Add in severity 1 sig for computername query #134
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Just for extra information & username sig coming too. This is the real sig I want to get complete and then converted back (this sig works well for Dridex but I need a lot more building of it):
cuckoosandbox/community#120
Once i have this signature working fully with all necessary APis, data and ways it is used I will convert it back. As I have been doing a lot of cuckoo-2.0 stuff it was easier to get the data flagged there and then I will look at getting the appended data, deduplication etc done for modified but hopefully it could end up being a useful sig for identifying how CnC is constructed or that it is setting up for CnC.
On a side note cuckoo 2.0 signature conversions are going ok and I am making sure everything is properly credited in the signature and the pull requests are linked to any of the original content on cuckoo-modified. I am doing what I can; obviously there is a lot that can't come over currently and there is also behaviour results not being followed right such as injections or process injections not followed, unlreated processes being included in results or even process creation not being followed it seems. Still I am reporting everything I find there and requesting features. Hopefully the spare time I spend doing this will be useful to the cuckoo community.
Still cuckoo-modified is my production and prefered sandbox. While I know I have said amazing job before you have done with this (as well as others) & doing comparisons and really digging into the activities the quality is awesome so thanks again!