Commit f3941a7
authored
Add rule for recent Crate compromises; run fmt to pick up new yara-x newline formatting (#1140)
* Add rule for recent Crate compromises; run fmt to pick up new yara-x newline formatting
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Expand additional rules to capture the URL IOC
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Better regex string naming
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
---------
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>1 parent f84894f commit f3941a7
71 files changed
Lines changed: 42 additions & 68 deletions
File tree
- rules
- anti-static
- obfuscation
- xor
- c2
- addr
- connect
- tool_transfer
- credential
- cloud
- gaming
- crypto
- data
- embedded
- encoding
- random
- discover/cloud
- evasion
- bypass_security/linux
- file
- location
- prefix
- mimicry
- exec/dylib
- exfil
- stealer
- false_positives
- fs
- file
- path
- proc
- hw
- impact
- remote_access
- ui
- lateral/ssh
- malware
- family
- net
- ssl
- url
- os
- fd
- kernel
- time
- privesc
- process
- group
- terminate
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
76 | 76 | | |
77 | 77 | | |
78 | 78 | | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
79 | 91 | | |
80 | 92 | | |
81 | 93 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
0 commit comments