- 23 Jan, 2021 1 commit
 - 
- 
add TOOLKIT_Redteam_Tools_by_Name.yar, TOOLKIT_Redteam_Tools_by_GUID.yar, TOOLKIT_Solarwinds_credential_stealer.yar rules to detect 339 hacktools, mostly c#
Arnim Rupp authored 
 - 
 - 28 Dec, 2020 7 commits
 - 
- 
yararules authored
 - 
Create MALW_PurpleWave.yar
Jaume Martin authored - 
Create Email_PHP_Mailer.yar
Jaume Martin authored - 
change file type comment from exe to jar for JavaDropper : RAT
Jaume Martin authored - 
Add rules for SipHash and Aria
Jaume Martin authored - 
yararules authored
 - 
Stuxnet python rule
Jaume Martin authored 
 - 
 - 24 Dec, 2020 3 commits
 - 17 Dec, 2020 1 commit
 - 
- 
Sylvain Pelissier authored
 
 - 
 - 21 Sep, 2020 1 commit
 - 
- 
Marking Surtr referenced rules RSharedStrings, RemoteStrings, and GmRemoteStrings as private to limit false alerts. RSharedStrings alerts on Microsoft signed wininet.dll 6B39A43271B0A631EAEFDAFDD51D17E3 SharedStrings alerts on Microsoft signed ntoskrnl.exe 68762D4C4412B4BB52BE2FC11F977503 Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
Ryan B authored 
 - 
 - 11 Sep, 2020 1 commit
 - 
- 
Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
Ryan B authored 
 - 
 - 02 Aug, 2020 2 commits
 - 10 Jul, 2020 2 commits
 - 
- 
yararules authored
 - 
rename contentis_base64 to contains
Jaume Martin authored 
 - 
 - 08 Jul, 2020 1 commit
 - 
- 
Ԝеѕ authored
 
 - 
 - 01 Jul, 2020 8 commits
 - 
- 
Jaume Martin authored
 - 
Xumeiquer authored
 - 
Jaume Martin authored
 - 
yararules authored
 - 
Move MicrosoftVisualCV80 rule from packer.yar
Jaume Martin authored - 
Jaume Martin authored
 - 
yararules authored
 - 
add .yar extensions and fix a typo
Jaume Martin authored 
 - 
 - 30 Jun, 2020 13 commits
 - 
- 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-august-31st-2018-devs-on-vacation/ is mentioned as the reference, and the picture has a space between “the” and “decryption”.
lcol3117 authored - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 - 
lcol3117 authored
 
 -