Skip to content

Commit

Permalink
fix: FP with CVE folder in Aurora sigma rule sub folders
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Oct 17, 2023
1 parent 8e74996 commit 3746bcc
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion iocs/filename-iocs.txt
Original file line number Diff line number Diff line change
Expand Up @@ -3903,7 +3903,7 @@ linpeas\.log;75
\\passav\.exe;65

# Exploit Code File Names
\\(cve|CVE)-20[012][0-9]\-[0-9]{4,5}.{0,20}($|\\);60;(\\share\\doc|\\Microsoft\\Windows Defender Advanced Threat Protection\\|/\.cpanm/work/| \.\.\.\.\. ok|\\sigma\\|\\(cve|CVE)-20[012][0-9]\-[0-9]{4,5}\\n )
\\(cve|CVE)-20[012][0-9]\-[0-9]{4,5}.{0,20}($|\\);60;(\\share\\doc|\\Microsoft\\Windows Defender Advanced Threat Protection\\|/\.cpanm/work/| \.\.\.\.\. ok|\\sigma\\|\\(cve|CVE)-20[012][0-9]\-[0-9]{4,5}\\n | MFSA |emerging-threats)
\\(cve|CVE)-20[012][0-9]\-[0-9]{4,5}.{0,20}(\.py|\.exe|\.vbs|\.bat|\.ps1|\.dll);75;(\\share\\doc|CVE\-2017\-9800\-pre\-commit)

# Possible Service Path Escalation Attempt http://www.commonexploits.com/unquoted-service-paths/ or simple malware
Expand Down

0 comments on commit 3746bcc

Please sign in to comment.