-via-mutex.yml
|
tighten Windows mutex related rules (#1004)
|
2025-02-21 12:37:01 -07:00 |
|
check-for-windows-sandbox-via-subdirectory.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
check-if-directory-exists.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
check-if-process-is-running-under-android-emulator-on-android.yml
|
adding new and updating linux / android rules (#903)
|
2024-05-31 13:24:19 -04:00 |
|
check-license-value.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
check-processdebugflags.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
check-systemkerneldebuggerinformation.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
check-thread-suspend-count-exceeded.yml
|
Add capa rules create-thread-bypass-freeze.yml and check-thread-suspend-count-exceeded.yml to nursery. (#912)
|
2024-09-16 14:45:21 +02:00 |
|
check-thread-yield-allowed.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
clear-clipboard-data.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
collect-ssh-keys.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
communicate-using-ftp.yml
|
new/updated rules from recent malware samples (#1063)
|
2025-08-12 10:21:05 -06:00 |
|
communicate-with-kernel-module-via-netlink-socket-on-linux.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
compare-security-identifiers.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
compile-csharp-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
compile-dotnet-assembly.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
compile-visual-basic-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
compiled-from-epl.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
compiled-from-fsharp.yml
|
dotnet: adding new rules based on recent samples (#1082)
|
2025-11-07 08:39:46 +01:00 |
|
compiled-with-exescript.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
compiled-with-xamarin.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
compress-data-using-gzip-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
connect-network-resource.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
contain-a-thread-local-storage-tls-section-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
covertly-decode-and-write-data-to-windows-directory-using-indirect-calls.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
create-container.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
create-executable-heap.yml
|
add create executable heap rule (#1058)
|
2025-08-04 12:40:42 -06:00 |
|
create-process-via-wmi-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
create-registry-key-via-stdregprov.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
create-restart-manager-session.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
create-thread-bypassing-process-freeze.yml
|
Add capa rules create-thread-bypass-freeze.yml and check-thread-suspend-count-exceeded.yml to nursery. (#912)
|
2024-09-16 14:45:21 +02:00 |
|
create-udp-socket.yml
|
Fix: False positive in UDP socket (#1111)
|
2026-01-30 10:04:39 -07:00 |
|
create-zip-archive-in-dotnet.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
debug-build.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
decode-data-using-base64-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
decode-data-using-base64-via-vbmi-lookup-table.yml
|
remove example and move to nursery
|
2024-08-16 13:47:03 +02:00 |
|
decode-data-using-url-encoding.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
decrypt-data-using-aes-via-dotnet.yml
|
dotnet: adding new rules based on recent samples (#1082)
|
2025-11-07 08:39:46 +01:00 |
|
decrypt-data-using-rsa-via-winapi.yml
|
New rules: RSA & bigint (#982)
|
2025-01-21 11:36:04 -07:00 |
|
decrypt-data-using-tripledes-in-dotnet.yml
|
detect usage of TripleDesCryptoServiceProvider (#1021)
|
2025-03-20 09:06:27 -06:00 |
|
decrypt-data-via-sspi.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
delete-file-on-linux.yml
|
update linux/android rules and reduce fps for intel-specific rules (#927)
|
2024-08-16 12:57:08 -06:00 |
|
delete-internet-cache.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
delete-registry-key-via-offline-registry-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
delete-registry-key-via-stdregprov.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
delete-registry-value-via-stdregprov.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
delete-user-account-from-group.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
delete-user-account-group.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
delete-user-account.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
delete-windows-backup-catalog.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
deserialize-json-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
destroy-software-breakpoint-capability.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
disable-automatic-windows-recovery-features.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
disable-device-guard-features-via-registry-on-windows.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
disable-firewall-features-via-registry-on-windows.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
disable-system-features-via-registry-on-windows.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
disable-system-restore-features-via-registry-on-windows.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
disable-windows-defender-features-via-registry-on-windows.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
display-service-notification-message-box.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
empty-the-recycle-bin.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
enable-safe-mode-boot.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
encrypt-data-using-aes-via-x86-extensions.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
encrypt-data-using-aes.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
encrypt-data-using-fakem-cipher.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
encrypt-data-using-openssl-dsa.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
encrypt-data-using-openssl-ecdsa.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
encrypt-data-using-openssl-rsa.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
encrypt-data-using-rsa-via-winapi.yml
|
New rules: RSA & bigint (#982)
|
2025-01-21 11:36:04 -07:00 |
|
encrypt-data-using-salsa20-or-chacha.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
encrypt-data-using-tripledes-in-dotnet.yml
|
detect usage of TripleDesCryptoServiceProvider (#1021)
|
2025-03-20 09:06:27 -06:00 |
|
encrypt-data-via-sspi.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
encrypt-or-decrypt-data-via-bcrypt.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enter-debug-mode-in-dotnet.yml
|
Enter debug mode rule (#1022)
|
2025-03-14 11:41:19 -06:00 |
|
enumerate-aws-cloudformation.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-aws-cloudtrail.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-aws-direct-connect.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-aws-ec2.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-aws-iam.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-aws-s3.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-aws-support-cases.yml
|
feat(targeting): add cloud and container collection/interaction rules (#1098)
|
2026-02-23 09:32:32 -07:00 |
|
