Skip to content

New type of version bumping error#400

Merged
pyth0n1c merged 2 commits intomainfrom
version_bumping_check_change
Apr 22, 2025
Merged

New type of version bumping error#400
pyth0n1c merged 2 commits intomainfrom
version_bumping_check_change

Conversation

@ljstella
Copy link
Copy Markdown
Contributor

We previously checked for versions increasing AT LEAST 1 when there were changes.

This adds a check to ensure that versions do not increase more than 1 between builds, and cleans up the errors to clarify this.

@ljstella
Copy link
Copy Markdown
Contributor Author

Sample output:

Detection Metadata Validation:
        ❌ ESCU - Disable Registry Tool - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disable Security Logs Using MiniNt Registry - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Disable Show Hidden Files - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disable Windows App Hotkeys - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Disabling CMD Application - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disabling ControlPanel - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disabling NoRun Windows App - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Download Files Using Telegram - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Enable WDigest UseLogonCredential Registry - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Enumerate Users Local Group Using Telegram - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - FodHelper UAC Bypass - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - GetWmiObject User Account with PowerShell - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - LOLBAS With Network Traffic - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Malicious InProcServer32 Modification - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Mmc LOLBAS Execution Process Spawn - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - MSI Module Loaded by Non-System Binary - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Msmpeng Application DLL Side Loading - Rule
                🔸 Detection version in current build should be bumped to 9.
        ❌ ESCU - Potential Telegram API Request Via CommandLine - Rule
                🔸 Detection version in current build should be reduced to 3.
        ❌ ESCU - PowerShell 4104 Hunting - Rule
                🔸 Detection version in current build should be reduced to 15.
        ❌ ESCU - Powershell Creating Thread Mutex - Rule
                🔸 Detection version in current build should be reduced to 9.
        ❌ ESCU - Remcos client registry install entry - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Revil Registry Entry - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Rundll32 Shimcache Flush - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Suspicious Copy on System32 - Rule
                🔸 Detection version in current build should be reduced to 9.
        ❌ ESCU - Suspicious Process Executed From Container File - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Suspicious Reg exe Process - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Windows Cmdline Tool Execution From Non-Shell Process - Rule
                🔸 Detection version in current build should be reduced to 5.
        ❌ ESCU - Windows Defender ASR Registry Modification - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Defender ASR Rule Disabled - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Deleted Registry By A Non Critical Process File Path - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Disable Change Password Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable LogOff Button Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Notification Center - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Shutdown Button Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Windows Exfiltration Over C2 Via Invoke RestMethod - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Hide Notification Features Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows HTTP Network Communication From MSIExec - Rule
                🔸 Detection version in current build should be reduced to 4.
        ❌ ESCU - Windows Impair Defenses Disable AV AutoStart via Registry - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows InProcServer32 New Outlook Form - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Known Abused DLL Created - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Known Abused DLL Loaded Suspiciously - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Known GraphicalProton Loaded Modules - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows LOLBAS Executed As Renamed File - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Masquerading Explorer As Child Process - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Windows Modify Registry AuthenticationLevelOverride - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Auto Minor Updates - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Auto Update Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Configure BitLocker - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows Modify Registry Default Icon Setting - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Delete Firewall Rules - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Modify Registry Disable RDP - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows Modify Registry Disable Restricted Admin - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry Disable Toast Notifications - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disable Win Defender Raw Write Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disable WinDefender Notifications - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disable Windows Security Center Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DisableRemoteDesktopAntiAlias - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DisableSecuritySettings - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disabling WER Settings - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DisAllow Windows App - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Do Not Connect To Win Update - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DontShowUI - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry EnableLinkedConnections - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry LongPathsEnabled - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry MaxConnectionPerServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry No Auto Reboot With Logon User - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry No Auto Update - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry NoChangingWallPaper - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry on Smart Card Group Policy - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows Modify Registry ProxyEnable - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry ProxyServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Qakbot Binary Data Registry - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Regedit Silent Reg Import - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Modify Registry Suppress Win Defender Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Tamper Protection - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry to Add or Modify Firewall Rule - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry UpdateServiceUrlAlternate - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry USeWuServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Utilize ProgIDs - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Modify Registry ValleyRAT C2 Config - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry ValleyRat PWN Reg Entry - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry With MD5 Reg Key Name - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry WuServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry wuStatusServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Show Compress Color And Info Tip Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows MSIExec DLLRegisterServer - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Windows MsiExec HideWindow Rundll32 Execution - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows MSIExec Remote Download - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Windows MSIExec Spawn Discovery Command - Rule
                🔸 Detection version in current build should be reduced to 9.
        ❌ ESCU - Windows New InProcServer32 Added - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Outlook WebView Registry Modification - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows PowerShell Export PfxCertificate - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows Process Injection Remote Thread - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Screen Capture Via Powershell - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Snake Malware Registry Modification wav OpenWithProgIds - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows SnappyBee Create Test Registry - Rule
                🔸 Detection version in current build should be bumped to 3.
        ❌ ESCU - Windows SqlWriter SQLDumper DLL Sideload - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Suspicious Process File Path - Rule
                🔸 Detection version in current build should be reduced to 10.
        ❌ ESCU - Windows System Network Config Discovery Display DNS - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Unsigned DLL Side-Loading In Same Process Path - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows WMI Impersonate Token - Rule
                🔸 Detection version in current build should be reduced to 6.
Verbose error logging is DISABLED.

