Skip to content

Commit

Permalink
Shorten AV string "Mimikatz" to "mikatz" because of "HackTool:Win32/M…
Browse files Browse the repository at this point in the history
…ikatz"

Microsoft also uses HackTool:Win32/Mikatz, e.g.
1b441fde04d361a6fd7fbd83e969014622453c263107ce2bed87ad0bff7cf13f
  • Loading branch information
ruppde committed Jun 5, 2024
1 parent d7bd600 commit 2cc3c19
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 6 deletions.
4 changes: 2 additions & 2 deletions rules/category/antivirus/av_hacktool.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ references:
- https://www.nextron-systems.com/?s=antivirus
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2021/08/16
modified: 2023/02/03
modified: 2024/06/05
tags:
- attack.execution
- attack.t1204
Expand Down Expand Up @@ -43,7 +43,7 @@ detection:
- 'Metasploit'
- 'Meterpreter'
- 'MeteTool'
- 'Mimikatz'
- 'mikatz'
- 'Mpreter'
- 'Nighthawk'
- 'PentestPowerShell'
Expand Down
4 changes: 2 additions & 2 deletions rules/category/antivirus/av_password_dumper.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ references:
- https://www.virustotal.com/gui/file/a4edfbd42595d5bddb442c82a02cf0aaa10893c1bf79ea08b9ce576f82749448
author: Florian Roth (Nextron Systems)
date: 2018/09/09
modified: 2023/01/18
modified: 2024/06/05
tags:
- attack.credential_access
- attack.t1003
Expand All @@ -22,7 +22,7 @@ detection:
- Signature|startswith: 'PWS'
- Signature|contains:
- 'DumpCreds'
- 'Mimikatz'
- 'mikatz'
- 'PWCrack'
- 'HTool/WCE'
- 'PSWTool'
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ references:
- https://www.virustotal.com/gui/file/5092b2672b4cb87a8dd1c2e6047b487b95995ad8ed5e9fc217f46b8bfb1b8c01
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2017/02/19
modified: 2023/11/22
modified: 2024/06/05
tags:
- attack.resource_development
- attack.t1588
Expand Down Expand Up @@ -54,7 +54,7 @@ detection:
- 'Metasploit'
- 'Meterpreter'
- 'MeteTool'
- 'Mimikatz'
- 'mikatz'
- 'Mpreter'
- 'Nighthawk'
- 'Packed.Generic.347'
Expand Down

0 comments on commit 2cc3c19

Please sign in to comment.