Skip to content

Commit

Permalink
Update third-party rules as of 2024-12-09
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions[bot] committed Dec 9, 2024
1 parent c1a5736 commit 12216a0
Show file tree
Hide file tree
Showing 7 changed files with 13,377 additions and 12,912 deletions.
Binary file modified tests/macOS/2023.3CX/libffmpeg.change_decrease.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.change_increase.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.dirty.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.increase.mdiff
Binary file not shown.
4 changes: 2 additions & 2 deletions tests/windows/2024.aspdasdksa2/callback.bat.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,11 @@
],
"RiskScore": 4,
"RiskLevel": "CRITICAL",
"RuleURL": "https://github.com/Neo23x0/signature-base/blob/c60c8e3408dce1c9597259b8816f7526df9ac778/yara/gen_powershell_susp.yar#L52-L91",
"RuleURL": "https://github.com/Neo23x0/signature-base/blob/b1bc331bada41a30f3b2f8943e750798f7aaa1a9/yara/gen_powershell_susp.yar#L52-L91",
"ReferenceURL": "Internal%20Research",
"RuleAuthor": "Florian Roth (Nextron Systems)",
"RuleLicense": "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE",
"RuleLicenseURL": "https://github.com/Neo23x0/signature-base/blob/c60c8e3408dce1c9597259b8816f7526df9ac778/LICENSE",
"RuleLicenseURL": "https://github.com/Neo23x0/signature-base/blob/b1bc331bada41a30f3b2f8943e750798f7aaa1a9/LICENSE",
"ID": "3P/sig_base/powershell_webdownload",
"RuleName": "SIGNATURE_BASE_Suspicious_Powershell_Webdownload_1"
},
Expand Down
2 changes: 1 addition & 1 deletion third_party/yara/YARAForge/RELEASE
Original file line number Diff line number Diff line change
@@ -1 +1 @@
20241201
20241208
26,283 changes: 13,374 additions & 12,909 deletions third_party/yara/YARAForge/yara-rules-full.yar

Large diffs are not rendered by default.

0 comments on commit 12216a0

Please sign in to comment.