Skip to content

Commit

Permalink
chore: move more rules
Browse files Browse the repository at this point in the history
  • Loading branch information
nasbench committed Apr 21, 2023
1 parent 7f88625 commit b26f9a9
Show file tree
Hide file tree
Showing 17 changed files with 11 additions and 3 deletions.
1 change: 1 addition & 0 deletions rules-compliance/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
1 change: 1 addition & 0 deletions rules-deprecated/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
1 change: 1 addition & 0 deletions rules-dfir/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ id: 33a2d1dd-f3b0-40bd-8baf-7974468927cc
status: test
description: Detects an image load pattern as seen when a tool named PRIVATELOG is used and rarely observed under legitimate circumstances
references:
- https://www.fireeye.com/blog/threat-research/2021/09/unknown-actor-using-clfs-log-files-for-stealth.html
- https://web.archive.org/web/20210901184449/https://www.fireeye.com/blog/threat-research/2021/09/unknown-actor-using-clfs-log-files-for-stealth.html
author: Florian Roth (Nextron Systems)
date: 2021/09/07
modified: 2022/10/09
Expand Down
1 change: 1 addition & 0 deletions rules-emerging-threats/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
1 change: 1 addition & 0 deletions rules-placeholder/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
1 change: 1 addition & 0 deletions rules-threat-hunting/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
1 change: 1 addition & 0 deletions rules-unsupported/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
1 change: 1 addition & 0 deletions rules/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TBD
4 changes: 2 additions & 2 deletions rules/web/proxy_generic/proxy_apt_domestic_kitten.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
title: Domestic Kitten FurBall Malware Pattern
id: 6c939dfa-c710-4e12-a4dd-47e1f10e68e1
status: test
status: deprecated
description: Detects specific malware patterns used by FurBall malware linked to Iranian Domestic Kitten APT group
references:
- https://research.checkpoint.com/2021/domestic-kitten-an-inside-look-at-the-iranian-surveillance-operations/
author: Florian Roth (Nextron Systems)
date: 2021/02/08
modified: 2022/10/09
modified: 2023/04/20
tags:
- attack.command_and_control
logsource:
Expand Down

0 comments on commit b26f9a9

Please sign in to comment.