1. 18 Nov, 2021 1 commit
    • Tighten Glasses rule · 12c21f76
      Marked GlassesCode rule private to prevent alerting. Modified Glasses rule to require both GlassesCode and GlassesStrings to limit alerting. Added a reference URL and a reference file hash value to the rules. Updated the last modified dates. Tested rules against the reference hash file with both GlassesStrings and Glasses producing detections.
      
      Fixes #422
      RandomRhythm authored
  2. 08 Oct, 2021 3 commits
  3. 25 Aug, 2021 2 commits
  4. 05 Aug, 2021 5 commits
  5. 30 Jul, 2021 1 commit
  6. 11 May, 2021 1 commit
  7. 21 Apr, 2021 2 commits
  8. 23 Mar, 2021 3 commits
  9. 09 Mar, 2021 2 commits
  10. 27 Feb, 2021 3 commits
  11. 26 Feb, 2021 2 commits
  12. 05 Feb, 2021 2 commits
  13. 23 Jan, 2021 1 commit
  14. 28 Dec, 2020 7 commits
  15. 24 Dec, 2020 3 commits
  16. 17 Dec, 2020 1 commit
  17. 21 Sep, 2020 1 commit
    • Marking Surtr referenced rules RSharedStrings, RemoteStrings, and… · 1384b638
      Marking Surtr referenced rules RSharedStrings, RemoteStrings, and GmRemoteStrings as private to limit false alerts.
      
      RSharedStrings alerts on Microsoft signed wininet.dll	6B39A43271B0A631EAEFDAFDD51D17E3
      SharedStrings alerts on Microsoft signed ntoskrnl.exe 68762D4C4412B4BB52BE2FC11F977503
      
      Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
      Ryan B authored