enumerate-browser-history.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
enumerate-device-drivers-on-linux.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-device-drivers-on-windows.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
enumerate-disk-volumes.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-drives.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
enumerate-files-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-internet-cache.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-network-shares.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-pe-sections-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
enumerate-processes-that-use-resource.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-processes-via-procfs.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
enumerate-system-firmware-tables.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
execute-dotnet-assembly.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
execute-shell-command-via-windows-remote-management.yml
|
Improve existing persistence rules (#953)
|
2024-12-09 10:51:47 +01:00 |
|
execute-shellcode-via-indirect-call.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
execute-sqlite-statement-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
execute-syscall.yml
|
Add SysWhispers2 detection & add 0x2e syscall detection (#888)
|
2024-09-24 13:24:52 +02:00 |
|
execute-via-asynchronous-task-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
execute-via-timer-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
extract-zip-archive-in-dotnet.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
find-data-using-regex-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
find-process-by-name.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
generate-method-via-reflection-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
generate-random-bytes-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
generate-random-filename-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
generate-random-numbers-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
generate-random-numbers-using-the-delphi-lcg.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
get-client-handle-via-schannel.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-current-pid-on-linux.yml
|
add android OS where applicable
|
2024-04-23 13:49:05 +02:00 |
|
get-current-process-command-line.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-current-process-file-path.yml
|
add new linux rules to nursery (#870)
|
2024-01-11 15:20:02 +01:00 |
|
get-current-process-filesystem-mounts-on-linux.yml
|
adding / updating linux / android rules (#907)
|
2024-06-11 12:10:57 -06:00 |
|
get-current-process-memory-mapping-on-linux.yml
|
adding / updating linux / android rules (#907)
|
2024-06-11 12:10:57 -06:00 |
|
get-disk-information-via-ioctl.yml
|
add rules for volume interaction via IOCTLs (#879)
|
2024-02-14 14:56:47 +01:00 |
|
get-dotnet-assembly-entry-point.yml
|
dotnet: adding new rules based on recent samples (#1082)
|
2025-11-07 08:39:46 +01:00 |
|
get-file-system-information-on-linux.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
get-http-request-uri.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
get-inbound-credentials-handle-via-credssp.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
get-mac-address-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-mac-address-on-linux.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-networking-parameters.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
get-ntoskrnl-base-address.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
get-os-information-via-kuser_shared_data.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-os-version-in-dotnet-on-android.yml
|
update scopes
|
2023-11-24 11:51:37 +01:00 |
|
get-os-version-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
get-password-database-entry-on-linux.yml
|
added detections for reading/writing shadow file, password database (#949)
|
2024-10-30 16:19:22 +01:00 |
|
get-process-image-filename.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-proxy.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-remote-cert-context-via-schannel.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
get-session-information.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-shadow-password-file-entry-on-linux.yml
|
added detections for reading/writing shadow file, password database (#949)
|
2024-10-30 16:19:22 +01:00 |
|
get-socket-information.yml
|
add API features for ws2_32 ordinals (#893)
|
2024-04-23 14:20:28 +02:00 |
|
get-storage-device-properties.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-system-information-on-linux.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-system-property-on-android.yml
|
adding / updating linux / android rules (#907)
|
2024-06-11 12:10:57 -06:00 |
|
get-system-web-proxy.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
get-thread-local-storage-value.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
get-token-privileges.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
get-volume-information-via-ioctl.yml
|
add rules for volume interaction via IOCTLs (#879)
|
2024-02-14 14:56:47 +01:00 |
|
hash-data-using-aphash.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-crc32b.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-jshash.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-md4.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
hash-data-using-murmur2.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-ripemd128.yml
|
fix scopes for rules with subscopes 2
|
2023-11-24 11:35:03 +01:00 |
|
hash-data-using-ripemd256.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hash-data-using-ripemd320.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hash-data-using-rshash.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-sha1-via-wincrypt.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hash-data-using-sha1-via-x86-extensions.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-sha256-via-x86-extensions.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-using-sha512managed-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hash-data-using-whirlpool.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
hash-data-via-bcrypt.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hook-routines-via-dlsym-rtld_next.yml
|
add new linux rules to nursery (#870)
|
2024-01-11 15:20:02 +01:00 |
|
hook-routines-via-lsplant.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hook-routines-via-microsoft-detours.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
hooked-by-api-override.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
implement-com-dll.yml
|
fix some dynamic unsupported rules
|
2023-11-24 11:35:05 +01:00 |
|
implement-ui-automation-client-in-dotnet.yml
|
rules: dotnet: adding new .NET rules
|
2024-09-20 16:13:55 -06:00 |
|
initialize-hashing-via-wincrypt.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
inject-shellcode-using-thread-pool-work-insertion-with-tp_io.yml
|
Add Thread Pool injection techniques (#1087)
|
2025-12-04 10:17:27 -07:00 |
|
inject-shellcode-using-thread-pool-work-insertion-with-tp_timer.yml
|
Add Thread Pool injection techniques (#1087)
|
2025-12-04 10:17:27 -07:00 |
|
inject-shellcode-using-thread-pool-work-insertion-with-tp_work.yml
|
Add Thread Pool injection techniques (#1087)
