v6.0.0
Summary
Added: 32 rules
Modified: 22 rules
Renamed: 3 rules
Deleted: 3 rules
Detailed release changes: rules v5.1.0...v6.0.0
Added rules (32)
- anti-analysis/anti-av/patch-event-tracing-for-windows-function.yml
- anti-analysis/anti-vm/vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml
- anti-analysis/anti-vm/vm-detection/detect-vm-via-motherboard-hardware-wmi-queries.yml
- communication/mailslot/read-from-mailslot.yml
- communication/socket/create-vmci-socket.yml
- compiler/cx_freeze/compiled-with-cx_freeze.yml
- data-manipulation/encryption/aes/encrypt-data-using-aes-mixcolumns-step.yml
- host-interaction/file-system/create-virtual-file-system-in-dotnet.yml
- host-interaction/filter/enumerate-minifilter-drivers.yml
- host-interaction/gui/switch-active-desktop.yml
- host-interaction/hardware/enumerate-devices-by-category.yml
- host-interaction/memory/create-new-application-domain-in-dotnet.yml
- host-interaction/process/inject/inject-shellcode-using-extra-window-memory.yml
- host-interaction/process/inject/inject-shellcode-using-window-subclass-procedure.yml
- host-interaction/service/continue-service.yml
- host-interaction/service/pause-service.yml
- host-interaction/service/query-service-configuration.yml
- linking/runtime-linking/resolve-function-by-brute-ratel-badger-hash.yml
- linking/static/aplib/linked-against-aplib.yml
- load-code/shellcode/execute-shellcode-via-windows-callback-function.yml
- nursery/check-for-sandbox-via-mac-address-ouis-in-dotnet.yml
- nursery/compiled-with-exescript.yml
- nursery/covertly-decode-and-write-data-to-windows-directory-using-indirect-calls.yml
- nursery/hash-data-using-sha512managed-in-dotnet.yml
- persistence/act-as-dhcp-server-callout-dll.yml
- persistence/act-as-dns-server-plugin-dll.yml
- persistence/authentication-process/act-as-security-support-provider-dll.yml
- persistence/authentication-process/act-as-subauthentication-package-dll.yml
- persistence/exchange/act-as-exchange-transport-agent.yml
- persistence/office/act-as-excel-xll-add-in.yml
- persistence/office/act-as-office-com-add-in.yml
- persistence/office/act-as-word-wll-add-in.yml
Modified rules (22)
- anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
- collection/microphone/capture-microphone-audio.yml
- communication/http/reference-http-user-agent-string.yml
- communication/socket/create-raw-socket.yml
- data-manipulation/compression/compress-data-via-zlib-inflate-or-deflate.yml
- data-manipulation/encryption/rsa/reference-public-rsa-key.yml
- data-manipulation/hashing/fnv/hash-data-using-fnv.yml
- executable/resource/extract-resource-via-kernel32-functions.yml
- host-interaction/clipboard/read-clipboard-data.yml
- host-interaction/clipboard/write-clipboard-data.yml
- host-interaction/file-system/copy/copy-file.yml
- host-interaction/file-system/get-common-file-path.yml
- host-interaction/file-system/read/read-file-on-windows.yml
- host-interaction/file-system/reference-absolute-stream-path-on-windows.yml
- host-interaction/file-system/write/write-file-on-windows.yml
- host-interaction/service/stop/stop-service.yml
- impact/wipe-disk/wipe-mbr/overwrite-master-boot-record-mbr.yml
- lib/create-or-open-file.yml
- lib/get-os-version.yml
- load-code/pe/enumerate-pe-sections.yml
- nursery/encrypt-data-using-aes.yml
Renamed rules (3)
- anti-analysis/anti-debugging/debugger-evasion/hide-thread-from-debugger.yml (was nursery/hide-thread-from-debugger.yml)
- host-interaction/file-system/get-windows-directory-from-kuser_shared_data.yml (was nursery/get-windows-directory-from-kuser_shared_data.yml)
- nursery/execute-shellcode-via-indirect-call.yml (was load-code/shellcode/execute-shellcode-via-enumuilanguages.yml)