Skip to content

Commit

Permalink
disable CS rule
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Oct 13, 2023
1 parent 2f5a581 commit 857ac87
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions yara/gen_cobaltstrike.yar
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@ rule HKTL_CobaltStrike_SleepMask_Jul22 {
// This yara was specially crafted for the core (in-memory scans) which cannot be
// avoided in way by an operator, making the malleability, UDRL or IAT hooking useless

/* FR: rule caused 6490 false positives in our testing environment - cannot be used in the current form
rule HKTL_CobaltStrike_CS_Core_Oct23 {
meta:
description = "Hunts for opcodes used in Cobaltstrike 4.9.1 and earlier"
Expand All @@ -36,3 +38,4 @@ rule HKTL_CobaltStrike_CS_Core_Oct23 {
condition:
1 of them
}
*/

0 comments on commit 857ac87

Please sign in to comment.