Commit e93915f
authored
Add file type support for report generation (#898)
* Add file type support for report generation
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* More rules
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Tweak Discord rule
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix up tests
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix up Windows samples
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Run make yara-x-fmt
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix merge conflict artifacts
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Remove JSON from map
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix test
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Use kind.Ext instead of kind.MIME
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix Slack test
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix up rename reporting
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Add more file types to explicit_rename
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Fix up remaining PHP filetypes
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Remove redundant programkind condition
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Add more file types to rules
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Loosen up execution policy rules
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* More rule tweaks
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
---------
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
Signed-off-by: Evan Gibler <20933572+egibs@users.noreply.github.com>1 parent 553cb87 commit e93915f
305 files changed
Lines changed: 795 additions & 884 deletions
File tree
- pkg
- action
- testdata
- programkind
- report
- rules
- anti-behavior
- anti-static
- base64
- elf
- macho
- obfuscation
- packer
- unmarshal
- c2
- addr
- connect
- discovery
- tool_transfer
- collect
- archives
- credential
- crypto
- data
- base64
- builtin
- discover
- processes
- system
- user
- evasion
- indicator_blocking
- logging
- net
- rootkit
- self_deletion
- time
- exec
- cmd
- imports
- install_additional
- program
- remote_commands
- shell
- exfil
- stealer
- fs
- attributes
- directory
- file
- path
- impact
- degrade
- ransom
- remote_access
- resource
- wipe
- lateral/scan
- malware/family
- mem
- net
- download
- http
- resolve
- socket
- ssl
- udp
- persist
- kernel_module
- systemd
- privesc
- process
- sus
- tests
- c/clean/ruby_http_parser
- javascript
- 2022.an-instance.99.10.9
- 2024.lottie-player
- 2024.obfuscated
- clean
- linux
- 2020.bdvl
- 2021.XMR-Stak
- 2022.Symbiote
- 2022.ez-pwnkit
- 2024.Kaiji
- 2024.TellYouThePass
- 2024.chisel
- 2024.clobber_xmrig
- 2024.hadooken
- 2024.k4spreader
- 2024.kworker_pretenders
- 2024.melofee
- 2024.vncjew
- clean
- kibana
- kolide
- mimipenguin
- bash
- python
- synthetic
- macOS
- 2023.3CX
- 2024.79-137-192-4
- 2024.Rustdoor
- 2024.cobaltstrike
- npm
- 2024.bugsnagmw
- 2024.harthat
- 2024.hlwgirl
- 2024.legacyreact-aws-s3-typescript
- 2024.next-react-notify
- 2024.persona-tool
- 2024.solana_web3
- php
- 2024.S3RV4N7-SHELL
- 2024.WordFence.evasion
- 2024.malcure
- 2024.sagsooz
- clean
- python
- 2022.PyPI.valyrian_debug
- 2024.Custom.RAT
- 2024.RookeryCapital_PythonTest
- 2024.ScreenLocker
- 2024.krypton_ddos
- 2024.obfuscation
- 2024.pyobfuscate
- 2024.ultralytics
- v8.3.41/utils
- v8.3.46
- clean
- google-auth-library-python
