chronicle / detection-rules

Collection of YARA-L 2.0 sample rules for the Chronicle Detection API
https://chronicle.security
Apache License 2.0
275 stars 66 forks source link

Detection for SOGU malware #60

Closed Rommel-J closed 2 months ago

Rommel-J commented 2 months ago

Added 3 YARAL detection for SOGU malware behaviour.

First time contributing to the project. Pls help review.

Reference: https://www.mandiant.com/resources/blog/infected-usb-steal-secrets

google-cla[bot] commented 2 months ago

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.