Commit Graph

340 Commits

Author SHA1 Message Date
yugoslavskiy 49bc6ada25 Rename win_susp_cdb.yml to process_creation_susp_cdb.yml 2019-11-04 20:35:28 +03:00
yugoslavskiy 95412e5f30 Rename win_susp_bginfo.yml to process_creation_susp_bginfo.yml 2019-11-04 20:35:11 +03:00
yugoslavskiy 9371e533c3 Update win_susp_openwith_execution.yml 2019-11-04 19:05:23 +03:00
yugoslavskiy e6a39f1061 Update win_susp_odbcconf.yml 2019-11-04 19:01:30 +03:00
yugoslavskiy c18fa0940d Update win_susp_msoffice.yml 2019-11-04 18:44:07 +03:00
yugoslavskiy bd0ebf0604 Update win_susp_dxcap.yml 2019-11-04 18:43:42 +03:00
yugoslavskiy df07291e53 Update win_susp_cdb.yml 2019-11-04 18:43:03 +03:00
yugoslavskiy a66539c771 Update win_susp_msoffice.yml 2019-11-04 18:42:26 +03:00
yugoslavskiy 56b7402e62 Update win_susp_dxcap.yml 2019-11-04 18:38:37 +03:00
yugoslavskiy a9fdfee5c2 Update win_susp_dnx.yml 2019-11-04 18:34:25 +03:00
yugoslavskiy dc23e566a0 Update win_susp_devtoolslauncher_execution.yml 2019-11-04 18:30:04 +03:00
yugoslavskiy 989d75033a Update win_susp_cdb.yml 2019-11-04 18:25:30 +03:00
yugoslavskiy 43c20d203d Update and rename win_susp_capture_screenshots.yml to win_susp_psr_capture_screenshots.yml 2019-11-04 18:16:39 +03:00
yugoslavskiy a800093aaf Update win_susp_bginfo.yml 2019-11-04 18:14:44 +03:00
Florian Roth 5786688f97 rule: Firewall disabled via Netsh 2019-11-04 16:10:10 +01:00
Florian Roth 3107c0c268 rule: Formbook rule improved 2019-10-31 09:32:18 +01:00
zinint 60bf34e220 T1042 2019-10-30 23:30:56 +03:00
zinint b3b203e5b1 t1040 2019-10-30 23:15:19 +03:00
Florian Roth 4741b6a4d6 rule: Mustang Panda dropper 2019-10-30 18:22:40 +01:00
Florian Roth d661771608 rule: another DTRACK reference 2019-10-30 18:22:25 +01:00
Florian Roth 3ac28f3eed rule: DTRACK process creation 2019-10-30 15:16:33 +01:00
Thomas Patzke 219f00e3fb Added command line parameter
Implements #418
2019-10-29 23:04:28 +01:00
Thomas Patzke b6403793c1 Fixed escaping in rule 2019-10-29 22:06:23 +01:00
zinint c243c4e210 T1035 2019-10-29 20:58:52 +03:00
Florian Roth 1a3444d0ef docs: comment on rule expression 2019-10-28 12:02:46 +01:00
zinint 87c8326133 T1033 2019-10-27 23:49:07 +03:00
zinint 55eaae1cea Rename win_app_windows_descovery.yml to win_app_windows_discovery.yml 2019-10-27 23:15:10 +03:00
zinint 93b867024c T1012 2019-10-27 23:13:03 +03:00
root 717e40e8ed modified win_susp_dxcap.yml 2019-10-26 20:27:32 +02:00
root 9bf0150100 modified win_susp_dnx.yml 2019-10-26 20:20:21 +02:00
root 3b70f2edd6 modified win_susp_dnx.yml 2019-10-26 20:16:40 +02:00
root 3528afeef7 modified win_susp_dnx.yml 2019-10-26 20:13:53 +02:00
root 1dca0456ee modified win_susp_dxcap.yml 2019-10-26 20:09:25 +02:00
root cbe0d73ce8 add win_susp_dxcap.yml 2019-10-26 20:06:02 +02:00
root aaf63d2238 add win_susp_dxcap.yml 2019-10-26 20:02:25 +02:00
root 0616c2c39d add win_susp_dnx.yml 2019-10-26 19:58:45 +02:00
root ee21888e67 add win_susp_cdb.yml 2019-10-26 19:49:45 +02:00
Florian Roth 42808b7eb8 rule: webshell detection improved 2019-10-26 09:14:54 +02:00
root 844d55c781 add win_susp_bginfo.yml 2019-10-26 08:18:37 +02:00
root 5bb5938e86 add win_susp_bginfo.yml 2019-10-26 08:16:08 +02:00
root 01c4c7cdbd modifed win_susp_msoffice.yml 2019-10-26 08:11:09 +02:00
root bea2daac45 modifed win_susp_msoffice.yml 2019-10-26 07:55:44 +02:00
root fc7f8ecea3 add win_susp_msoffice.yml 2019-10-26 07:48:38 +02:00
root 611c193826 modifed win_susp_odbcconf.yml 2019-10-26 07:45:53 +02:00
root aa9a22e662 add win_susp_odbcconf.yml 2019-10-25 19:02:17 +02:00
alexpetrov12 8c2b7e9f85 fix 2019-10-25 18:30:40 +03:00
alexpetrov12 7aa804fe90 added new rules
Packet capture Windows command prompt, ODBCCONF execution dll, Windows Registry Persistence - COM key linking
2019-10-25 18:01:36 +03:00
zinint 6e94e798be t1010 2019-10-25 16:12:51 +03:00
Florian Roth a5ec6722a1 rule: the actual changes to hwp rule 2019-10-24 15:35:13 +02:00
zinint 7c5dc0ca01 Update win_data_compressed.yml 2019-10-24 15:34:13 +03:00