Skip to content

Commit 34c5d66

Browse files
authored
Merge PR #5966 from @nasbench - Update mitre tags to use attack v19
chore: update mitre tags to use attack v19
1 parent 0e3b749 commit 34c5d66

1,612 files changed

Lines changed: 1887 additions & 1867 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

rules-emerging-threats/2014/TA/Axiom/proc_creation_win_apt_zxshell.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ date: 2017-07-20
1010
modified: 2021-11-27
1111
tags:
1212
- attack.execution
13+
- attack.stealth
1314
- attack.t1059.003
14-
- attack.defense-evasion
1515
- attack.t1218.011
1616
- attack.s0412
1717
- attack.g0001

rules-emerging-threats/2014/TA/Turla/proc_creation_win_apt_turla_comrat_may20.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ modified: 2025-10-19
1010
tags:
1111
- attack.privilege-escalation
1212
- attack.persistence
13-
- attack.defense-evasion
13+
- attack.stealth
1414
- attack.g0010
1515
- attack.execution
1616
- attack.t1059.001

rules-emerging-threats/2015/Exploits/CVE-2015-1641/proc_creation_win_exploit_cve_2015_1641.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ author: Florian Roth (Nextron Systems)
99
date: 2018-02-22
1010
modified: 2021-11-27
1111
tags:
12-
- attack.defense-evasion
12+
- attack.stealth
1313
- attack.t1036.005
1414
- cve.2015-1641
1515
- detection.emerging-threats

rules-emerging-threats/2017/Malware/Fireball/proc_creation_win_malware_fireball.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ date: 2017-06-03
1010
modified: 2021-11-27
1111
tags:
1212
- attack.execution
13-
- attack.defense-evasion
13+
- attack.stealth
1414
- attack.t1218.011
1515
- detection.emerging-threats
1616
logsource:

rules-emerging-threats/2017/Malware/Hancitor/proc_access_win_malware_verclsid_shellcode.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ author: John Lambert (tech), Florian Roth (Nextron Systems)
88
date: 2017-03-04
99
modified: 2021-11-27
1010
tags:
11-
- attack.defense-evasion
1211
- attack.privilege-escalation
12+
- attack.stealth
1313
- attack.t1055
1414
- detection.emerging-threats
1515
logsource:

rules-emerging-threats/2017/Malware/NotPetya/proc_creation_win_malware_notpetya.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,10 @@ author: Florian Roth (Nextron Systems), Tom Ueltschi
99
date: 2019-01-16
1010
modified: 2022-12-15
1111
tags:
12-
- attack.defense-evasion
12+
- attack.stealth
13+
- attack.defense-impairment
1314
- attack.t1218.011
14-
- attack.t1070.001
15+
- attack.t1685.005
1516
- attack.credential-access
1617
- attack.t1003.001
1718
- car.2016-04-002

rules-emerging-threats/2017/Malware/PlugX/proc_creation_win_malware_plugx_susp_exe_locations.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,9 @@ modified: 2023-02-03
1111
tags:
1212
- attack.privilege-escalation
1313
- attack.persistence
14+
- attack.execution
15+
- attack.stealth
1416
- attack.s0013
15-
- attack.defense-evasion
1617
- attack.t1574.001
1718
- detection.emerging-threats
1819
logsource:

rules-emerging-threats/2017/Malware/WannaCry/proc_creation_win_malware_wannacry.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,10 +10,10 @@ date: 2019-01-16
1010
modified: 2025-10-18
1111
tags:
1212
- attack.lateral-movement
13+
- attack.defense-impairment
1314
- attack.t1210
1415
- attack.discovery
1516
- attack.t1083
16-
- attack.defense-evasion
1717
- attack.t1222.001
1818
- attack.impact
1919
- attack.t1486

rules-emerging-threats/2017/TA/Dragonfly/proc_creation_win_apt_ta17_293a_ps.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ author: Florian Roth (Nextron Systems)
88
date: 2017-10-22
99
modified: 2023-05-02
1010
tags:
11-
- attack.defense-evasion
11+
- attack.stealth
1212
- attack.g0035
1313
- attack.t1036.003
1414
- car.2013-05-009

rules-emerging-threats/2017/TA/Lazarus/proc_creation_win_apt_lazarus_binary_masquerading.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ author: Trent Liffick (@tliffick), Bartlomiej Czyz (@bczyz1)
88
date: 2020-06-03
99
modified: 2023-03-10
1010
tags:
11-
- attack.defense-evasion
11+
- attack.stealth
1212
- attack.t1036.005
1313
- detection.emerging-threats
1414
logsource:

0 commit comments

Comments
 (0)