Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

set state tcp connection #829

Merged
merged 4 commits into from
Oct 6, 2023
Merged

set state tcp connection #829

merged 4 commits into from
Oct 6, 2023

Conversation

johnk3r
Copy link
Contributor

@johnk3r johnk3r commented Sep 18, 2023

Rule to detect the use of the "SetTcpEntry" API, commonly used by TA to disable EDR.

@johnk3r johnk3r changed the title Add files via upload set state tcp connection Sep 18, 2023
Copy link
Collaborator

@williballenthin williballenthin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

logic looks great, recommend tweaking the rule name

@mr-tz
Copy link
Collaborator

mr-tz commented Sep 22, 2023

please rename to set-tcp-connection-state.yml then good to merge

Copy link
Collaborator

@mr-tz mr-tz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

Copy link
Collaborator

@mr-tz mr-tz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@mr-tz mr-tz merged commit b33f95c into mandiant:master Oct 6, 2023
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants