Detection Rule List

Rule Name Rule Type Technique Count Creation Date
Detect RDTSC Check YARA 1 3 years, 9 months
Detect NtQueryInformationProcess Usage YARA 1 3 years, 9 months
Detect NtSetInformationThread Usage YARA 1 3 years, 9 months
Detect NtQueryObject Usage YARA 1 3 years, 9 months
Detect OutputDebugString Usage YARA 1 3 years, 9 months
Detect EventPairHandles Usage YARA 1 3 years, 9 months
Detect CsrGetProcessID Usage YARA 1 3 years, 9 months
Detect CloseHandle / NtClose Usage YARA 1 3 years, 9 months
Detect Process Enumeration Techniques YARA 1 3 years, 9 months
Detect Unhandled Exception Filters YARA 1 3 years, 9 months
Detect Interrupts 2 YARA 3 3 years, 9 months
Detect OllyDbg Bad Format YARA 1 3 years, 9 months
Detect Guard Pages Technique YARA 1 3 years, 9 months
Detect IsDebugged Indicator YARA 1 3 years, 9 months
Detect SetDebugFilterState Usage YARA 1 3 years, 9 months
Detect AntiDebug Thread Control YARA 1 3 years, 9 months
Detect TLSCallback Anti-Debug Trick YARA 1 3 years, 9 months
Detect Antivirus Killers YARA 0 3 years, 9 months
Detect NtGlobalFlags Debugger Flag YARA 1 3 years, 9 months
Detect Events Logs Wiping YARA 0 3 years, 9 months
Detect CheckRemoteDebuggerPresent Usage YARA 0 3 years, 9 months
Detect MSAcpi_ThermalZoneTemperature Usage YARA 0 3 years, 9 months
Detect QEMU Registry Artifacts YARA 1 3 years, 9 months
Detect Shamoon Wiper YARA 1 3 years, 9 months
Detect GetForegroundWindow Usage YARA 0 3 years, 9 months
Detect Process Kill Techniques YARA 1 3 years, 9 months
Detect UAC Bypass Techniques YARA 1 3 years, 9 months
Detect Encryption Artifacts YARA 2 3 years, 9 months
Detect MAC Address Lookup YARA 0 3 years, 9 months
Detect Anti-Unpacking Techniques YARA 2 3 years, 9 months
Filter