Releases: JerryLinLinLin/Huorong-ATP-Rules
Releases · JerryLinLinLin/Huorong-ATP-Rules
v0.1.11
更新日志
- 修复
Exploit.MSOffice
规则误报 - 修复
Suspicious.SysProcAddAutoRun
规则误报
What's Changed
- Fixed false positives of
Exploit.MSOffice
rule - Fixed false positives of
Suspicious.SysProcAddAutoRun
rule
Full Changelog: v0.1.10...v0.1.11
v0.1.10
更新日志
- 修复
Ransom.DoubleExt.A
规则对于WPS的误报 - 调整
Suspicious.PowerShell.A
规则 - 调整
Suspicious.ScriptHost.A
规则 - 调整
Suspicious.AppCertDLLs.A
规则,默认不启用
What's Changed
- Fix WPS false positives of
Ransom.DoubleExt.A
rule - Adjust
Suspicious.PowerShell.A
rule - Adjust
Suspicious.ScriptHost.A
rule - Adjust
Suspicious.AppCertDLLs.A
rule, default to be OFF
Full Changelog: v0.1.9...v0.1.10
v0.1.9
更新日志
- 修复
RunFromSusPath
规则组错误
What's Changed
- Fix an error in
RunFromSusPath
ruleset
Full Changelog: v0.1.8...v0.1.9
v0.1.8
更新日志
- 修复
Suspicious.AppCertDLLs
规则组的误报 - 启用实验性规则组
What's Changed
- Fix false positives for
Suspicious.AppCertDLLs
ruleset - Enable experimental rulesets
Full Changelog: v0.1.7...v0.1.8
v0.1.7
更新日志
- 新增遥测组别
Telemetry
,默认状态为关闭 - 新增以下规则组:
Suspicious.AppCertDLLs
Suspicious.AppInitDLLs
Suspicious.NetDebugger
Suspicious.NetWinAppXRT
Telemetry.ActiveSetup
Telemetry.CredentialProviders
Telemetry.LSAConfig
Telemetry.PowerShell
Telemetry.ReadBrowserData
Telemetry.TerminalServer
- 其他规则组调整
What's Changed
- Added new group category
Telemetry
, the default state is off - The following rule groups have been added:
Suspicious.AppCertDLLs
Suspicious.AppInitDLLs
Suspicious.NetDebugger
Suspicious.NetWinAppXRT
Telemetry.ActiveSetup
Telemetry.CredentialProviders
Telemetry.LSAConfig
Telemetry.PowerShell
Telemetry.ReadBrowserData
Telemetry.TerminalServer
- Other ruleset adjustments
Full Changelog: v0.1.6...v0.1.7
v0.1.6
更新日志
- 新增
Trojan.Nanocore
规则组 - 修复
ReadBrowserData
部分误报 - 修复文档生成脚本部分描述错误
What's Changed
- Add
Trojan.Nanocore
ruleset - Fix
ReadBrowserData
false positives - Fix a description error in the document generation script
Full Changelog: v0.1.5...v0.1.6
v0.1.5
更新日志
- 新增英文文档。
- 新增规则文档生成CI。
- 修复
ReadBrowserData
规则名错误。
What's Changed
- Add English readme and documentation.
- Add CI for rule document generation.
- Fix
ReadBrowserData
rule name error.
Full Changelog: v0.1.4...v0.1.5
v0.1.4
更新日志
- 完成公开发布前的准备工作。
- 调整规则启用。
- 新增规则组
Trojan.Remcos
。 - 修复
ReadBrowserData
误报。
What's Changed
- Finished the works before public release.
- Adjusted rule status.
- Add new rule group
Trojan.Remcos
. - Fix
ReadBrowserData
false positives.
Full Changelog: v0.1.3...v0.1.4
v0.1.3
What's Changed
- Update release.yml by @JerryLinLinLin in #6
- Update release.yml by @JerryLinLinLin in #7
- Update main.yml by @JerryLinLinLin in #8
- Update main.yml by @JerryLinLinLin in #9
- Delete release.yml by @JerryLinLinLin in #10
- Update main.yml by @JerryLinLinLin in #11
- Test CI by @JerryLinLinLin in #12
Full Changelog: v0.1.2...v0.1.3
v0.1.2
What's Changed
- Update body.md by @JerryLinLinLin in #4
- Update release.yml by @JerryLinLinLin in #5
Full Changelog: v0.1.1...v0.1.2