Commit f64ea6b
File tree
- .github
- workflows
- deprecated
- windows
- other
- regression_data
- rules-emerging-threats
- 2025/Malware/Shai-Hulud
- proc_creation_win_mal_shai_hulud_indicator
- proc_creation_win_mal_shai_hulud_malicious_node_bun_execution
- proc_creation_win_mal_shai_hulud_malicious_npm_package_installation
- 2026/Exploits
- CVE-2026-33829/proc_creation_win_exploit_cve_2026_33829
- RedSun
- file_event_win_exploit_redsun_indicators
- pipe_created_win_exploit_redsun_named_pipe
- win_defender_exploit_redsun_tiering_engine_detected_as_eicar
- rules-threat-hunting/windows/image_load/image_load_win_werfaultsecure_dbgcore_dbghelp_load
- rules
- cisco/aaa/cisco_cli_dot1x_disabled
- windows
- builtin
- security/win_security_susp_scheduled_task_delete_or_disable
- taskscheduler/win_taskscheduler_susp_schtasks_delete_or_disable
- file/file_event
- file_event_win_hktl_netexec_file_indicators
- file_event_win_susp_right_to_left_override_extension_spoofing
- image_load
- image_load_side_load_cpl_from_non_system_location
- image_load_side_load_vcruntime140
- process_creation
- proc_creation_win_autologger_session_registry_modification
- proc_creation_win_hktl_netexec
- proc_creation_win_lolbin_sftp_indirect_cmd_execution
- proc_creation_win_print_dump_sensitive_files
- proc_creation_win_pua_memprocfs
- proc_creation_win_pua_trufflehog
- proc_creation_win_python_base64_encoded_execution
- proc_creation_win_reg_system_language_discovery
- proc_creation_win_reg_system_restore_modification
- proc_creation_win_schtasks_delete
- proc_creation_win_schtasks_disable
- proc_creation_win_susp_right_to_left_override
- proc_creation_win_susp_script_interpretor_spawn_credential_scanner
- proc_creation_win_susp_system_exe_anomaly
- proc_creation_win_svchost_masqueraded_execution
- proc_creation_win_user_shell_folders_registry_modification
- proc_creation_win_wmic_service_startup_change
- registry/registry_set
- registry_set_disable_autologger_sessions
- registry_set_disable_system_restore
- registry_set_susp_user_shell_folders
- rules-emerging-threats
- 2014/TA
- Axiom
- Turla
- 2015/Exploits/CVE-2015-1641
- 2017
- Malware
- Fireball
- Hancitor
- NotPetya
- PlugX
- WannaCry
- TA
- Dragonfly
- Lazarus
- 2018/TA
- APT27
- APT28
- APT29-CozyBear
- APT32-Oceanlotus
- MuddyWater
- OilRig
- 2019
- Exploits
- CVE-2019-1378
- CVE-2019-14287
- Malware
- BabyShark
- Dridex
- Emotet
- Ursnif
- TA
- APC-C-12
- EmpireMonkey
- EquationGroup
- Operation-Wocao
- 2020
- Exploits/CVE-2020-1048
- Malware
- Blue-Mockingbird
- ComRAT
- Emotet
- FlowCloud
- Ke3chang-TidePool
- TA
- Evilnum
- Greenbug
- TAIDOOR-RAT
- Winnti
- 2021
- Exploits
- CVE-2021-1675
- CVE-2021-4034
- CVE-2021-40444
- CVE-2021-42287
- RazerInstaller-LPE-Exploit
- Malware
- BlackByte
- Devil-Bait
- Goofy-Guineapig
- Netwire
- Pingback
- Small-Sieve
- TA/PRIVATELOG
- 2022
- Exploits/CVE-2022-30190
- Malware/Bumblebee
- 2023
- Exploits/CVE-2023-36884
- Malware
- COLDSTEEL
- GuLoader
- IcedID
- Pikabot
- Qakbot
- Rhadamanthys
- Rorschach
- TA
- 3CX-Supply-Chain
- Cozy-Bear
- Diamond-Sleet
- Lazarus
- Okta-Support-System-Breach
- UNC4841-Barracuda-ESG-Zero-Day-Exploitation
- 2024
- Exploits
- CVE-2024-1709
- CVE-2024-3400
- Malware
- Lummac-Stealer
- Raspberry-Robin
- kapeka
- TA
- Forest-Blizzard
- SlashAndGrab-Exploitation-In-Wild
- 2025
