v1.5.0
Summary
Added: 44 rules
Modified: 170 rules
Renamed: 13 rules
Deleted: 1 rule
Detailed release changes: rules v1.4.0...v1.5.0
Added rules (44)
- anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml
- anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml
- anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml
- collection/microphone/capture-microphone-audio.yml
- collection/network/capture-public-ip.yml
- collection/network/get-domain-trust-relationships.yml
- communication/http/client/check-http-status-code.yml
- compiler/perl2exe/compiled-with-perl2exe.yml
- compiler/ps2exe/compiled-with-ps2exe.yml
- compiler/pyarmor/compiled-with-pyarmor.yml
- data-manipulation/prng/generate-random-numbers-via-winapi.yml
- host-interaction/file-system/files/list/enumerate-files-recursively.yml
- host-interaction/file-system/read/read-virtual-disk.yml
- host-interaction/filter/start-minifilter-driver.yml
- host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml
- host-interaction/process/inject/hijack-thread-execution.yml
- host-interaction/process/inject/inject-dll.yml
- host-interaction/process/inject/inject-pe.yml
- host-interaction/registry/delete/delete-registry-value.yml
- host-interaction/registry/query-or-enumerate-registry-key.yml
- host-interaction/thread/resume/resume-thread.yml
- host-interaction/thread/suspend/suspend-thread.yml
- lib/allocate-memory.yml
- lib/allocate-rw-memory.yml
- lib/contain-pusha-popa-sequence.yml
- lib/create-or-open-file.yml
- lib/open-process.yml
- lib/open-thread.yml
- linking/runtime-linking/get-kernel32-base-address.yml
- linking/runtime-linking/get-ntdll-base-address.yml
- nursery/check-for-windows-sandbox-via-mutex.yml
- nursery/encrypt-or-decrypt-data-via-bcrypt.yml
- nursery/generate-random-numbers-using-the-delphi-lcg.yml
- nursery/hash-data-via-bcrypt.yml
- nursery/migrate-process-to-active-window-station.yml
- nursery/patch-process-command-line.yml
- nursery/resolve-function-by-hash.yml
- persistence/registry/winlogon-helper/persist-via-winlogon-helper-dll-registry-key.yml
- persistence/scheduled-tasks/schedule-task-via-command-line.yml
Modified rules (170)
- anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
- anti-analysis/anti-vm/vm-detection/check-for-sandbox-username.yml
- anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml
- anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml
- anti-analysis/packer/aspack/packed-with-aspack.yml
- anti-analysis/packer/generic/packed-with-generic-packer.yml
- anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml
- anti-analysis/packer/nspack/packed-with-nspack.yml
- anti-analysis/packer/pebundle/packed-with-pebundle.yml
- anti-analysis/packer/pelocknt/packed-with-pelocknt.yml
- anti-analysis/packer/peshield/packed-with-peshield.yml
- anti-analysis/packer/petite/packed-with-petite.yml
- anti-analysis/packer/rlpack/packed-with-rlpack.yml
- anti-analysis/packer/upack/packed-with-upack.yml
- anti-analysis/packer/y0da/packed-with-y0da-crypter.yml
- c2/file-transfer/download-and-write-a-file.yml
- c2/file-transfer/write-and-execute-a-file.yml
- collection/browser/gather-firefox-profile-information.yml
- collection/credit-card/parse-credit-card-information.yml
- collection/screenshot/capture-screenshot.yml
- communication/http/client/create-http-request.yml
- communication/socket/get-socket-status.yml
- compiler/autoit/compiled-with-autoit.yml
- compiler/py2exe/compiled-with-py2exe.yml
- data-manipulation/checksum/adler32/compute-adler32-checksum.yml
- data-manipulation/checksum/crc32/hash-data-with-crc32.yml
- data-manipulation/compression/compress-data-via-winapi.yml
- data-manipulation/compression/decompress-data-using-quicklz.yml
- data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml
- data-manipulation/encoding/base64/encode-data-using-base64.yml
- data-manipulation/encoding/base64/reference-base64-string.yml
- data-manipulation/encoding/xor/encode-data-using-xor.yml
- data-manipulation/encryption/blowfish/encrypt-data-using-blowfish.yml
- data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml
- data-manipulation/encryption/des/encrypt-data-using-des-via-winapi.yml
