Commit Graph

867 Commits

Author SHA1 Message Date
nishikawaakira
0663f8403d Merge pull request #12 from YamatoSecurity/feature/toml
Feature/toml
2020-10-11 14:46:48 +09:00
akiranishikawa
7e9ce2fbe8 cargo fmt --all 2020-10-10 11:18:43 +09:00
akiranishikawa
03be1dad34 cargo fmt --all 2020-10-10 11:14:39 +09:00
akiranishikawa
a8536d78a0 テストファイルディレクトリ修正 2020-10-10 11:12:32 +09:00
akiranishikawa
f2f3a7e99a Toml読み込み機能実装 2020-10-10 10:21:08 +09:00
akiranishikawa
6fc709c2b4 Toml読み込み機能実装 2020-10-10 09:59:08 +09:00
nishikawaakira
22edee0332 Merge pull request #7 from YamatoSecurity/feature/powershell
Add: DeepBlueCLI PowerShell's rules
一旦、whitelistを引数で受け取る実装でマージします。
この部分はのちほど改修予定。
2020-10-09 18:55:22 +09:00
nishikawaakira
2ce9ed7e24 Merge branch 'master' into feature/powershell 2020-10-09 18:54:09 +09:00
itiB
5f5251a4a4 Fix: solve thread 2020-10-09 02:13:04 +09:00
itiB
c12090227e Fix: <utils.rs-check_command()> get rdr by reference 2020-10-09 02:04:31 +09:00
itiB
8dba24554f Add: DeepBlueCLI PowerShell's rule for 4103 2020-10-09 02:04:31 +09:00
itiB
7f2bbcc1f1 Update: call check_command() from PowerShell's error 4104 2020-10-09 02:04:26 +09:00
itiB
2220500a9c Add: DeepBlueCLI PowerShell's rules 2020-10-09 02:02:48 +09:00
nishikawaakira
d53518211d Merge pull request #10 from YamatoSecurity/feature/security
Feature/security
2020-10-08 21:50:23 +09:00
ichiichi11
6ad9a77361 testcase implemented 2020-10-08 08:30:56 +09:00
siamease
dd6f3c39a4 cleanup 2020-10-07 02:11:07 +09:00
siamease
e2086ea0b8 add utils::check_command support 2020-10-07 02:09:02 +09:00
siamease
ce22a934c0 Merge pull request #4 from YamatoSecurity/feature/sysmon
Feature/sysmon
2020-10-07 01:02:22 +09:00
siamease
1c2ec6e6dd Implementation 2020-10-07 00:56:03 +09:00
ichiichi11
c3feb1eca2 refactor for test. 2020-10-07 00:53:19 +09:00
siamease
c62c8dc326 fix 2020-10-07 00:16:47 +09:00
ichiichi11
3f257a52be eventid=4674 2020-10-06 22:37:19 +09:00
ichiichi11
32c6e13ccf refactor 2020-10-06 22:13:00 +09:00
nishikawaakira
5f989da6b9 Merge pull request #6 from YamatoSecurity/feature/security
Security module Implemented without 4674
2020-10-06 05:08:47 +09:00
nishikawaakira
3e1ea5faf4 Merge branch 'master' into feature/security 2020-10-06 05:04:03 +09:00
Your Name
87796f83e6 fix line feed code and refactoring 2020-10-05 20:56:47 +09:00
Your Name
7bc48e80f9 fix typo 2020-10-05 09:42:47 +09:00
Your Name
dc2e55cc9f refactor 2020-10-05 09:08:32 +09:00
Your Name
1057a72efc remove unneccesary pub 2020-10-05 08:55:03 +09:00
nishikawaakira
3ea4381393 Merge pull request #5 from YamatoSecurity/feature/Check-Command
add check_command functions
2020-10-05 06:06:09 +09:00
Your Name
ca56063f12 Security module Implemented without 4674 2020-10-04 18:37:05 +09:00
Kazuminn
9cab0bb343 add comment 2020-10-04 17:15:08 +09:00
Kazuminn
3e3f7bc51e fix :コメントで指摘されたところ 2020-10-04 17:07:09 +09:00
Kazuminn
e3631abeb3 add test : white listとマッチする時は、すぐにreturnする 2020-10-04 16:13:26 +09:00
Kazuminn
7242dfbc1b refactor 2020-10-03 20:07:45 +09:00
Kazuminn
6d57923ff2 refactor 2020-10-03 20:04:21 +09:00
Kazuminn
61049ce9a8 refactor 2020-10-03 19:52:04 +09:00
Kazuminn
d5fba5e54b fix test 2020-10-03 19:40:40 +09:00
Kazuminn
fb4ee59dee refactor 2020-10-03 17:58:43 +09:00
Kazuminn
5071aa0783 all test passed 2020-10-03 17:55:08 +09:00
Kazuminn
927df3f32a check_regex test ok 2020-10-03 17:34:37 +09:00
Kazuminn
6d8e0a61d2 test 2 pass 2020-10-03 16:52:39 +09:00
Kazuminn
bb2d4bc537 add check_command() 2020-10-03 13:06:25 +09:00
Kazuminn
acf8f8d022 add check_obfu() 2020-10-02 23:26:07 +09:00
Kazuminn
2bf76c4209 add check_regex() and check_creater() 2020-10-02 14:37:56 +09:00
siamease
fa9f3813ae add sysmon 2020-10-02 00:14:33 +09:00
siamease
42f8483485 add sysmon 2020-10-02 00:10:38 +09:00
akiranishikawa
d883def462 Merge branch 'feature/code_refactor' 2020-09-29 20:09:39 +09:00
akiranishikawa
9c8ca18b5f matchを使わない形に修正 2020-09-29 20:07:45 +09:00
nishikawaakira
fa7e5a057f Merge pull request #3 from YamatoSecurity/feature/system_104_7040
add DeepBlueCLI System's 104 7040 rule
2020-09-29 19:17:55 +09:00