v3.2.0
Summary
Added: 3 rules
Modified: 19 rules
Renamed: 1 rule
Deleted: 0 rules
Detailed release changes: rules v3.1.0...v3.2.0
Added rules (3)
- anti-analysis/anti-av/block-operations-on-executable-memory-pages-using-arbitrary-code-guard.yml
- anti-analysis/anti-av/protect-spawned-processes-with-mitigation-policies.yml
- anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml
Modified rules (19)
- anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml
- anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml
- anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml
- anti-analysis/packer/gopacker/packed-with-gopacker.yml
- anti-analysis/reference-analysis-tools-strings.yml
- collection/screenshot/capture-screenshot.yml
- host-interaction/network/domain/enumerate-domain-computers-via-ldap.yml
- host-interaction/network/domain/get-domain-controller-name.yml
- host-interaction/process/dump/create-process-memory-minidump.yml
- host-interaction/service/run-as-service.yml
- impact/inhibit-system-recovery/delete-volume-shadow-copies.yml
- load-code/pe/rebuild-import-table.yml
- nursery/check-for-process-debug-object.yml
- nursery/check-processdebugflags.yml
- nursery/check-systemkerneldebuggerinformation.yml
- nursery/check-thread-yield-allowed.yml
- nursery/list-domain-servers.yml
- nursery/monitor-local-ipv4-address-changes.yml
- nursery/schedule-task-via-itaskservice.yml