v3.0.0
Summary
Added: 54 rules
Modified: 114 rules
Renamed: 10 rules
Deleted: 0 rules
Detailed release changes: rules v2.0.0...v3.0.0
Added rules (54)
- anti-analysis/packer/gopacker/packed-with-gopacker.yml
- c2/shell/create-reverse-shell-on-linux.yml
- c2/shell/execute-shell-command-received-from-socket-on-linux.yml
- collection/get-current-user-on-linux.yml
- collection/webcam/capture-webcam-image.yml
- communication/socket/tcp/send/obtain-transmitpackets-callback-function-via-wsaioctl.yml
- data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml
- data-manipulation/encryption/hc-128/encrypt-data-using-hc-128-via-wolfssl.yml
- host-interaction/driver/create-device-object.yml
- host-interaction/file-system/change-file-permission-on-linux.yml
- host-interaction/file-system/files/list/enumerate-files-on-linux.yml
- host-interaction/file-system/read/read-file-on-linux.yml
- host-interaction/file-system/write/write-file-on-linux.yml
- host-interaction/hardware/memory/get-memory-information.yml
- host-interaction/log/clfs/append-data-to-clfs-log-container.yml
- host-interaction/log/clfs/read-data-from-clfs-log-container.yml
- host-interaction/mutex/lock-file.yml
- host-interaction/os/version/get-kernel-version.yml
- host-interaction/os/version/get-linux-distribution.yml
- host-interaction/process/create/create-process-on-linux.yml
- host-interaction/process/create/execute-command.yml
- host-interaction/process/terminate/terminate-process-via-kill.yml
- lib/duplicate-stdin-and-stdout.yml
- nursery/add-user-account-group.yml
- nursery/add-user-account-to-group.yml
- nursery/add-user-account.yml
- nursery/capture-network-configuration-via-ifconfig.yml
- nursery/change-user-account-password.yml
- nursery/collect-ssh-keys.yml
- nursery/delete-user-account-from-group.yml
- nursery/delete-user-account-group.yml
- nursery/delete-user-account.yml
- nursery/enumerate-processes-via-procfs.yml
- nursery/get-mac-address-on-linux.yml
- nursery/get-system-information-on-linux.yml
- nursery/interact-with-iptables.yml
- nursery/link-function-at-runtime-on-linux.yml
- nursery/linked-against-cpp-http-library.yml
- nursery/linked-against-cpp-json-library.yml
- nursery/list-domain-servers.yml
- nursery/list-drag-and-drop-files.yml
- nursery/list-groups-for-user-account.yml
- nursery/list-user-account-groups.yml
- nursery/list-user-accounts-for-group.yml
- nursery/list-user-accounts.yml
- nursery/load-windows-common-language-runtime.yml
- nursery/monitor-clipboard-content.yml
- nursery/monitor-local-ipv4-address-changes.yml
- nursery/parse-url.yml
- nursery/register-raw-input-devices.yml
- nursery/resize-volume-shadow-copy-storage.yml
- persistence/persist-via-desktop-autostart.yml
- persistence/persist-via-shell-profile-or-rc-file.yml
- persistence/service/persist-via-rc-script.yml
Modified rules (114)
- anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
- anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml
- anti-analysis/packer/upx/packed-with-upx.yml
- anti-analysis/reference-analysis-tools-strings.yml
- c2/file-transfer/download-and-write-a-file.yml
- c2/file-transfer/write-and-execute-a-file.yml
- c2/shell/create-reverse-shell.yml
- collection/acquire-credentials-from-windows-credential-manager.yml
- collection/browser/gather-firefox-profile-information.yml
- collection/file-managers/gather-3d-ftp-information.yml
- collection/file-managers/gather-alftp-information.yml
- collection/file-managers/gather-bitkinex-information.yml
- collection/file-managers/gather-blazeftp-information.yml
- collection/file-managers/gather-bulletproof-ftp-information.yml
- collection/file-managers/gather-classicftp-information.yml
- collection/file-managers/gather-coreftp-information.yml
- collection/file-managers/gather-cuteftp-information.yml
- collection/file-managers/gather-cyberduck-information.yml
- collection/file-managers/gather-direct-ftp-information.yml
- collection/file-managers/gather-directory-opus-information.yml
- collection/file-managers/gather-expandrive-information.yml
- collection/file-managers/gather-faststone-browser-information.yml
- collection/file-managers/gather-ffftp-information.yml
- collection/file-managers/gather-filezilla-information.yml
- collection/file-managers/gather-flashfxp-information.yml
- collection/file-managers/gather-fling-ftp-information.yml
- collection/file-managers/gather-frigate3-information.yml
- collection/file-managers/gather-ftp-commander-information.yml
- collection/file-managers/gather-ftp-explorer-information.yml
- collection/file-managers/gather-ftp-voyager-information.yml
- collection/file-managers/gather-ftpgetter-information.yml
- collection/file-managers/gather-ftpinfo-information.yml
- collection/file-managers/gather-ftprush-information.yml
- collection/file-managers/gather-global-downloader-information.yml
- collection/file-managers/gather-leapftp-information.yml
- collection/file-managers/gather-netdrive-information.yml
- collection/file-managers/gather-nova-ftp-information.yml
- collection/file-managers/gather-robo-ftp-information.yml