|
2025-12-04 10:17:27 -07:00 |
|
inspect-load-icon-resource.yml
|
fix some dynamic unsupported rules
|
2023-11-24 11:35:05 +01:00 |
|
interact-with-iptables.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
interact-with-shortcut-via-iwshshortcut-in-dotnet.yml
|
rules: dotnet: adding new .NET rules
|
2024-09-20 16:13:55 -06:00 |
|
interact-with-windows-scripting-host-in-dotnet.yml
|
rules: dotnet: adding new .NET rules
|
2024-09-20 16:13:55 -06:00 |
|
invoke-dotnet-assembly-method.yml
|
dotnet: improve dotnet invoke-dotnet-assembly-method.yml
|
2024-08-01 16:21:13 -06:00 |
|
link-function-at-runtime-on-linux.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
linked-against-cpp-http-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-cpp-json-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-cpp-regex-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-go-process-enumeration-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-go-registry-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-go-static-asset-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-go-wmi-library.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-libsodium.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
linked-against-xzip.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
list-containers.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
list-domain-servers.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
list-drag-and-drop-files.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
list-groups-for-user-account.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
list-tcp-connections-and-listeners.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
list-udp-connections-and-listeners.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
list-user-account-groups.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
list-user-accounts-for-group.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
list-user-accounts.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
listen-for-remote-procedure-calls.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
load-dotnet-assembly.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
load-packed-dex-via-jiagu-on-android.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
load-xml-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
log-keystrokes-via-input-method-manager.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
log-keystrokes-via-raw-input-data.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
make-an-http-request-with-a-cookie.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
manipulate-console-window.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
manipulate-network-credentials-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
manipulate-unmanaged-memory-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
manipulate-user-privileges.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
map-or-unmap-memory-on-linux.yml
|
adding new and updating linux / android rules (#903)
|
2024-05-31 13:24:19 -04:00 |
|
mark-thread-detached-on-linux.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
migrate-process-to-active-window-station.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
mixed-mode.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
modify-api-blacklist-or-denylist-via-jni-on-android.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
monitor-clipboard-content.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
monitor-local-ipv4-address-changes.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
move-directory.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
obfuscated-with-koivm.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packaged-as-a-createinstall-installer.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packaged-as-a-nsis-installer.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packaged-as-a-pintool.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packaged-as-a-winzip-self-extracting-archive.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packaged-as-a-wise-installer.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packaged-as-an-installshield-installer.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-ccg.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-crunch.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-dragon-armor.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-enigma.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-epack.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-maskpe.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-mew.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-mpress.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-neolite.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-pepack.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-perplex.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-procrypt.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-rpcrypt.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-seausfx.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-shrinker.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-simple-pack.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-starforce.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-svkp.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-tsuloader.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-vprotect.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
packed-with-wwpack.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
parse-url.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
persist-via-aedebug-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-amsi-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-app-paths-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-appcertdlls-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-application-shimming.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-appx-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-autodialdll-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-autoplayhandlers-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-bits-job.yml
|
Remove COM usage detection from BITS jobs persistence
|
2024-11-22 16:16:19 +01:00 |
|
persist-via-bootverificationprogram-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-code-signing-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-com-hijack.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-command-processor-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-contextmenuhandlers-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-cor_profiler_path-registry-value.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-default-file-association-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-disk-cleanup-handler-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-dotnet-dbgmanageddebugger-registry-key.yml
|
fix: escape "." that are not expected to be dot operators (#1028)
|
2025-03-18 15:01:39 -06:00 |
|
persist-via-dotnet_startup_hooks-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-errorhandler-script.yml
|
fix: escape "." that are not expected to be dot operators (#1028)
|
2025-03-18 15:01:39 -06:00 |
|
persist-via-explorer-tools-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-filter-handlers-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-get-variable-hijack.yml
|
