Commit Graph

4601 Commits

Author SHA1 Message Date
Jonhnathan 1f7f0956af Update win_crime_fireball.yml 2020-10-15 17:48:37 -03:00
Jonhnathan 9d2ae693fc Update win_control_panel_item.yml 2020-10-15 17:47:25 -03:00
Jonhnathan 1ea8adea31 Update win_cmdkey_recon.yml 2020-10-15 17:46:14 -03:00
Jonhnathan f995f9fa1d Update win_bypass_squiblytwo.yml
Changed selection a bit
2020-10-15 17:44:51 -03:00
Jonhnathan 63dc8ce837 Update win_attrib_hiding_files.yml 2020-10-15 17:41:44 -03:00
Jonhnathan afc52e5da5 Update win_apt_zxshell.yml 2020-10-15 17:40:07 -03:00
Jonhnathan ae95b5e998 Update win_apt_wocao.yml 2020-10-15 17:38:05 -03:00
Jonhnathan 5e3b9dc8ba Update win_apt_unidentified_nov_18.yml 2020-10-15 17:36:20 -03:00
Jonhnathan 126fc47101 Update win_apt_tropictrooper.yml 2020-10-15 17:35:41 -03:00
Jonhnathan 3b78c473c8 Update win_apt_slingshot.yml 2020-10-15 17:35:05 -03:00
Jonhnathan c547011499 Update win_apt_mustangpanda.yml 2020-10-15 17:33:44 -03:00
Jonhnathan 82fbfed2c2 Update win_apt_mustangpanda.yml 2020-10-15 17:33:02 -03:00
Jonhnathan a06114d611 Update win_apt_lazarus_session_highjack.yml 2020-10-15 17:31:50 -03:00
Jonhnathan 01bf24b4fc Update win_apt_judgement_panda_gtr19.yml 2020-10-15 17:31:09 -03:00
Jonhnathan 7f5c75ab3e Update win_apt_hurricane_panda.yml 2020-10-15 17:30:34 -03:00
Jonhnathan 0926d76449 Update win_apt_equationgroup_dll_u_load.yml 2020-10-15 17:29:44 -03:00
Jonhnathan 8b593aa309 Update win_apt_empiremonkey.yml 2020-10-15 17:29:19 -03:00
Jonhnathan 00232982b2 Update win_apt_emissarypanda_sep19.yml 2020-10-15 17:28:33 -03:00
Jonhnathan 54f1a0c583 Update win_apt_elise.yml 2020-10-15 17:28:07 -03:00
Jonhnathan d074ea110f Update win_apt_dragonfly.yml 2020-10-15 17:27:42 -03:00
Jonhnathan 5eac9e5161 Update win_apt_cloudhopper.yml 2020-10-15 17:27:27 -03:00
Jonhnathan 2cdead8778 Update win_apt_chafer_mar18.yml 2020-10-15 17:26:58 -03:00
Jonhnathan 96ef4733c3 Update win_apt_bluemashroom.yml 2020-10-15 17:25:17 -03:00
Jonhnathan ca31849be1 Update win_apt_bear_activity_gtr19.yml 2020-10-15 17:24:56 -03:00
Jonhnathan 10522becc3 Update win_apt_apt29_thinktanks.yml 2020-10-15 17:24:03 -03:00
Jonhnathan bc1efd9843 Update sysmon_logon_scripts_userinitmprlogonscript_proc.yml 2020-10-15 17:23:44 -03:00
Jonhnathan fdd9234acc Revert "Create win_susp_replace_lolbin.yml"
This reverts commit e6a6549676.
2020-10-15 14:57:18 -03:00
Jonhnathan 17e7eee3a6 Revert "Changed the rule to download only and not the copy"
This reverts commit 1324bc1ad1.
2020-10-15 14:57:14 -03:00
Sander 0c718d5ce7 Created Win Regedit import rules 2020-10-15 18:14:56 +02:00
Sander 72162125e9 Created Win Regedit export rules 2020-10-15 18:14:25 +02:00
Наталья Шорникова aa1824838f Adding win_manage-bde_lolbas.yml Rule 2020-10-15 17:59:43 +03:00
Наталья Шорникова c3c71a7476 Adding win_CL_Mutexverifiers_LOLScript.yml Rule 2020-10-15 17:51:44 +03:00
Наталья Шорникова be67acd52d Adding win_CL_Invocation_LOLScript.yml Rule 2020-10-15 17:36:18 +03:00
Jonhnathan 8f6ad7df6b Update win_etw_trace_evasion.yml 2020-10-15 09:22:13 -03:00
Ivan Dyachkov 787c87e032 added backslash for image search 2020-10-15 14:01:30 +03:00
OpalSec ffbcb402e3 Creation of Rules for Task 24 - Invoke-Obfuscation VAR+ Launcher 2020-10-15 21:36:27 +11:00
Ivan Dyachkov f79342cc59 fixed image search 2020-10-15 13:21:06 +03:00
uncleP@sk 0018b66e7d The author field escape char added 2020-10-15 11:55:57 +03:00
uncleP@sk 0e8c92a864 The author field escape char added 2020-10-15 11:54:11 +03:00
uncleP@sk 7269114e5d The author field escape char added 2020-10-15 11:52:18 +03:00
uncleP@sk 3a3079789a The author field escape char added 2020-10-15 11:50:56 +03:00
Ivan Dyachkov cf399927e1 uncommented tags 2020-10-15 10:52:54 +03:00
Ivan Dyachkov 5a9c368e9c fixed tags, image search 2020-10-15 10:51:15 +03:00
Vasilisa-L 688e85aefc chertovy testy, prohoditezz 2020-10-15 10:21:01 +03:00
OpalSec 762840ec25 Creation of Rules for Task 25 - Invoke-Obfuscation STDIN+ Launcher 2020-10-15 17:59:36 +11:00
OpalSec efe8773753 Create win_invoke_obfuscation_clip+.yml 2020-10-15 17:56:41 +11:00
Vasilisa-L d0b2c021ce attack.t1059.001 try 2 2020-10-14 16:57:58 +03:00
Ivan Dyachkov 24eb0b92be commented tags 2020-10-14 16:56:52 +03:00
Ivan Dyachkov f005a74c49 commented tags 2020-10-14 16:56:10 +03:00
Ivan Dyachkov f2f7216378 commented tags 2020-10-14 16:32:24 +03:00