From a573a8e1bca11d7e04ff3fcfddb86a684c013b65 Mon Sep 17 00:00:00 2001 From: jstnk9 Date: Fri, 25 Nov 2022 15:34:38 +0100 Subject: [PATCH] Title modified in several rules (#3728) --- .../proc_creation_lnx_file_and_directory_discovery.yml | 4 ++-- .../proc_creation_macos_file_and_directory_discovery.yml | 4 ++-- .../registry_set/registry_set_uac_bypass_eventvwr.yml | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/rules/linux/process_creation/proc_creation_lnx_file_and_directory_discovery.yml b/rules/linux/process_creation/proc_creation_lnx_file_and_directory_discovery.yml index 50bd11e9c..a7c0e3ce8 100644 --- a/rules/linux/process_creation/proc_creation_lnx_file_and_directory_discovery.yml +++ b/rules/linux/process_creation/proc_creation_lnx_file_and_directory_discovery.yml @@ -1,4 +1,4 @@ -title: File and Directory Discovery +title: File and Directory Discovery - Linux id: d3feb4ee-ff1d-4d3d-bd10-5b28a238cc72 status: test description: Detects usage of system utilities to discover files and directories @@ -6,7 +6,7 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1083/T1083.md author: Daniil Yugoslavskiy, oscd.community date: 2020/10/19 -modified: 2021/11/27 +modified: 2022/11/25 tags: - attack.discovery - attack.t1083 diff --git a/rules/macos/process_creation/proc_creation_macos_file_and_directory_discovery.yml b/rules/macos/process_creation/proc_creation_macos_file_and_directory_discovery.yml index 43ffdd8ed..4aca758c0 100644 --- a/rules/macos/process_creation/proc_creation_macos_file_and_directory_discovery.yml +++ b/rules/macos/process_creation/proc_creation_macos_file_and_directory_discovery.yml @@ -1,4 +1,4 @@ -title: File and Directory Discovery +title: File and Directory Discovery - MacOS id: 089dbdf6-b960-4bcc-90e3-ffc3480c20f6 status: test description: Detects usage of system utilities to discover files and directories @@ -6,7 +6,7 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1083/T1083.md author: Daniil Yugoslavskiy, oscd.community date: 2020/10/19 -modified: 2021/11/27 +modified: 2022/11/25 tags: - attack.discovery - attack.t1083 diff --git a/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml b/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml index fab13cd6c..487b79eeb 100755 --- a/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml +++ b/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml @@ -1,4 +1,4 @@ -title: UAC Bypass via Event Viewer +title: UAC Bypass via Event Viewer - Registry Set id: 7c81fec3-1c1d-43b0-996a-46753041b1b6 status: experimental description: Detects UAC bypass method using Windows event viewer @@ -7,7 +7,7 @@ references: - https://www.hybrid-analysis.com/sample/e122bc8bf291f15cab182a5d2d27b8db1e7019e4e96bb5cdbd1dfe7446f3f51f?environmentId=100 author: Florian Roth date: 2017/03/19 -modified: 2022/03/26 +modified: 2022/11/25 tags: - attack.defense_evasion - attack.privilege_escalation