Skip to content

Commit 7d734ac

Browse files
committed
Add DataStreams Field to MFT Rules and Add Part 1 Rules for Suspicious Script and Executable Locations
Add DataStreams Field to MFT Rules and Add Part 1 Rules for Suspicious Script and Executable Locations Reduce False Positives with Recycle Bin and ADAMNTDS.DIT and NTDS.DIT Exclude Intel and Temp from root_nonstand_fold as other rules cover this Add MFT Rules to Cover Root of Program Files and Windows Folders Add MFT rule for RTLO and add .lnk to most sup_script_exec rules
1 parent f1152b1 commit 7d734ac

38 files changed

+2032
-4
lines changed

rules/mft/adamntds_dit_mft.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,9 +33,11 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
38-
condition: (adamntds and adamntds_1) and not adamntds_2
40+
condition: (adamntds and adamntds_1) and not (adamntds_2 or adamntds_3)
3941

4042
adamntds:
4143
FullPath:
@@ -49,4 +51,8 @@ filter:
4951
FullPath:
5052
- 'iProgram Files\Microsoft ADAM\*'
5153
- 'iWindows\WinSxS*'
52-
- 'iWindows\servicing\LCU\*'
54+
- 'iWindows\servicing\LCU\*'
55+
56+
adamntds_3:
57+
FileSize:
58+
- 55

rules/mft/advanced_ip_scanner_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: ais and (ais_1 or ais_2 or ais_3 or ais_4)

rules/mft/advanced_port_scanner_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: aps and (aps_1 or aps_2 or aps_3 or aps_4)

rules/mft/angry_ip_scanner_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: ais and (ais_1 or ais_2 or ais_3 or ais_4)

rules/mft/anydesk_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: anydesk and (anydesk_1 or anydesk_2 or anydesk_3 or anydesk_4 or anydesk_5 or anydesk_6)

rules/mft/browserscan_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: (browserscan and browserscan_loot) or (browserscan_1 and browserscan_2)

rules/mft/filezilla_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: filezilla and (filezilla_1 or filezilla_2 or filezilla_3 or filezilla_4)

rules/mft/lsass_dmp_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: lsass and (lsass_1 or lsass_2)

rules/mft/megasync_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: ms and (ms_1 or ms_2 or ms_3)

rules/mft/mimikatz_mft.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
to: IsDeleted
3434
- name: HasAlternateDataStreams
3535
to: HasAlternateDataStreams
36+
- name: DataStreams
37+
to: DataStreams
3638

3739
filter:
3840
condition: mimikatz

0 commit comments

Comments
 (0)