Skip to content

v1.5.0

@OmarRao OmarRao tagged this 17 Jun 14:53
New rule sets:
- clop.yar: Cl0p ransomware + MOVEit/GoAnywhere exploitation (CVE-2023-34362, CVE-2023-0669)
- emerging_ransomware.yar: Play, Akira, RansomHub, Black Basta, Hunters International
- lotl_techniques.yar: certutil, mshta, regsvr32, wscript, bitsadmin, PowerShell cradles, rundll32
- credential_harvesting.yar: browser creds, DPAPI, SAM/NTDS, Kerberoasting, LSA secrets, cloud creds
- supply_chain_attacks.yar: dependency confusion, CI/CD tampering, malicious npm/PyPI, Docker poisoning

Total: 11 rule sets, 50+ rules
Assets 2
Loading