- data-manipulation/encryption/des/encrypt-data-using-des.yml
- data-manipulation/encryption/hc-128/encrypt-data-using-hc-128.yml
- data-manipulation/encryption/skipjack/encrypt-data-using-skipjack.yml
- data-manipulation/encryption/sosemanuk/encrypt-data-using-sosemanuk.yml
- data-manipulation/hashing/murmur/hash-data-using-murmur3.yml
- data-manipulation/hashing/tiger/hash-data-using-tiger.yml
- executable/subfile/pe/contain-an-embedded-pe-file.yml
- host-interaction/cli/accept-command-line-arguments.yml
- host-interaction/cli/resolve-path-using-msvcrt.yml
- host-interaction/clipboard/open-clipboard.yml
- host-interaction/clipboard/replace-clipboard-data.yml
- host-interaction/clipboard/write-clipboard-data.yml
- host-interaction/console/manipulate-console.yml
- host-interaction/driver/install-driver.yml
- host-interaction/driver/interact-with-driver-via-control-codes.yml
- host-interaction/environment-variable/query-environment-variable.yml
- host-interaction/environment-variable/set-environment-variable.yml
- host-interaction/file-system/copy/copy-file.yml
- host-interaction/file-system/create/create-directory.yml
- host-interaction/file-system/delete/delete-directory.yml
- host-interaction/file-system/delete/delete-file.yml
- host-interaction/file-system/get-common-file-path.yml
- host-interaction/file-system/get-program-files-directory.yml
- host-interaction/file-system/meta/get-file-attributes.yml
- host-interaction/file-system/meta/set-file-attributes.yml
- host-interaction/file-system/read/read-file.yml
- host-interaction/file-system/read/read-ini-file.yml
- host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml
- host-interaction/file-system/write/write-file.yml
- host-interaction/firewall/modify/access-firewall-settings-via-inetfwmgr.yml
- host-interaction/gui/session/lock/lock-the-desktop.yml
- host-interaction/gui/session/wallpaper/change-the-wallpaper.yml
- host-interaction/gui/taskbar/find/find-taskbar.yml
- host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml
- host-interaction/gui/window/get-text/get-graphical-window-text.yml
- host-interaction/gui/window/hide/hide-graphical-window.yml
- host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml
- host-interaction/hardware/cpu/get-cpu-information.yml
- host-interaction/hardware/keyboard/layout/get-keyboard-layout.yml
- host-interaction/hardware/mouse/swap-mouse-buttons.yml
- host-interaction/hardware/storage/get-disk-size.yml
- host-interaction/mutex/check-mutex-and-exit.yml
- host-interaction/mutex/check-mutex.yml
- host-interaction/mutex/create-mutex.yml
- host-interaction/network/dns/resolve/resolve-dns.yml
- host-interaction/network/traffic/copy/copy-network-traffic.yml
- host-interaction/process/allocate-thread-local-storage.yml
- host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml
- host-interaction/process/create/create-process-suspended.yml
- host-interaction/process/create/create-process.yml
- host-interaction/process/inject/allocate-rwx-memory.yml
- host-interaction/process/inject/free-user-process-memory.yml
- host-interaction/process/inject/inject-thread.yml
- host-interaction/process/inject/use-process-replacement.yml
- host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml
- host-interaction/process/list/enumerate-processes.yml
- host-interaction/process/set-thread-local-storage-value.yml
- host-interaction/process/terminate/terminate-process-via-fastfail.yml
- host-interaction/process/terminate/terminate-process.yml
- host-interaction/registry/create/set-registry-value.yml
- host-interaction/registry/delete/delete-registry-key.yml
- host-interaction/service/create/create-service.yml
- host-interaction/service/modify/modify-service.yml
- host-interaction/service/query-service-status.yml
- host-interaction/service/stop/stop-service.yml
- host-interaction/session/get-session-user-name.yml
- host-interaction/thread/create/create-thread.yml
- host-interaction/thread/terminate/terminate-thread.yml
- host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml
- host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml
- impact/inhibit-system-recovery/delete-volume-shadow-copies.yml
