Florian Roth
|
bf93ee34d5
|
APT Buckeye
|
2016-09-10 01:16:28 +02:00 |
|
Florian Roth
|
0a1648519f
|
PowerShell Toolkit YARA Rules
|
2016-09-04 18:19:57 +02:00 |
|
Florian Roth
|
c8617942ce
|
Malware Set QA
|
2016-09-02 08:50:46 +02:00 |
|
Florian Roth
|
54f6aecd44
|
Removed duplicate rule
|
2016-08-31 14:34:21 +02:00 |
|
Florian Roth
|
0dfc21592c
|
WCE in-memory rule
|
2016-08-30 19:41:30 +02:00 |
|
Florian Roth
|
8b303b41e3
|
JSP Webshell Names by Cisco Talos
|
2016-08-30 19:41:19 +02:00 |
|
Florian Roth
|
ffe3aca416
|
Removed C2 prone to false positives
|
2016-08-27 00:21:23 +02:00 |
|
Florian Roth
|
08ebcc5b36
|
OTX Update and b374k back connect shell
|
2016-08-26 21:43:11 +02:00 |
|
Florian Roth
|
de84c3ae42
|
Device Guard Evasion
|
2016-08-18 08:44:27 +02:00 |
|
Florian Roth
|
c8d65ddbc4
|
PlugX Signature by Jay DiMartino
PDF
https://t.co/4xQ8G2mNap
|
2016-08-17 13:20:52 +02:00 |
|
Florian Roth
|
1fe1837c0f
|
Rule based on RC5/RC6 static key finding by Kaspersky
|
2016-08-17 09:32:56 +02:00 |
|
Florian Roth
|
cdb364758a
|
EQRP Extra Rules
|
2016-08-16 21:35:42 +02:00 |
|
Florian Roth
|
366abc510a
|
Equation Group Firewall Toolset Leak YARA Rules (First Set)
|
2016-08-16 20:37:13 +02:00 |
|
Florian Roth
|
e3ada3ee24
|
Renamed Webshell Rules
|
2016-08-16 20:32:06 +02:00 |
|
Florian Roth
|
9a23aba2c4
|
Merge pull request #3 from jonaslejon/master
Add new mimkatz yara-signature
|
2016-08-15 14:51:19 +02:00 |
|
Jonas Lejon
|
eea36d5ce0
|
Add new mimkatz yara-signature
From https://blog.didierstevens.com/2016/08/12/mimikatz-golden-ticket-dcsync/
|
2016-08-13 18:39:22 +02:00 |
|
Florian Roth
|
94b3b52a67
|
OTX - Threat Exchange Update
|
2016-08-12 13:56:15 +02:00 |
|
Florian Roth
|
754d19604d
|
Invoke-Mimikatz Rule
- useful to impress PowerShell hipsters
|
2016-08-10 09:35:08 +02:00 |
|
Florian Roth
|
2c5005744c
|
My Sauron Extra Rules
|
2016-08-10 09:34:15 +02:00 |
|
Florian Roth
|
dad52eb4a0
|
Symantec Strider IOCs and YARA Rules
|
2016-08-10 09:33:54 +02:00 |
|
Florian Roth
|
f10ecb5929
|
Project Sauron IOCs
|
2016-08-08 17:29:28 +02:00 |
|
Florian Roth
|
eca6d816f1
|
Project Sauron
|
2016-08-08 17:11:20 +02:00 |
|
Florian Roth
|
630db83081
|
Renamed Rule
|
2016-08-01 16:57:58 +02:00 |
|
Florian Roth
|
2db411300f
|
Generic Rule - Transformed Strings
|
2016-08-01 08:31:33 +02:00 |
|
Florian Roth
|
2ecac1d2c1
|
CKnife Webshell - by Levi
|
2016-07-20 13:31:11 +02:00 |
|
Florian Roth
|
37f8738c9e
|
Mimikittenz
