Tareq AlKhatib
|
ecffe28933
|
Correct MITRE tag
|
2019-01-22 21:26:07 +03:00 |
|
Tareq AlKhatib
|
925ffae9b8
|
Removed Outlook detection which is a subset of the Office one
|
2019-01-02 07:47:44 +03:00 |
|
yt0ng
|
16160dfc80
|
added additional binaries and attack tactics/techniques
|
2018-07-23 15:47:56 +02:00 |
|
Florian Roth
|
d8bbf26f2c
|
Added msiexec to rule in order to cover new threats
https://twitter.com/DissectMalware/status/984252467474026497
|
2018-04-12 09:12:50 +02:00 |
|
Florian Roth
|
e53826e167
|
Extended Sysmon Office Shell rule
|
2018-04-09 08:37:30 +02:00 |
|
SherifEldeeb
|
48441962cc
|
Change All "str" references to be "list"to mach schema update
|
2018-01-28 02:24:16 +03:00 |
|
SherifEldeeb
|
112a0939d7
|
Change "reference" to "references" to match new schema
|
2018-01-28 02:12:19 +03:00 |
|
Florian Roth
|
b7e8000ccb
|
Improved Office Shell rule > added 'schtasks.exe'
|
2017-10-25 23:53:45 +02:00 |
|
Thomas Patzke
|
986c9ff9b7
|
Added field names to first rules
|
2017-09-12 23:54:04 +02:00 |
|
Florian Roth
|
59821d1bcb
|
Office Shell: Reference added to new entry
|
2017-08-22 10:04:22 +02:00 |
|
Florian Roth
|
8f4a780c3b
|
Added regsvr32.exe to suspicious child processes
|
2017-08-20 23:14:41 +02:00 |
|
Florian Roth
|
edb52e098a
|
Extended hh.exe in Office Shell detection
https://www.hybrid-analysis.com/sample/6abc2b63f1865a847ff7f5a9d49bb944397b36f5503b9718d6f91f93d60f7cd7?environmentId=100
|
2017-08-04 09:18:55 +02:00 |
|
Florian Roth
|
c2ed7bd9df
|
MSHTA Rule v1
|
2017-04-13 01:08:37 +02:00 |
|
Florian Roth
|
a0047f7c67
|
Sysmon as 'service' of product 'windows'
|
2017-03-13 09:23:08 +01:00 |
|
Michael Haag
|
1317fe9df2
|
Modifications
+ Added Sysmon detection of Office binaries spawning Windows shells
+ Additional web servers added for webshell detection
|
2017-03-04 14:22:44 -08:00 |
|