- lib/calculate-modulo-256-via-x86-assembly.yml
- lib/delay-execution.yml
- lib/peb-access.yml
- linking/runtime-linking/access-peb-ldr_data.yml
- linking/static/cryptopp/linked-against-crypto.yml
- linking/static/openssl/linked-against-openssl.yml
- linking/static/polarssl/linked-against-polarsslmbed-tls.yml
- linking/static/zlib/linked-against-zlib.yml
- nursery/acquire-debug-privileges.yml
- nursery/compiled-from-epl.yml
- nursery/create-restart-manager-session.yml
- nursery/get-installed-programs.yml
- nursery/get-proxy.yml
- nursery/get-socket-information.yml
- nursery/hash-data-using-murmur2.yml
- nursery/hooked-by-api-override.yml
- nursery/impersonate-user.yml
- nursery/packaged-as-a-createinstall-installer.yml
- nursery/packaged-as-a-nsis-installer.yml
- nursery/packaged-as-a-pintool.yml
- nursery/packed-with-ccg.yml
- nursery/packed-with-crunch.yml
- nursery/packed-with-dragon-armor.yml
- nursery/packed-with-enigma.yml
- nursery/packed-with-epack.yml
- nursery/packed-with-maskpe.yml
- nursery/packed-with-mew.yml
- nursery/packed-with-mpress.yml
- nursery/packed-with-neolite.yml
- nursery/packed-with-pecompact.yml
- nursery/packed-with-pepack.yml
- nursery/packed-with-perplex.yml
- nursery/packed-with-procrypt.yml
- nursery/packed-with-rpcrypt.yml
- nursery/packed-with-seausfx.yml
- nursery/packed-with-shrinker.yml
- nursery/packed-with-simple-pack.yml
- nursery/packed-with-starforce.yml
- nursery/packed-with-svkp.yml
- nursery/packed-with-themida.yml
- nursery/packed-with-tsuloader.yml
- nursery/packed-with-vprotect.yml
- nursery/packed-with-wwpack.yml
- nursery/read-and-send-data-from-client-to-server.yml
- nursery/read-process-memory.yml
- nursery/rebuilt-by-imprec.yml
- nursery/receive-and-write-data-from-server-to-client.yml
- nursery/reference-alidns-dns-server.yml
- nursery/reference-cloudflare-dns-server.yml
- nursery/reference-comodo-secure-dns-server.yml
- nursery/reference-dns-over-https-endpoints.yml
- nursery/reference-google-public-dns-server.yml
- nursery/reference-hurricane-electric-dns-server.yml
- nursery/reference-kornet-dns-server.yml
- nursery/reference-opendns-dns-server.yml
- nursery/reference-quad9-dns-server.yml
- nursery/reference-verisign-dns-server.yml
- nursery/terminate-process-by-name.yml
- persistence/registry/appinitdlls/persist-via-appinit_dlls-registry-key.yml
- persistence/registry/ginadll/persist-via-ginadll-registry-key.yml
- persistence/registry/run/persist-via-run-registry-key.yml
- persistence/scheduled-tasks/schedule-task-via-itaskscheduler.yml
- persistence/service/persist-via-windows-service.yml
Renamed rules (13)
- collection/network/get-mac-address.yml (was nursery/get-mac-address.yml)
- compiler/go/compiled-with-go.yml (was nursery/compiled-with-go.yml)
- data-manipulation/checksum/luhn/validate-payment-card-number-using-luhn-algorithm.yml (was data-manipulation/checksum/luhn/validate-credit-card-number-using-luhn-algorithm.yml)
- data-manipulation/hashing/fnv/hash-data-using-fnv.yml (was nursery/hash-data-using-fnv.yml)
- host-interaction/file-system/get-file-system-object-information.yml (was host-interaction/registry/query/query-registry-key.yml)
- host-interaction/filter/register-minifilter-driver.yml (was host-interaction/registry/open/open-registry-key.yml)
- host-interaction/gui/enumerate-gui-resources.yml (was nursery/enumerate-graphical-windows.yml)
- host-interaction/log/winevt/access/access-the-windows-event-log.yml (was nursery/access-the-windows-event-log.yml)
- host-interaction/process/inject/inject-apc.yml (was nursery/inject-apc.yml)
- host-interaction/registry/create-or-open-registry-key.yml (was host-interaction/registry/create/create-registry-key.yml)
- host-interaction/registry/query-or-enumerate-registry-value.yml (was host-interaction/registry/query/query-registry-value.yml)
- lib/validate-payment-card-number-using-luhn-algorithm-with-lookup-table.yml (was lib/validate-credit-card-number-using-luhn-algorithm-with-lookup-table.yml)
- lib/validate-payment-card-number-using-luhn-algorithm-with-no-lookup-table.yml (was lib/validate-credit-card-number-using-luhn-algorithm-with-no-lookup-table.yml)