ThreatHunting-Keywords #5
Closed
mthcht
announced in
Announcements
Replies: 1 comment
-
note [20240508]: Multiple old rules with high false positives rules detected, will be corrected in the next release |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
April 2024 updates
Added/Updated rules:
all.yara
greyware_tools.yara
offensive_tools.yara
Ammyy Admin.yara
adexplorer.yara
boringproxy.yara
crowbar.yara
curl.yara
FileZilla.yara
duckdns.org.yara
expose.yara
go-http-tunnel.yara
gost.yara
gsocket.yara
gt.yara
hypertunnel.yara
jprq.yara
lsa-whisperer.yara
netsh.yara
ngrok.yara
Portr.yara
PyPagekite.yara
pgrok.yara
powershell.yara
python.yara
SetACL.yara
SirTunnel.yara
rathole.yara
reg.yara
remotemoe.yara
restic.yara
reverse-tunnel.yara
setspn.yara
shadowsocks.yara
sish.yara
softperfect networkscanner.yara
tunnel.yara
tunneller.yara
tunnelmole-client.yara
tunnelto.dev.yara
tunwg.yara
wget.yara
wiretap.yara
zrok.yara
ASPJinjaObfuscator.yara
BrowsingHistoryView.yara
CelestialSpark.yara
bpf-keylogger.yara
curlshell.yara
DLHell.yara
FilelessPELoader.yara
fuegoshell.yara
KExecDD.yara
impacket.yara
kali.yara
LDAP-Password-Hunter.yara
LetMeowIn.yara
NetNTLMtoSilverTicket.yara
lsassy.yara
metasploit.yara
nanodump.yara
Ouned.yara
PILOT.yara
Python-Rootkit.yara
prefetch-tool.yara
pyrdp.yara
Shell3er.yara
var0xshell.yara
veeam-creds.yara
wmiexec-pro.yara
wraith.yara
Amnesiac.yara
Antivirus Signature.yara
BeRoot.yara
Invoke-TheHash.yara
KPortScan.yara
kiglogger.yara
Lime-Crypter.yara
merlin.yara
PEASS.yara
SharpEDRChecker.yara
Venom.yara
cat.yara
icalcs.yara
RemotePC.yara
rdpwrap.yara
regsvr32.yara
ren.yara
takeown.yara
AMSI-Provider.yara
EvilClippy.yara
dll-hijack-by-proxying.yara
GraphSpy.yara
LocalShellExtParse.yara
MacroMeter.yara
NTMLRecon.yara
NetshHelperBeacon.yara
lnk2pwn.yara
logon_backdoor.yara
masscan.yara
mimidogz.yara
nishang.yara
Offensive-Netsh-Helper.yara
OffensiveCpp.yara
Office-Persistence.yara
Persistence-Accessibility-Features.yara
persistence_demos.yara
RID-Hijacking.yara
SharpDllProxy.yara
SharpGPOAbuse.yara
ShimDB.yara
Snaffler.yara
rattler.yara
spoofing-office-macro.yara
tricky.lnk.yara
Waitfor-Persistence.yara
WinPirate.yara
Windows-Crack.yara
vbad.yara
viperc2.yara
xz.yara
Ahk2Exe.yara
adfind.yara
adrecon.yara
Goodsync.yara
IObitUnlocker.yara
meshcentral.yara
psexec.yara
RemCom.yara
sc.yara
slack.yara
whoami.yara
wireproxy.yara
AzureADLateralMovement.yara
ccmpwn.yara
copy.yara
crackmapexec.yara
Defeat-Defender.yara
DragonCastle.yara
goWMIExec.yara
Jasmin-Ransomware.yara
Koppeling.yara
NTHASH-FPC.yara
mssqlproxy.yara
PickleC2.yara
poshc2.yara
pwdump.yara
ScheduleRunner.yara
SharpNoPSExec.yara
SharpSCCM.yara
SharpWSUS.yara
Slackor.yara
Tchopper.yara
scshell.yara
WMEye.yara
Details:
Lists:
Tools:
This discussion was created from the release ThreatHunting-Keywords.
Beta Was this translation helpful? Give feedback.
All reactions