frack113
							
						 
					 | 
					
						
						
							
						
						1072d3dc34
					 | 
					
						
						
							
							Add sigma ref Detection (#272)
						
						
						
						
						
						
						
						* Add sigma ref
* Add missing sigma ref
* Fix sigma link
* Remove by Defender
* Remove by Defender 
						
						
					 | 
					
						2022-12-29 09:51:15 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Grzegorz Tworek
							
						 
					 | 
					
						
						
							
						
						ec676cbd93
					 | 
					
						
						
							
							Create Runexehelper.yml (#269)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-12-17 17:30:30 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Michał Kucharski
							
						 
					 | 
					
						
						
							
						
						8452c1ca96
					 | 
					
						
						
							
							Update eventvwr.yml with Execute part (#252)
						
						
						
						
						
						
						
						* Update eventvwr.yml with Execute part
All things added based on https://twitter.com/orange_8361/status/1518970259868626944 and my re-tests.
* Update Eventvwr.yml
As asked by @bohops
* Update Eventvwr.yml 
						
						
					 | 
					
						2022-11-13 14:56:32 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Nasreddine Bencherchali
							
						 
					 | 
					
						
						
							
						
						0d7efb8ead
					 | 
					
						
						
							
							Adding and updating various LOLBINS (#229)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-11-11 16:42:44 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Grzegorz Tworek
							
						 
					 | 
					
						
						
							
						
						1587eeaf6c
					 | 
					
						
						
							
							Create Setres.yml (#262)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-10-26 11:15:13 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						c20f388444
					 | 
					
						
						
							
							Fixing minor error in description of Explorer, closes #257
						
						
						
						
						
						
					 | 
					
						2022-10-26 09:14:27 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						01d7580886
					 | 
					
						
						
							
							Add Sigma rule references to various LOLBAS (#260)
						
						
						
						
						
						
					 | 
					
						2022-10-26 09:10:39 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						a0556744d1
					 | 
					
						
						
							
							Merge branch 'master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-10-04 15:45:57 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						6f2135e173
					 | 
					
						
						
							
							Updating category of fltMC to tamper
						
						
						
						
						
						
					 | 
					
						2022-10-04 15:37:56 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						76acca6f2b
					 | 
					
						
						
							
							Merge branch 'master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-10-04 12:31:31 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								C-h4ck-0
							
						 
					 | 
					
						
						
							
						
						f29471dde9
					 | 
					
						
						
							
							Adding download functionality entries to existing binaries (#239)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-10-04 12:27:31 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								saulpanders
							
						 
					 | 
					
						
						
							
						
						83ca9aa197
					 | 
					
						
						
							
							Adding Windows Package Manager tool winget.exe (#188)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-10-04 11:27:47 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						67e1040172
					 | 
					
						
						
							
							Merge remote-tracking branch 'upstream/master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-10-03 16:18:57 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						da38f3d8ed
					 | 
					
						
						
							
							Merge pull request #185 from whickey-r7/patch-1
						
						
						
						
						
						
						
						Create Unregmp2.yml 
						
						
					 | 
					
						2022-09-17 21:38:59 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						a9e5707f74
					 | 
					
						
						
							
							Removing extra YAML record start "---"
						
						
						
						
						
						
					 | 
					
						2022-09-17 21:37:30 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						59808608e7
					 | 
					
						
						
							
							Merge pull request #180 from wietze/new/CustomShellHost
						
						
						
						
						
						
						
						Adding CustomShellHost.exe LOLBAS 
						
						
					 | 
					
						2022-09-17 21:34:04 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						05faad73b2
					 | 
					
						
						
							
							Removing extra YAML record start "---"
						
						
						
						
						
						
					 | 
					
						2022-09-17 21:32:13 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						c22d17a116
					 | 
					
						
						
							
							Merge pull request #176 from akat12/Ssh
						
						
						
						
						
						
						
						Create Ssh 
						
						
					 | 
					
						2022-09-17 21:25:49 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						14896a1436
					 | 
					
						
						
							
							Removed trailing space on line 3
						
						
						
						
						
						
					 | 
					
						2022-09-17 21:24:04 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						730359aa0d
					 | 
					
						
						
							
							Changed AWL MitreID and removed extra YAML record start "---"
						
						
						
						
						
						
					 | 
					
						2022-09-17 21:21:13 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						aa698337ff
					 | 
					
						
						
							
							Merge pull request #148 from elliotkillick/fsutil
						
						
						
						
						
						
						
						Create fsutil.yml 
						
						
					 | 
					
						2022-09-17 08:10:53 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						181672267b
					 | 
					
						
						
							
							Adding quotes since the ":" falls at the end to fix linting error
						
						
						
						
						
						
					 | 
					
						2022-09-17 08:09:27 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						4615fbc582
					 | 
					
						
						
							
							fixing indentation in line 14
						
						
						
						
						
						
					 | 
					
						2022-09-17 08:04:58 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						2759dd0565
					 | 
					
						
						
							
							Adding USN deletion that @bohops mentioned in #148 notes
						
						
						
						
						
						
					 | 
					
						2022-09-17 08:01:53 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						e878c66e6f
					 | 
					
						
						
							
							Cleaning YAML, updated new category Tamper
						
						
						
						
						
						
					 | 
					
						2022-09-17 07:55:16 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						f5c797a888
					 | 
					
						
						
							
							Merge pull request #147 from elliotkillick/DeviceCredentialDeployment
						
						
						
						
						
						
						
						Create DeviceCredentialDeployment.yml 
						
						
					 | 
					
						2022-09-17 07:52:29 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						7dd6ca24aa
					 | 
					
						
						
							
							Removing invalid MiterLink key.
						
