Skip to content

Commit

Permalink
fix: 🐛 Yaml error
Browse files Browse the repository at this point in the history
  • Loading branch information
frack113 committed Apr 24, 2024
1 parent 4592fc6 commit ac848f7
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 1 deletion.
6 changes: 6 additions & 0 deletions sigma_rule.csv
Original file line number Diff line number Diff line change
Expand Up @@ -3199,11 +3199,17 @@ file_event_win_exploit_cve_2024_1709_user_database_modification_screenconnect.ym
web_exploit_cve_2024_1709_screenconnect.yml;False
win_security_exploit_cve_2024_1709_user_database_modification_screenconnect.yml;False
proc_creation_lnx_exploit_cve_2024_3094_sshd_child_process.yml;False
paloalto_globalprotect_os_command_injection.yml;False
proc_creation_win_malware_kamikakabot_lnk_lure_execution.yml;False
proc_creation_win_malware_kamikakabot_schtasks_persistence.yml;False
registry_set_malware_kamikakabot_winlogon_persistence.yml;False
proc_creation_win_malware_raspberry_robin_rundll32_shell32_cpl_exection.yml;False
dns_query_win_apt_dprk_malicious_domains.yml;False
file_event_win_apt_forest_blizzard_activity.yml;False
file_event_win_apt_forest_blizzard_constrained_js.yml;False
proc_creation_win_apt_forest_blizzard_activity.yml;False
registry_set_apt_forest_blizzard_custom_protocol_handler.yml;False
registry_set_apt_forest_blizzard_custom_protocol_handler_dll.yml;False
file_event_win_apt_unknown_exploitation_indicators.yml;False
microsoft365_susp_email_forwarding_activity.yml;False
okta_password_health_report_query.yml;False
Expand Down
2 changes: 1 addition & 1 deletion yml/00682c9f-7df4-4df8-950b-6dcaaa3ad9af.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ technique:
- T1059.003
os:
- windows
description: |--
description: |-
Simulate DarkGate malware's second stage by writing a VBscript to disk directly from the command prompt then executing it.
The script will execute 'whoami' then exit.
executor: command_prompt
Expand Down

0 comments on commit ac848f7

Please sign in to comment.