Commit Graph

387 Commits

Author SHA1 Message Date
Florian Roth
7d5227d20f Removed WebShell_Generic_PHP_5 prone to false positives 2017-02-16 19:41:26 +01:00
Florian Roth
2cd4d7b422 Deactivated False Positives in Grizzly Steppe Rules - US CERT 2017-02-12 18:26:02 +01:00
Florian Roth
c19ef7de0d OTX Update 2017-02-11 12:14:11 +01:00
Florian Roth
6534da8d3a Cosmetics 2017-02-11 12:01:31 +01:00
Florian Roth
2f42964d1d Removed duplicate rule StreamEx_ShellCrew 2017-02-11 11:38:12 +01:00
Florian Roth
8d577f57b0 US CERT Grizzly Steppe Report 2017-02-11 11:36:10 +01:00
Florian Roth
0069690f19 Remove False Positive Rules 2017-02-10 10:40:52 +01:00
Florian Roth
dd8d5585f0 Metasploit Payloads 2017-02-10 10:40:21 +01:00
Florian Roth
e4c17818b6 Shell Crew StreamEx 2017-02-10 10:23:29 +01:00
Florian Roth
ce887d4eb3 Rotten Potato - Avoiding False Positives 2017-02-07 17:58:44 +01:00
Florian Roth
291833ccdd Winnti malware MS Report 2017-02-07 10:45:19 +01:00
Florian Roth
b80152fbc2 Servant Shell 2017-02-07 10:37:26 +01:00
Florian Roth
959f30b62d Rotten Potato 2017-02-07 09:20:10 +01:00
Florian Roth
376dcfcf5e ysoserial payloads 2017-02-05 13:27:10 +01:00
Florian Roth
2a7c06adf8 CN APT Proofpoint ZeroT RAT 2017-02-05 13:26:03 +01:00
Florian Roth
4b1abf072e New build of OTX receiver with new SDK 2017-02-05 13:25:01 +01:00
Florian Roth
a384dd543d Private Rule Bugfix 2017-02-03 22:04:51 +01:00
Florian Roth
3a737e0ea8 FP Reduction 2017-02-03 21:59:32 +01:00
Florian Roth
6ace90f226 UAC Elevators Update 2017-02-03 21:59:14 +01:00
Florian Roth
d0ff872894 OTX Update 2017-02-01 17:57:23 +01:00
Florian Roth
896b6eeb99 Minor changes 2017-01-31 18:47:29 +01:00
Florian Roth
df58486639 FP avoidance 2017-01-28 12:49:14 +01:00
Florian Roth
6ddaf42ec3 Google Bot User Agent 2017-01-28 11:39:32 +01:00
Florian Roth
2ca25d1c00 Greenbug YARA rules 2017-01-26 14:00:36 +01:00
Florian Roth
7b16da5081 P0wnShell 2017-01-15 16:30:56 +01:00
Florian Roth
8b8e11282d EquationGroup Rules Update 2017-01-14 19:38:43 +01:00
Florian Roth
58b7514527 Merge branch 'master' of https://github.com/Neo23x0/signature-base 2017-01-14 19:38:12 +01:00
Florian Roth
b5776d6971 Venom Linux Rootkit 2017-01-14 19:38:06 +01:00
Florian Roth
8e2e39196a FScan output 2017-01-14 19:28:47 +01:00
Florian Roth
14a8c75e89 Merged branch master into master 2017-01-10 11:12:00 +01:00
Florian Roth
72ff9fae4d ShadowBrokers Screens File Names Jan17 2017-01-10 11:07:04 +01:00
Florian Roth
eec5a37407 Updated Grizzly Steppe
- include more PHP Web kit Versions
2017-01-02 08:10:21 +01:00
Florian Roth
4112bc4ebf Renamed APT29 YARA rule file 2016-12-30 10:38:03 +01:00
Florian Roth
eb25fa4a1c Grizzly Steppe YARA Rules 2016-12-30 10:36:35 +01:00
Florian Roth
02b006d92b RAT YARA rules from malwareconfig.com
Thx to Kevin Breen
2016-12-27 23:26:07 +01:00
Florian Roth
ceb33d261d Telebots YARA Rule 2016-12-27 23:23:59 +01:00
Florian Roth
473ca25339 Promethium Neodymium YARA Rules 2016-12-27 23:23:46 +01:00
Florian Roth
54e1276cd1 False Positive - PipeList 2016-12-27 23:20:01 +01:00
Florian Roth
a568be5030 File Type Signature - Windows Registry Files 2016-12-27 23:19:03 +01:00
Florian Roth
1f78a4e321 OTX Update 2016-12-27 23:18:34 +01:00
Florian Roth
50f14d7d1d ShadowBroker Screens File Names 2016-12-18 12:20:09 +01:00
Florian Roth
f485f9bc93 Merged branch master into master 2016-12-18 11:43:28 +01:00
Florian Roth
524bee2139 ShadowBroker Screens / README Extractions 2016-12-18 11:41:35 +01:00
Florian Roth
230713a9e7 SysInternals Anomalies 2016-12-09 00:20:38 +01:00
Florian Roth
cb85ea73ca GoldenEye Ransomware 2016-12-06 17:13:12 +01:00
Florian Roth
86e45a3e70 Shamoon 2.0 Rev1 2016-12-01 23:02:21 +01:00
Florian Roth
a9ff4c43c1 Regshell False Positive 2016-12-01 22:44:48 +01:00
Florian Roth
83daf31b8e Shamoon 2.0 2016-12-01 22:44:35 +01:00
Florian Roth
86de943e70 False Positive Reduced 2016-11-29 17:50:21 +01:00
Florian Roth
3e7ce48830 Changed duplicate rule name 2016-11-12 12:26:55 +01:00