- Exploits
- CVE-2025-32463
- CVE-2025-33053
- CVE-2025-49144
- CVE-2025-57788
- CVE_2025_4598
- Malware
- Atomic-MacOS-Stealer
- Shai-Hulud
- 2026
- Exploits
- CVE-2026-33829
- RedSun
- Malware/Axios-NPM-Compromise
- TA/TeamPCP
- rules-placeholder
- cloud
- aws/cloudtrail
- azure
- audit_logs
- signin_logs
- identity/okta
- windows/builtin/security
- rules-threat-hunting
- cloud
- azure/signin_logs
- m365/audit
- linux
- file/file_event
- process_creation
- windows
- builtin/firewall_as
- create_remote_thread
- file
- file_access
- file_change
- file_delete
- file_event
- file_rename
- image_load
- network_connection
- powershell/powershell_script
- process_access
- process_creation
- registry/registry_set
- rules
- application
- bitbucket/audit
- github/audit
- kubernetes/audit
- opencanary
- rpc_firewall
- cloud
- aws/cloudtrail
- azure
- activity_logs
- audit_logs
- identity_protection
- privileged_identity_management
- signin_logs
- gcp
- audit
- gworkspace
- admin
- login
- m365
- audit
- threat_management
- identity
- cisco_duo
- okta
- linux
- auditd
- execve
- path
- service_stop
- syscall
- builtin
- syslog
- file_event
- process_creation
- macos/process_creation
- network
- cisco
- aaa
- bgp
- ldp
- fortinet/fortigate
- huawei/bgp
- juniper/bgp
- web
- proxy_generic
- webserver_generic
- windows
- builtin
- application
- application_error
- microsoft-windows_audit_cve
- microsoft_windows_backup
- microsoft_windows_software_restriction_policies
- msiinstaller
- mssqlserver
- windows_error_reporting
- appmodel_runtime
- appxdeployment_server
- appxpackaging_om
- bits_client
- code_integrity
- dns_server
- firewall_as
- iis-configuration
- msexchange
- ntlm
- security_mitigations
- security
- account_management
- object_access
- system
- application_popup
- lsasrv
- microsoft_windows_certification_authority
- microsoft_windows_dhcp_server
- microsoft_windows_eventlog
- netlogon
- service_control_manager
- taskscheduler
- windefend
- create_remote_thread
- create_stream_hash
- dns_query
- driver_load
- file
- file_delete
- file_event
- file_executable_detected
- image_load
- network_connection
- pipe_created
- powershell
- powershell_classic
- powershell_module
- powershell_script
- process_access
- process_creation
- process_tampering
- raw_access_thread
- registry
- registry_delete
- registry_event
- registry_set
- sysmon
- tests
- validate-sigma-schema
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
76 | | - | |
| 76 | + | |
77 | 77 | | |
78 | 78 | | |
| 79 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
25 | | - | |
| 24 | + | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
| 6 | + | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
5 | 8 | | |
6 | 9 | | |
7 | 10 | | |
| |||
16 | 19 | | |
17 | 20 | | |
18 | 21 | | |
19 | | - | |
| 22 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
101 | 101 | | |
102 | 102 | | |
103 | 103 | | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
160 | 160 | | |
161 | 161 | | |
162 | 162 | | |
| 163 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1125 | 1125 | | |
1126 | 1126 | | |
1127 | 1127 | | |
| 1128 | + | |
| 1129 | + | |
| 1130 | + | |
| 1131 | + | |
| 1132 | + | |
| 1133 | + | |
| 1134 | + | |
1128 | 1135 | | |
1129 | 1136 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
| |||
0 commit comments