-
-
Notifications
You must be signed in to change notification settings - Fork 195
Pull requests: rabbitstack/fibratus
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat(rules): New Anything related to detection rules
LSASS process clone creation via reflection
rule
rules
#486
opened Apr 8, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Suspicious XSL script execution
rule
rules
#485
opened Apr 6, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Suspicious execution via WMI from a Microsoft Office process
rule
rules
#484
opened Apr 6, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Potential process creation via shellcode
rule
rules
#483
opened Apr 3, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Potential shellcode execution via ETW logger thread
rule
rules
#481
opened Apr 2, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Suspicious Netsh Helper DLL execution
rule
rules
#479
opened Apr 1, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
LSASS access from unsigned executable
rule
rules
#476
opened Mar 27, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
LSASS handle leak via Seclogon
rule
rules
#475
opened Mar 27, 2025 by
rabbitstack
Loading…
chore(deps): bump github.com/spf13/viper from 1.6.2 to 1.20.1
deps
Anything related to dependencies
#474
opened Mar 27, 2025 by
dependabot
bot
Loading…
feat(rules): New Anything related to detection rules
DLL loaded via LdrpKernel32 overwrite
rule
rules
#473
opened Mar 26, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Suspicious access to the hosts file
rule
rules
#472
opened Mar 26, 2025 by
rabbitstack
Loading…
chore(rules): Improve Anything related to detection rules
Unsigned DLL injection via remote thread
rule
rules
#466
opened Mar 20, 2025 by
rabbitstack
Loading…
chore(deps): bump golang.org/x/net from 0.33.0 to 0.36.0
deps
Anything related to dependencies
#458
opened Mar 13, 2025 by
dependabot
bot
Loading…
chore(rules): Improve
Script interpreter host or untrusted process persistence
rule
#451
opened Feb 24, 2025 by
N0vaSky
Loading…
fix(rules): Add
CompatTelRunner.exe
as an exclusion in Unusual process modified registry run key
rule
#449
opened Feb 24, 2025 by
N0vaSky
Loading…
fix(rules): Add process exclusions in
Potential privilege escalation via phantom DLL hijacking
rule
#447
opened Feb 24, 2025 by
N0vaSky
Loading…
chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.2 to 3.3.0
deps
Anything related to dependencies
#429
opened Jan 28, 2025 by
dependabot
bot
Loading…
chore(deps): bump github.com/Microsoft/go-winio from 0.4.14 to 0.6.2
deps
Anything related to dependencies
#263
opened Apr 22, 2024 by
dependabot
bot
Loading…
chore(deps): bump gopkg.in/yaml.v3 from 3.0.0-20210107192922-496545a6307b to 3.0.1
deps
Anything related to dependencies
#154
opened Mar 6, 2023 by
dependabot
bot
Loading…
chore(deps): bump github.com/olivere/elastic/v7 from 7.0.20 to 7.0.32
deps
Anything related to dependencies
#113
opened Mar 21, 2022 by
dependabot
bot
Loading…
ProTip!
Add no:assignee to see everything that’s not assigned.