- google-cloud-sdk
- numpy
- requests
- setuptools
- ruby
- 2018.CMD_Backdoor
- 2021.vector
- 2024.Infecting_Simulation
- 2024.Ruby_rootkit
- 2024.gtfo
- 2024.reverse_shells
- windows
- 2024.GitHub.Clipper
- 2024.aspdasdksa2
- clean
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
159 | 159 | | |
160 | 160 | | |
161 | 161 | | |
162 | | - | |
| 162 | + | |
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
82 | | - | |
83 | | - | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
89 | 105 | | |
90 | | - | |
| 106 | + | |
91 | 107 | | |
92 | 108 | | |
93 | 109 | | |
| |||
173 | 189 | | |
174 | 190 | | |
175 | 191 | | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
176 | 203 | | |
177 | 204 | | |
178 | 205 | | |
| |||
1071 | 1098 | | |
1072 | 1099 | | |
1073 | 1100 | | |
1074 | | - | |
| 1101 | + | |
| 1102 | + | |
1075 | 1103 | | |
1076 | 1104 | | |
1077 | 1105 | | |
| |||
1080 | 1108 | | |
1081 | 1109 | | |
1082 | 1110 | | |
1083 | | - | |
| 1111 | + | |
1084 | 1112 | | |
1085 | | - | |
| 1113 | + | |
1086 | 1114 | | |
1087 | | - | |
1088 | | - | |
1089 | | - | |
| 1115 | + | |
| 1116 | + | |
| 1117 | + | |
1090 | 1118 | | |
1091 | | - | |
| 1119 | + | |
1092 | 1120 | | |
1093 | 1121 | | |
1094 | 1122 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
| 74 | + | |
74 | 75 | | |
75 | 76 | | |
| 77 | + | |
76 | 78 | | |
77 | 79 | | |
| 80 | + | |
| 81 | + | |
78 | 82 | | |
| 83 | + | |
79 | 84 | | |
80 | 85 | | |
| 86 | + | |
81 | 87 | | |
82 | 88 | | |
83 | 89 | | |
| |||
209 | 215 | | |
210 | 216 | | |
211 | 217 | | |
212 | | - | |
| 218 | + | |
213 | 219 | | |
214 | 220 | | |
215 | 221 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
20 | 21 | | |
21 | 22 | | |
22 | 23 | | |
| |||
364 | 365 | | |
365 | 366 | | |
366 | 367 | | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
367 | 380 | | |
368 | | - | |
| 381 | + | |
369 | 382 | | |
370 | 383 | | |
371 | 384 | | |
| |||
425 | 438 | | |
426 | 439 | | |
427 | 440 | | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
428 | 445 | | |
429 | 446 | | |
430 | 447 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| 17 | + | |
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
| |||
27 | 29 | | |
28 | 30 | | |
29 | 31 | | |
| 32 | + | |
30 | 33 | | |
31 | 34 | | |
32 | 35 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
| 20 | + | |
19 | 21 | | |
20 | 22 | | |
21 | 23 | | |
| |||
45 | 47 | | |
46 | 48 | | |
47 | 49 | | |
| 50 | + | |
48 | 51 | | |
49 | 52 | | |
50 | 53 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
| |||
32 | 33 | | |
33 | 34 | | |
34 | 35 | | |
| 36 | + | |
35 | 37 | | |
36 | 38 | | |
37 | 39 | | |
| |||
43 | 45 | | |
44 | 46 | | |
45 | 47 | | |
| 48 | + | |
46 | 49 | | |
47 | 50 | | |
48 | 51 | | |
| |||
54 | 57 | | |
55 | 58 | | |
56 | 59 | | |
| 60 | + | |
57 | 61 | | |
58 | 62 | | |
59 | 63 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
| |||
14 | 15 | | |
15 | 16 | | |
16 | 17 | | |
| 18 | + | |
17 | 19 | | |
18 | 20 | | |
19 | 21 | | |
| |||
25 | 27 | | |
26 | 28 | | |
27 | 29 | | |
| 30 | + | |
28 | 31 | | |
29 | 32 | | |
30 | 33 | | |
| |||
37 | 40 | | |
38 | 41 | | |
39 | 42 | | |
| 43 | + | |
40 | 44 | | |
41 | 45 | | |
42 | 46 | | |
| |||
49 | 53 | | |
50 | 54 | | |
51 | 55 | | |
| 56 | + | |
52 | 57 | | |
53 | 58 | | |
54 | 59 | | |
| |||
61 | 66 | | |
62 | 67 | | |
63 | 68 | | |
| 69 | + | |
64 | 70 | | |
65 | 71 | | |
66 | 72 | | |
| |||
0 commit comments