Skip to content

Commit

Permalink
Merge pull request SigmaHQ#2289 from V1D1AN/master
Browse files Browse the repository at this point in the history
add tag mitre t1041
  • Loading branch information
frack113 authored Nov 20, 2021
2 parents 3eeeb81 + 83dee26 commit 76da6e3
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 2 deletions.
3 changes: 2 additions & 1 deletion rules/network/net_apt_equationgroup_c2.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,4 +24,5 @@ falsepositives:
level: high
tags:
- attack.command_and_control
- attack.g0020
- attack.g0020
- attack.t1041
6 changes: 5 additions & 1 deletion rules/network/net_pua_cryptocoin_mining_xmr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,5 +33,9 @@ detection:
- 'pool.hashvault.pro'
condition: selection
falsepositives:
- Legeitimate crypto coin mining
- Legitimate crypto coin mining
tags:
- attack.impact
- attack.t1496
- attack.t1567
level: high

0 comments on commit 76da6e3

Please sign in to comment.