						
						
						
						
						
					 | 
					
						2022-09-17 07:50:44 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						1e6d6d23cc
					 | 
					
						
						
							
							Removing extra document start "---" and updating category to Conceal.
						
						
						
						
						
						
					 | 
					
						2022-09-17 07:47:06 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						61043ccf0b
					 | 
					
						
						
							
							Merge pull request #245 from gtworek/patch-1
						
						
						
						
						
						
						
						Create Ldifde.yml 
						
						
					 | 
					
						2022-09-17 00:09:22 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						2689786b59
					 | 
					
						
						
							
							Update Ldifde.yml
						
						
						
						
						
						
						
						Removed trailing spaces. 
						
						
					 | 
					
						2022-09-17 00:06:25 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						9875eb2ed2
					 | 
					
						
						
							
							Update Ldifde.yml
						
						
						
						
						
						
						
						Removed final "---". It does not match the current template and schema checks. 
						
						
					 | 
					
						2022-09-17 00:03:20 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Conor Richard
							
						 
					 | 
					
						
						
							
						
						2c9a7a97ce
					 | 
					
						
						
							
							Merge pull request #244 from 721574n/tristan_add
						
						
						
						
						
						
						
						Added external reference about Rundll32 
						
						
					 | 
					
						2022-09-16 23:46:43 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						dfb30f194f
					 | 
					
						
						
							
							Tweaked the Link regex to allow anchor tags and the handle regex to permit blank entries.
						
						
						
						
						
						
					 | 
					
						2022-09-13 23:37:10 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						ee68df7f26
					 | 
					
						
						
							
							Put schema back to previous state and fixed non-compliant Link in At.yml
						
						
						
						
						
						
					 | 
					
						2022-09-13 23:06:42 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						92424a40de
					 | 
					
						
						
							
							Implimenting requested changes from PR #251 review from @wietze.
						
						
						
						
						
						
					 | 
					
						2022-09-13 22:51:52 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						654cdd2d61
					 | 
					
						
						
							
							Fixing file formating.
						
						
						
						
						
						
					 | 
					
						2022-09-11 01:33:36 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						3d6a4be2a5
					 | 
					
						
						
							
							Fixing more formatting errors.
						
						
						
						
						
						
					 | 
					
						2022-09-11 01:23:21 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						98813fe01b
					 | 
					
						
						
							
							Fixing errors found in yaml lint action.
						
						
						
						
						
						
					 | 
					
						2022-09-11 01:07:18 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						700d181c7e
					 | 
					
						
						
							
							Adding missing OperatingSystem key in Ilasm.yml
						
						
						
						
						
						
					 | 
					
						2022-09-10 23:30:36 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						d585695b08
					 | 
					
						
						
							
							Adding missing Descriptions.
						
						
						
						
						
						
					 | 
					
						2022-09-10 23:26:10 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						abb1034b00
					 | 
					
						
						
							
							Added missing description to Extexport.yml
						
						
						
						
						
						
					 | 
					
						2022-09-10 23:08:46 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						dd58662ee9
					 | 
					
						
						
							
							Correcting 'UAC bypass' to 'UAC Bypass'
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:58:06 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						0ed1694bf1
					 | 
					
						
						
							
							Correcting 'AWL bypass' to 'AWL Bypass'
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:55:32 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						09e81d0bd1
					 | 
					
						
						
							
							Correcting Cmstp.yml Category value, case.
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:48:08 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						5e0ae9c976
					 | 
					
						
						
							
							Correcting Cmstp.yml Category value.
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:46:13 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						ce36f924fc
					 | 
					
						
						
							
							Removing extra --- from each yaml file
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:16:47 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Ryan Stamp
							
						 
					 | 
					
						
						
							
						
						8810e30f0a
					 | 
					
						
						
							
							Fix incorrect decodehex command syntax (#230)
						
						
						
						
						
						
					 | 
					
						2022-09-02 18:44:23 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						e1df4e9f83
					 | 
					
						
						
							
							Merge remote-tracking branch 'upstream/master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-09-02 17:23:45 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Grzegorz Tworek
							
						 
					 | 
					
						
						
							
						
						9b70f38986
					 | 
					
						
						
							
							Create Ldifde.yml
						
						
						
						
						
						
					 | 
					
						2022-08-31 17:58:30 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								721574n
							
						 
					 | 
					
						
						
							
						
						4b564464fd
					 | 
					
						
						
							
							Added external reference for Rundll32
						
						
						
						
						
						
					 | 
					
						2022-08-24 12:11:31 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 |