fix: escape "." that are not expected to be dot operators (#1028)
|
2025-03-18 15:01:39 -06:00 |
|
persist-via-gnome-autostart-on-linux.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
persist-via-group-policy-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-hhctrl-com-hijack.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-htmlhelp-author-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-image-file-execution-options-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-iphlpapi-dll-hijack.yml
|
Add 10 file system-based persistence techniques (#955)
|
2024-12-03 17:26:03 +01:00 |
|
persist-via-lnk-shortcut.yml
|
Add 10 file system-based persistence techniques (#955)
|
2024-12-03 17:26:03 +01:00 |
|
persist-via-lsa-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-natural-language-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-netsh-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-network-provider-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-path-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-powershell-profile.yml
|
fix: escape "." that are not expected to be dot operators (#1028)
|
2025-03-18 15:01:39 -06:00 |
|
persist-via-print-monitors-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-print-processors-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-rdp-startup-programs-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-screensaver-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-silentprocessexit-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-telemetrycontroller-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-timeproviders-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-ts-initialprogram-registry-key.yml
|
add new rules to detect disabling system features via registry on Windows (#1034)
|
2025-03-24 10:38:19 -06:00 |
|
persist-via-userinitmprlogonscript-registry-value.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-windows-accessibility-tools.yml
|
fix: escape "." that are not expected to be dot operators (#1028)
|
2025-03-18 15:01:39 -06:00 |
|
persist-via-windows-error-reporting-registry-key.yml
|
use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999)
|
2025-02-20 14:02:16 -07:00 |
|
persist-via-windows-terminal-profile.yml
|
fix: escape "." that are not expected to be dot operators (#1028)
|
2025-03-18 15:01:39 -06:00 |
|
power-down-monitor.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
prompt-user-for-credentials.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
query-or-enumerate-registry-key-via-stdregprov.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
query-or-enumerate-registry-value-via-stdregprov.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
query-remote-server-for-available-data.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
read-and-send-data-from-client-to-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
read-process-memory.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
read-raw-disk-data.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
rebuilt-by-imprec.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
receive-and-write-data-from-server-to-client.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-114dns-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-aes-constants.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
reference-alidns-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-base58-string.yml
|
fix some dynamic unsupported rules
|
2023-11-24 11:35:05 +01:00 |
|
reference-cloudflare-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-comodo-secure-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-cryptocurrency-strings.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
reference-google-public-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-hurricane-electric-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-kornet-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-l3-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-opendns-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-processor-manufacturer-constants.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
reference-quad9-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
reference-startup-folder.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
reference-the-vmware-io-port.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
reference-verisign-dns-server.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
register-http-server-url.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
resize-volume-shadow-copy-storage.yml
|
fix scopes from lint errors
|
2025-01-29 18:54:25 +01:00 |
|
resolve-function-by-djb2-hash.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
resolve-function-by-fnv-1a-hash.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
resolve-function-by-hash.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
run-as-nodejs-native-module.yml
|
adding/updating rules based on recent samples (#1085)
|
2025-11-25 13:38:55 -07:00 |
|
run-in-container.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
save-image-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
schedule-task-via-itaskservice.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
search-for-credit-card-data.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
send-data-to-internet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
send-email-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
send-http-request-with-host-header.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
send-keystrokes.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
send-request-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
send-sms-on-android.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
serialize-json-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
set-current-directory.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
set-global-application-hook.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
set-http-cookie.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
set-http-user-agent-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
set-registry-value-via-stdregprov.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
set-shadow-password-file-entry-on-linux.yml
|
added detections for reading/writing shadow file, password database (#949)
|
2024-10-30 16:19:22 +01:00 |
|
set-thread-name-on-linux.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
set-web-proxy-in-dotnet.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
terminate-process-by-name-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
terminate-process-by-name.yml
|
upgrade rules using updated script
|
2023-11-24 11:34:28 +01:00 |
|
truncate-file-on-linux.yml
|
adding / updating linux / android rules (#907)
|
2024-06-11 12:10:57 -06:00 |
|
unmanaged-call-via-dynamic-pinvoke-in-dotnet.yml
|
use "span of calls" scope (#973)
|
2025-01-29 10:27:13 +01:00 |
|
unmanaged-call.yml
|
fix call/thread scopes manually
|
2023-11-24 11:35:00 +01:00 |
|
unmount-volume-via-ioctl.yml
|
fix scopes from lint errors
|
2025-01-29 18:54:25 +01:00 |
|
use-dotnet-library-simplejson.yml
|
rules: dotnet: adding new .NET rules
|
2024-09-20 16:13:55 -06:00 |
|
use-dotnet-library-websocket-sharp.yml
|
rules: dotnet: adding new .NET rules
|
2024-09-20 16:13:55 -06:00 |
|
write-to-browser-extension-directory.yml
|
Add 10 file system-based persistence techniques (#955)
|
2024-12-03 17:26:03 +01:00 |