Skip to content

Commit

Permalink
Update third-party rules as of 2024-12-01 (#671)
Browse files Browse the repository at this point in the history
Co-authored-by: Update third-party rules <41898282+github-actions[bot]@users.noreply.github.com>
  • Loading branch information
octo-sts[bot] and github-actions[bot] authored Dec 1, 2024
1 parent dd1e25f commit 1a60b8d
Show file tree
Hide file tree
Showing 6 changed files with 8,090 additions and 6,783 deletions.
1 change: 1 addition & 0 deletions tests/linux/2020.bdvl/bdvl.so.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2020.bdvl/bdvl.so: critical
3P/elastic/rootkit_bedevil: critical
anti-behavior/LD_DEBUG: medium
anti-behavior/process_check: high
credential/password: low
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.melofee/driver_decrypted.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.melofee/driver_decrypted: critical
3P/elastic/rootkit_melofee: critical
anti-static/binary/opaque: medium
evasion/indicator_blocking/process: high
evasion/mimicry/fake_process: high
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.melofee/pskt.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.melofee/pskt: critical
3P/elastic/melofee: critical
anti-behavior/LD_DEBUG: medium
anti-behavior/LD_PROFILE: medium
anti-static/elf/entropy: critical
Expand Down
1 change: 1 addition & 0 deletions tests/ruby/2024.Ruby_rootkit/Ruby.c.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# ruby/2024.Ruby_rootkit/Ruby.c: critical
3P/elastic/rootkit: high
c2/refs: medium
evasion/rootkit/kernel: critical
evasion/rootkit/refs: high
Expand Down
2 changes: 1 addition & 1 deletion third_party/yara/YARAForge/RELEASE
Original file line number Diff line number Diff line change
@@ -1 +1 @@
20241124
20241201
Loading

0 comments on commit 1a60b8d

Please sign in to comment.