|
2016-07-20 13:30:10 +02:00 |
|
Florian Roth
|
0c6838db9a
|
OTX False Positives
|
2016-07-20 13:29:53 +02:00 |
|
Florian Roth
|
7a68156e21
|
Furtims Parent
https://sentinelone.com/blogs/sfg-furtims-parent/
|
2016-07-17 12:59:29 +02:00 |
|
Florian Roth
|
09c01737cc
|
Filename IOCs
|
2016-07-16 11:19:40 +02:00 |
|
Florian Roth
|
e63f5f890d
|
Furtim Malware
|
2016-07-16 11:03:15 +02:00 |
|
Florian Roth
|
69f96e2011
|
Stuxnet Rules
- YARA Rules
- Hash IOCs
|
2016-07-11 19:48:03 +02:00 |
|
Florian Roth
|
13ab3e4876
|
Power PE Reflective Injection Rule by Benjamin Delpy
|
2016-07-11 19:47:37 +02:00 |
|
Florian Roth
|
e264d66a8e
|
Bugfix in Duqu2 Rule
|
2016-07-02 19:35:33 +02:00 |
|
Florian Roth
|
76791e7254
|
False Positive Reduction
|
2016-07-02 19:32:50 +02:00 |
|
Florian Roth
|
5f664abbd0
|
SysScan Rules by Kaspersky
|
2016-07-02 19:32:36 +02:00 |
|
Florian Roth
|
37c1835ae7
|
Fancy / Cozy Bear Sigs
|
2016-07-02 19:32:02 +02:00 |
|
Florian Roth
|
652a44d586
|
Duqu2 Sigs
|
2016-07-02 19:31:34 +02:00 |
|
Florian Roth
|
669bb122ec
|
OTX Update
|
2016-07-02 19:31:25 +02:00 |
|
Florian Roth
|
a248f3d8a9
|
Bugfix in prikormka Rules
|
2016-06-17 17:24:28 +02:00 |
|
Florian Roth
|
a1927bb1e5
|
FoxIT Mofang IOCs and YARA Rules
https://goo.gl/t3uUTG
|
2016-06-15 18:58:10 +02:00 |
|
Florian Roth
|
a3323e83aa
|
Sofacy Samples June 2016
http://researchcenter.paloaltonetworks.com/2016/06/unit42-new-sofacy-att
acks-against-us-government-agency/
|
2016-06-15 06:54:30 +02:00 |
|
Florian Roth
|
65ee46b9c9
|
Turla Rules - RUAG APT
https://goo.gl/N5MEj0
|
2016-06-13 10:41:59 +02:00 |
|
Florian Roth
|
b3a3556dcc
|
SharpCat YARA Signature
|
2016-06-10 18:14:26 +02:00 |
|
Florian Roth
|
1b9ba2eb17
|
Dubnium YARA Signatures
https://blogs.technet.microsoft.com/mmpc/2016/06/09/reverse-engineering-
dubnium-2/
|
2016-06-10 17:03:29 +02:00 |
|
Florian Roth
|
a27d6ee020
|
Sickly Nidiran Trojan YARA Signatures
|
2016-06-09 09:37:59 +02:00 |
|
Florian Roth
|
f23819ce94
|
Adjusted YARA Rule
|
2016-06-08 21:08:44 +02:00 |
|
Florian Roth
|
21cb4b1a45
|
PlugX Rules for Sample Set June 2016
|
2016-06-08 20:54:12 +02:00 |
|
Florian Roth
|
3b0ad587a7
|
Minor Changes to YARA Rules
|
2016-06-08 11:28:42 +02:00 |
|
Florian Roth
|
16de1a3b72
|
OTX Update
- Removed some Sofacy C2 False Positives
|
2016-06-08 11:28:22 +02:00 |
|
Florian Roth
|
f6c188143d
|
Merge branch 'master' of https://github.com/Neo23x0/signature-base
|
2016-06-04 17:39:00 +02:00 |
|