Skip to content

Commit

Permalink
Add files via upload
Browse files Browse the repository at this point in the history
  • Loading branch information
johnk3r authored Sep 18, 2023
1 parent b9c2bc1 commit 043aa57
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions host-interaction/network/connectivity/set-state-tcp-connection.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
rule:
meta:
name: set state tcp connection
namespace: host-interaction/network/connectivity
authors:
- "@johnk3r"
description: The SetTcpEntry function sets the state of a TCP connection.
scope: function
att&ck:
- Defense Evasion::Impair Defenses [T1562]
references:
- https://unit42.paloaltonetworks.com/evilgrab-delivered-by-watering-hole-attack-on-president-of-myanmars-website
- https://github.com/magisterquis/EDRSniper/blob/master/edrsniper.c
examples:
- 883bf161937f8dc6e766b07000110254:0x403150
features:
- or:
- api: iphlpapi.SetTcpEntry

0 comments on commit 043aa57

Please sign in to comment.