Skip to content

Commit 1f3fb62

Browse files
committed
headless_bee
1 parent 7939d2f commit 1f3fb62

27 files changed

+6
-31
lines changed

detections/endpoint/any_powershell_downloadfile.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,6 @@ tags:
8181
- Phemedrone Stealer
8282
- Braodo Stealer
8383
- PXA Stealer
84-
- Nexus APT Threat Activity
8584
- Data Destruction
8685
- Log4Shell CVE-2021-44228
8786
asset_type: Endpoint

detections/endpoint/detect_renamed_psexec.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,6 @@ tags:
4949
- DarkGate Malware
5050
- Sandworm Tools
5151
- Rhysida Ransomware
52-
- Nexus APT Threat Activity
5352
- Earth Estries
5453
- SamSam Ransomware
5554
asset_type: Endpoint

detections/endpoint/detect_renamed_winrar.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,6 @@ tags:
4141
- China-Nexus Threat Activity
4242
- CISA AA22-277A
4343
- Collection and Staging
44-
- Nexus APT Threat Activity
4544
- Earth Estries
4645
asset_type: Endpoint
4746
mitre_attack_id:

detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,6 @@ tags:
6464
- Linux Privilege Escalation
6565
- Compromised Linux Host
6666
- Linux Living Off The Land
67-
- Nexus APT Threat Activity
6867
- Earth Estries
6968
asset_type: Endpoint
7069
mitre_attack_id:

detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,6 @@ tags:
6161
- Linux Persistence Techniques
6262
- Linux Privilege Escalation
6363
- Compromised Linux Host
64-
- Nexus APT Threat Activity
6564
- Earth Estries
6665
asset_type: Endpoint
6766
mitre_attack_id:

detections/endpoint/linux_auditd_preload_hijack_library_calls.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,6 @@ tags:
6161
- Linux Persistence Techniques
6262
- Linux Privilege Escalation
6363
- Compromised Linux Host
64-
- Nexus APT Threat Activity
6564
- Earth Estries
6665
asset_type: Endpoint
6766
mitre_attack_id:

detections/endpoint/linux_common_process_for_elevation_control.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,6 @@ tags:
4848
- Linux Persistence Techniques
4949
- Linux Privilege Escalation
5050
- Linux Living Off The Land
51-
- Nexus APT Threat Activity
5251
- Earth Estries
5352
asset_type: Endpoint
5453
mitre_attack_id:

detections/endpoint/linux_file_creation_in_init_boot_directory.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,6 @@ tags:
5454
- Linux Persistence Techniques
5555
- XorDDos
5656
- Linux Privilege Escalation
57-
- Nexus APT Threat Activity
5857
asset_type: Endpoint
5958
mitre_attack_id:
6059
- T1037.004

detections/endpoint/linux_iptables_firewall_modification.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,6 @@ tags:
7070
- Backdoor Pingpong
7171
- Cyclops Blink
7272
- Sandworm Tools
73-
- Nexus APT Threat Activity
7473
asset_type: Endpoint
7574
mitre_attack_id:
7675
- T1562.004

detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,6 @@ tags:
6161
- China-Nexus Threat Activity
6262
- Linux Persistence Techniques
6363
- Linux Privilege Escalation
64-
- Nexus APT Threat Activity
6564
- Earth Estries
6665
asset_type: Endpoint
6766
mitre_attack_id:

0 commit comments

Comments
 (0)