Skip to content

Commit 5ae7e27

Browse files
authored
Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore
Ignore more rules
2 parents 68eb2d3 + 945d2ab commit 5ae7e27

File tree

1 file changed

+32
-0
lines changed

1 file changed

+32
-0
lines changed

salt/strelka/defaults.yaml

+32
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,43 @@
11
strelka:
22
ignore:
33
- apt_flame2_orchestrator.yar
4+
- apt_apt32.yar
5+
- apt_aa19_024a.yar
6+
- apt_apt15.yar
7+
- apt_barracuda_esg_unc4841_jun23.yar
8+
- apt_bluetermite_emdivi.yar
9+
- apt_danti_svcmondr.yar
10+
- apt_eqgrp.yar
11+
- apt_eqgrp_apr17.yar
12+
- apt_greenbug.yar
13+
- apt_grizzlybear_uscert.yar
14+
- apt_lazarus_jun18.yar
15+
- apt_mal_gopuram_apr23.yar
16+
- apt_moonlightmaze.yar
17+
- apt_oilrig.yar
18+
- apt_oilrig_oct17.yar
19+
- apt_passthehashtoolkit.yar
20+
- apt_poisonivy.yar
21+
- apt_winnti_burning_umbrella.yar
22+
- cn_pentestset_webshells.yar
23+
- crime_emotet.yar
24+
- gen_fake_amsi_dll.yar
25+
- gen_onenote_phish.yar
26+
- apt_laudanum_webshells.yar
27+
- apt_sandworm_cyclops_blink.yar
28+
- cn_pentestset_scripts.yar
29+
- expl_connectwise_screenconnect_vuln_feb24.yar
30+
- mal_fortinet_coathanger_feb24.yar
31+
- thor-hacktools.yar
32+
- thor-webshells.yar
433
- apt_tetris.yar
534
- gen_susp_js_obfuscatorio.yar
635
- gen_webshells.yar
36+
- gen_vcruntime140_dll_sideloading.yar
737
- generic_anomalies.yar
838
- general_cloaking.yar
939
- thor_inverse_matches.yar
40+
- yara-rules_vuln_drivers_strict_renamed.yar
1041
- yara_mixed_ext_vars.yar
1142
- apt_apt27_hyperbro.yar
1243
- apt_turla_gazer.yar
@@ -18,4 +49,5 @@ strelka:
1849
- gen_webshells_ext_vars.yar
1950
- configured_vulns_ext_vars.yar
2051
- expl_outlook_cve_2023_23397.yar
52+
- expl_citrix_netscaler_adc_exploitation_cve_2023_3519.yar
2153
- gen_mal_3cx_compromise_mar23.yar

0 commit comments

Comments
 (0)