- collection/file-managers/gather-securefx-information.yml
- collection/file-managers/gather-smart-ftp-information.yml
- collection/file-managers/gather-softx-ftp-information.yml
- collection/file-managers/gather-southriver-webdrive-information.yml
- collection/file-managers/gather-total-commander-information.yml
- collection/file-managers/gather-turbo-ftp-information.yml
- collection/file-managers/gather-ultrafxp-information.yml
- collection/file-managers/gather-winzip-information.yml
- collection/file-managers/gather-wise-ftp-information.yml
- collection/file-managers/gather-ws-ftp-information.yml
- collection/file-managers/gather-xftp-information.yml
- collection/network/capture-network-configuration-via-ipconfig.yml
- collection/network/capture-public-ip.yml
- collection/password-manager/steal-keepass-passwords-using-keefarce.yml
- communication/http/client/check-http-status-code.yml
- communication/send-data.yml
- communication/socket/receive/receive-data-on-socket.yml
- communication/socket/send/send-data-on-socket.yml
- communication/socket/tcp/connect-tcp-socket.yml
- communication/socket/tcp/create-tcp-socket.yml
- communication/socket/udp/send/create-udp-socket.yml
- compiler/autoit/compiled-with-autoit.yml
- compiler/delphi/compiled-with-borland-delphi.yml
- compiler/go/compiled-with-go.yml
- compiler/nim/compiled-with-nim.yml
- compiler/rust/compiled-with-rust.yml
- host-interaction/bootloader/disable-code-signing.yml
- host-interaction/driver/disable-driver-code-integrity.yml
- host-interaction/file-system/read/read-file-via-mapping.yml
- host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml
- host-interaction/gui/logon/references-logon-banner.yml
- host-interaction/gui/window/get-text/get-graphical-window-text.yml
- host-interaction/hardware/cpu/get-cpu-information.yml
- host-interaction/log/debug/write-event/print-debug-messages.yml
- host-interaction/mutex/check-mutex-and-exit.yml
- host-interaction/network/address/get-local-ipv4-addresses.yml
- host-interaction/network/dns/resolve/resolve-dns.yml
- host-interaction/network/domain/enumerate-domain-computers-via-ldap.yml
- host-interaction/network/interface/get-networking-interfaces.yml
- host-interaction/os/hostname/get-hostname.yml
- host-interaction/process/inject/inject-apc.yml
- host-interaction/process/inject/inject-dll.yml
- host-interaction/process/inject/inject-pe.yml
- host-interaction/process/inject/inject-thread.yml
- "host-interaction/process/inject/use-process-doppelg\303\244nging.yml"
- host-interaction/process/list/enumerate-processes.yml
- host-interaction/process/modules/list/enumerate-process-modules.yml
- host-interaction/registry/create/set-registry-value.yml
- host-interaction/thread/create/create-thread.yml
- host-interaction/thread/list/enumerate-threads.yml
- lib/create-or-open-file.yml
- linking/runtime-linking/link-many-functions-at-runtime.yml
- linking/static/libcurl/linked-against-libcurl.yml
- linking/static/openssl/linked-against-openssl.yml
- load-code/pe/access-pe-header.yml
- load-code/pe/enumerate-pe-sections.yml
- load-code/pe/inject-dll-reflectively.yml
- load-code/pe/inspect-section-memory-permissions.yml
- load-code/pe/parse-pe-exports.yml
- load-code/pe/parse-pe-header.yml
- load-code/pe/rebuild-import-table.yml
- nursery/bypass-uac-via-scheduled-task-environment-variable.yml
- nursery/capture-screenshot-in-go.yml
- nursery/compiled-from-epl.yml
- nursery/linked-against-go-static-asset-library.yml
- nursery/packaged-as-a-nsis-installer.yml
- nursery/packaged-as-a-wise-installer.yml
- nursery/read-and-send-data-from-client-to-server.yml
- nursery/receive-and-write-data-from-server-to-client.yml
- nursery/run-powershell-expression.yml
- persistence/scheduled-tasks/schedule-task-via-command-line.yml
- persistence/service/persist-via-windows-service.yml
- persistence/startup-folder/write-file-to-startup-folder.yml
Renamed rules (10)
- anti-analysis/anti-forensic/self-deletion/self-delete.yml (was anti-analysis/anti-forensic/self-deletion/self-delete-via-comspec-environment-variable.yml)
- anti-analysis/packer/pecompact/packed-with-pecompact.yml (was nursery/packed-with-pecompact.yml)
- collection/network/get-mac-address-on-windows.yml (was collection/network/get-mac-address.yml)
- host-interaction/file-system/read/read-file-on-windows.yml (was host-interaction/file-system/read/read-file.yml)
- host-interaction/file-system/write/write-file-on-windows.yml (was host-interaction/file-system/write/write-file.yml)
- host-interaction/os/info/get-system-information-on-windows.yml (was host-interaction/os/info/get-system-information.yml)
- host-interaction/process/create/create-process-on-windows.yml (was host-interaction/process/create/create-process.yml)
- linking/runtime-linking/link-function-at-runtime-on-windows.yml (was linking/runtime-linking/link-function-at-runtime.yml)
- load-code/shellcode/spawn-thread-to-rwx-shellcode.yml (was nursery/spawn-thread-to-rwx-shellcode.yml)
- nursery/linked-against-cpp-regex-library.yml (was nursery/linked-against-c-regex-library.yml)