v7.1.0
Summary
Added: 24 rules
Modified: 42 rules
Renamed: 2 rules
Deleted: 0 rules
Detailed release changes: rules v7.0.1...v7.1.0
Added rules (24)
- anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml
- compiler/dart/compiled-with-dart.yml
- data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml
- host-interaction/driver/interact-with-driver-via-ioctl.yml
- host-interaction/gui/window/hide/hide-graphical-window-from-taskbar.yml
- impact/wipe-disk/delete-drive-layout-via-ioctl.yml
- nursery/bypass-hidden-api-restrictions-via-jni-on-android.yml
- nursery/change-memory-permission-on-linux.yml
- nursery/check-file-permission-on-linux.yml
- nursery/check-if-process-is-running-under-android-emulator-on-android.yml
- nursery/get-current-process-filesystem-mounts-on-linux.yml
- nursery/get-current-process-memory-mapping-on-linux.yml
- nursery/get-disk-information-via-ioctl.yml
- nursery/get-system-property-on-android.yml
- nursery/get-volume-information-via-ioctl.yml
- nursery/hook-routines-via-lsplant.yml
- nursery/load-packed-dex-via-jiagu-on-android.yml
- nursery/map-or-unmap-memory-on-linux.yml
- nursery/modify-api-blacklist-or-denylist-via-jni-on-android.yml
- nursery/truncate-file-on-linux.yml
- nursery/unmount-volume-via-ioctl.yml
- persistence/act-as-share-provider-dll.yml
- persistence/act-as-time-provider-dll.yml
- persistence/act-as-windbg-extension.yml
Modified rules (42)
- collection/keylog/log-keystrokes-via-application-hook.yml
- communication/dns/resolve-dns.yml
- communication/socket/create-raw-socket.yml
- communication/socket/get-socket-status.yml
- communication/socket/initialize-winsock-library.yml
- communication/socket/receive/receive-data-on-socket.yml
- communication/socket/send/send-data-on-socket.yml
- communication/socket/set-socket-configuration.yml
- communication/socket/tcp/connect-tcp-socket.yml
- communication/socket/tcp/create-tcp-socket.yml
- communication/socket/udp/send/create-udp-socket.yml
- compiler/go/compiled-with-go.yml
- data-manipulation/encryption/dpapi/encrypt-data-using-dpapi.yml
- host-interaction/driver/install-driver.yml
- host-interaction/file-system/change-file-permission-on-linux.yml
- host-interaction/file-system/files/list/enumerate-files-on-linux.yml
- host-interaction/file-system/files/list/enumerate-files-recursively.yml
- host-interaction/file-system/read/read-file-on-linux.yml
- host-interaction/file-system/write/write-file-on-linux.yml
- host-interaction/gui/set-application-hook.yml
- host-interaction/hardware/memory/get-memory-information.yml
- host-interaction/hardware/storage/get-disk-size.yml
- host-interaction/mutex/create-semaphore-on-linux.yml
- host-interaction/mutex/lock-file.yml
- host-interaction/mutex/lock-semaphore-on-linux.yml
- host-interaction/mutex/unlock-semaphore-on-linux.yml
- host-interaction/process/create/create-process-on-linux.yml
- host-interaction/session/get-current-user-on-linux.yml
- host-interaction/thread/create/create-thread.yml
- lib/delay-execution.yml
- lib/duplicate-stdin-and-stdout.yml
- linking/runtime-linking/link-function-at-runtime-on-windows.yml
- linking/runtime-linking/link-many-functions-at-runtime.yml
- load-code/shellcode/execute-shellcode-via-windows-callback-function.yml
- nursery/encrypt-data-using-salsa20-or-chacha.yml
- nursery/get-current-pid-on-linux.yml
- nursery/get-password-database-entry-on-linux.yml
- nursery/get-socket-information.yml
- nursery/get-storage-device-properties.yml
- nursery/link-function-at-runtime-on-linux.yml
- nursery/resize-volume-shadow-copy-storage.yml
- nursery/set-thread-name-on-linux.yml