Commit 34c5d66
File tree
- rules-emerging-threats
- 2014/TA
- Axiom
- Turla
- 2015/Exploits/CVE-2015-1641
- 2017
- Malware
- Fireball
- Hancitor
- NotPetya
- PlugX
- WannaCry
- TA
- Dragonfly
- Lazarus
- 2018/TA
- APT27
- APT28
- APT29-CozyBear
- APT32-Oceanlotus
- MuddyWater
- OilRig
- 2019
- Exploits
- CVE-2019-1378
- CVE-2019-14287
- Malware
- BabyShark
- Dridex
- Emotet
- Ursnif
- TA
- APC-C-12
- EmpireMonkey
- EquationGroup
- Operation-Wocao
- 2020
- Exploits/CVE-2020-1048
- Malware
- Blue-Mockingbird
- ComRAT
- Emotet
- FlowCloud
- Ke3chang-TidePool
- TA
- Evilnum
- Greenbug
- TAIDOOR-RAT
- Winnti
- 2021
- Exploits
- CVE-2021-1675
- CVE-2021-4034
- CVE-2021-40444
- CVE-2021-42287
- RazerInstaller-LPE-Exploit
- Malware
- BlackByte
- Devil-Bait
- Goofy-Guineapig
- Netwire
- Pingback
- Small-Sieve
- TA/PRIVATELOG
- 2022
- Exploits/CVE-2022-30190
- Malware/Bumblebee
- 2023
- Exploits/CVE-2023-36884
- Malware
- COLDSTEEL
- GuLoader
- IcedID
- Pikabot
- Qakbot
- Rhadamanthys
- Rorschach
- TA
- 3CX-Supply-Chain
- Cozy-Bear
- Diamond-Sleet
- Lazarus
- UNC4841-Barracuda-ESG-Zero-Day-Exploitation
- 2024
- Exploits
- CVE-2024-1709
- CVE-2024-3400
- Malware
- Lummac-Stealer
- Raspberry-Robin
- kapeka
- TA
- Forest-Blizzard
- SlashAndGrab-Exploitation-In-Wild
- 2025
- Exploits
- CVE-2025-33053
- CVE-2025-49144
- CVE-2025-57788
- CVE_2025_4598
- Malware/Atomic-MacOS-Stealer
- 2026
- Exploits/RedSun
- Malware/Axios-NPM-Compromise
- rules-placeholder
- cloud
- aws/cloudtrail
- azure
- audit_logs
- signin_logs
- identity/okta
- windows/builtin/security
- rules-threat-hunting
- cloud/m365/audit
- linux
- file/file_event
- process_creation
- windows
- builtin/firewall_as
- create_remote_thread
- file
- file_access
- file_change
- file_delete
- file_event
- file_rename
- image_load
- network_connection
- powershell/powershell_script
- process_access
- process_creation
- registry/registry_set
- rules
- application
- bitbucket/audit
- github/audit
- kubernetes/audit
- opencanary
- rpc_firewall
- cloud
- aws/cloudtrail
- azure
- activity_logs
- audit_logs
- identity_protection
- privileged_identity_management
- signin_logs
- gcp
- audit
- gworkspace/login
- m365
- audit
- threat_management
- identity
- cisco_duo
- okta
- linux
- auditd
- execve
- path
- service_stop
- syscall
- builtin
- syslog
- file_event
- process_creation
- macos/process_creation
- network
- cisco
- aaa
- bgp
- ldp
- fortinet/fortigate
- huawei/bgp
- juniper/bgp
- web
- proxy_generic
- webserver_generic
- windows
- builtin
- application
- application_error
- microsoft-windows_audit_cve
- microsoft_windows_backup
- microsoft_windows_software_restriction_policies
- msiinstaller
- mssqlserver
- windows_error_reporting
- appmodel_runtime
- appxdeployment_server
- appxpackaging_om
- bits_client
- dns_server
- firewall_as
- iis-configuration
- msexchange
- ntlm
- security_mitigations
- security
- account_management
- object_access
- system
- application_popup
- lsasrv
- microsoft_windows_certification_authority
- microsoft_windows_dhcp_server
- microsoft_windows_eventlog
- netlogon
- service_control_manager
- windefend
- create_remote_thread
- create_stream_hash
- dns_query
- driver_load
- file
- file_delete
- file_event
- file_executable_detected
- image_load
- network_connection
- pipe_created
- powershell
- powershell_classic
- powershell_module
- powershell_script
- process_access
- process_creation
- process_tampering
- raw_access_thread
- registry
- registry_delete
- registry_event
- registry_set
- sysmon
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | | - | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
12 | 11 | | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| |||
Lines changed: 3 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
| 13 | + | |
13 | 14 | | |
14 | | - | |
| 15 | + | |
15 | 16 | | |
16 | 17 | | |
17 | 18 | | |
| |||
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
14 | 16 | | |
15 | | - | |
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
16 | | - | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| |||
0 commit comments