-
-
Notifications
You must be signed in to change notification settings - Fork 195
Pull requests: rabbitstack/fibratus
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix(rule-engine): Check process state before evaluation
rule-engine
Anything related to the rule engine
#477
opened Mar 28, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
LSASS access from unsigned executable
rule
rules
#476
opened Mar 27, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
LSASS handle leak via Seclogon
rule
rules
#475
opened Mar 27, 2025 by
rabbitstack
Loading…
chore(deps): bump github.com/spf13/viper from 1.6.2 to 1.20.1
deps
Anything related to dependencies
#474
opened Mar 27, 2025 by
dependabot
bot
Loading…
feat(rules): New Anything related to detection rules
DLL loaded via LdrpKernel32 overwrite
rule
rules
#473
opened Mar 26, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Suspicious access to the hosts file
rule
rules
#472
opened Mar 26, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Potential ClickFix infection chain via Run window
rule
rules
#470
opened Mar 24, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
LSASS memory dump via MiniDumpWriteDump
rule
rules
#469
opened Mar 22, 2025 by
rabbitstack
Loading…
chore(rules): Improve Anything related to detection rules
Unsigned DLL injection via remote thread
rule
rules
#466
opened Mar 20, 2025 by
rabbitstack
Loading…
feat(rules): New Anything related to detection rules
Suspicious object symbolic link creation
rule
rules
#463
opened Mar 18, 2025 by
rabbitstack
Loading…
chore(deps): bump golang.org/x/net from 0.33.0 to 0.36.0
deps
Anything related to dependencies
#458
opened Mar 13, 2025 by
dependabot
bot
Loading…
chore(rules): Improve
Script interpreter host or untrusted process persistence
rule
#451
opened Feb 24, 2025 by
N0vaSky
Loading…
fix(rules): Exclusion for OneDrive to tune false positives in
Potential process hollowing
rule
#450
opened Feb 24, 2025 by
N0vaSky
Loading…
fix(rules): Add
CompatTelRunner.exe
as an exclusion in Unusual process modified registry run key
rule
#449
opened Feb 24, 2025 by
N0vaSky
Loading…
fix(rules): Add process exclusions in
Potential privilege escalation via phantom DLL hijacking
rule
#447
opened Feb 24, 2025 by
N0vaSky
Loading…
chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.2 to 3.3.0
deps
Anything related to dependencies
#429
opened Jan 28, 2025 by
dependabot
bot
Loading…
chore(deps): bump github.com/Microsoft/go-winio from 0.4.14 to 0.6.2
deps
Anything related to dependencies
#263
opened Apr 22, 2024 by
dependabot
bot
Loading…
chore(deps): bump gopkg.in/yaml.v3 from 3.0.0-20210107192922-496545a6307b to 3.0.1
deps
Anything related to dependencies
#154
opened Mar 6, 2023 by
dependabot
bot
Loading…
chore(deps): bump github.com/olivere/elastic/v7 from 7.0.20 to 7.0.32
deps
Anything related to dependencies
#113
opened Mar 21, 2022 by
dependabot
bot
Loading…
ProTip!
no:milestone will show everything without a milestone.