@ljstella
Copy link
Copy Markdown
Contributor Author

Now running inspect against develop in security_content:

Detection Metadata Validation:
        ❌ ESCU - Disable Registry Tool - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disable Security Logs Using MiniNt Registry - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Disable Show Hidden Files - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disable Windows App Hotkeys - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Disabling CMD Application - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disabling ControlPanel - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Disabling NoRun Windows App - Rule
                🔸 Detection version in current build should be bumped to 12.
        ❌ ESCU - Download Files Using Telegram - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Enable WDigest UseLogonCredential Registry - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Enumerate Users Local Group Using Telegram - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - FodHelper UAC Bypass - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - GetWmiObject User Account with PowerShell - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - LOLBAS With Network Traffic - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Malicious InProcServer32 Modification - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Mmc LOLBAS Execution Process Spawn - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Potential Telegram API Request Via CommandLine - Rule
                🔸 Detection version in current build should be reduced to 3.
        ❌ ESCU - PowerShell 4104 Hunting - Rule
                🔸 Detection version in current build should be reduced to 15.
        ❌ ESCU - Powershell Creating Thread Mutex - Rule
                🔸 Detection version in current build should be reduced to 9.
        ❌ ESCU - Remcos client registry install entry - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Revil Registry Entry - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Rundll32 Shimcache Flush - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Suspicious Copy on System32 - Rule
                🔸 Detection version in current build should be reduced to 9.
        ❌ ESCU - Suspicious Process Executed From Container File - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Suspicious Reg exe Process - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Windows Cmdline Tool Execution From Non-Shell Process - Rule
                🔸 Detection version in current build should be reduced to 5.
        ❌ ESCU - Windows Defender ASR Registry Modification - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Defender ASR Rule Disabled - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Deleted Registry By A Non Critical Process File Path - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Disable Change Password Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable LogOff Button Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Notification Center - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Shutdown Button Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule
                🔸 Detection version in current build should be bumped to 11.
        ❌ ESCU - Windows DLL Side-Loading In Calc - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows DLL Side-Loading Process Child Of Calc - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows Exfiltration Over C2 Via Invoke RestMethod - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Hide Notification Features Through Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows HTTP Network Communication From MSIExec - Rule
                🔸 Detection version in current build should be reduced to 4.
        ❌ ESCU - Windows Impair Defenses Disable AV AutoStart via Registry - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows InProcServer32 New Outlook Form - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Known GraphicalProton Loaded Modules - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows LOLBAS Executed As Renamed File - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Masquerading Explorer As Child Process - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Windows Modify Registry AuthenticationLevelOverride - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Auto Minor Updates - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Auto Update Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Configure BitLocker - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows Modify Registry Default Icon Setting - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Delete Firewall Rules - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Modify Registry Disable RDP - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows Modify Registry Disable Restricted Admin - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry Disable Toast Notifications - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disable Win Defender Raw Write Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disable WinDefender Notifications - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disable Windows Security Center Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DisableRemoteDesktopAntiAlias - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DisableSecuritySettings - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Disabling WER Settings - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DisAllow Windows App - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Do Not Connect To Win Update - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry DontShowUI - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry EnableLinkedConnections - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry LongPathsEnabled - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry MaxConnectionPerServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry No Auto Reboot With Logon User - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry No Auto Update - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry NoChangingWallPaper - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry on Smart Card Group Policy - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows Modify Registry ProxyEnable - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry ProxyServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Qakbot Binary Data Registry - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Regedit Silent Reg Import - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Modify Registry Suppress Win Defender Notif - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Tamper Protection - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry to Add or Modify Firewall Rule - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry UpdateServiceUrlAlternate - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry USeWuServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry Utilize ProgIDs - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Modify Registry ValleyRAT C2 Config - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry ValleyRat PWN Reg Entry - Rule
                🔸 Detection version in current build should be bumped to 8.
        ❌ ESCU - Windows Modify Registry With MD5 Reg Key Name - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry WuServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Registry wuStatusServer - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows Modify Show Compress Color And Info Tip Registry - Rule
                🔸 Detection version in current build should be bumped to 10.
        ❌ ESCU - Windows MSIExec DLLRegisterServer - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Windows MsiExec HideWindow Rundll32 Execution - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows MSIExec Remote Download - Rule
                🔸 Detection version in current build should be reduced to 8.
        ❌ ESCU - Windows MSIExec Spawn Discovery Command - Rule
                🔸 Detection version in current build should be reduced to 9.
        ❌ ESCU - Windows New InProcServer32 Added - Rule
                🔸 Detection version in current build should be bumped to 6.
        ❌ ESCU - Windows Outlook WebView Registry Modification - Rule
                🔸 Detection version in current build should be bumped to 5.
        ❌ ESCU - Windows PowerShell Export PfxCertificate - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows Process Injection Remote Thread - Rule
                🔸 Detection version in current build should be reduced to 7.
        ❌ ESCU - Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Screen Capture Via Powershell - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Snake Malware Registry Modification wav OpenWithProgIds - Rule
                🔸 Detection version in current build should be bumped to 7.
        ❌ ESCU - Windows SnappyBee Create Test Registry - Rule
                🔸 Detection version in current build should be bumped to 3.
        ❌ ESCU - Windows Suspicious Process File Path - Rule
                🔸 Detection version in current build should be reduced to 10.
        ❌ ESCU - Windows System Network Config Discovery Display DNS - Rule
                🔸 Detection version in current build should be reduced to 6.
        ❌ ESCU - Windows Unsigned DLL Side-Loading - Rule
                🔸 Detection version in current build should be reduced to 10.
        ❌ ESCU - Windows Unsigned MS DLL Side-Loading - Rule
                🔸 Detection version in current build should be reduced to 10.
        ❌ ESCU - Windows WMI Impersonate Token - Rule
                🔸 Detection version in current build should be reduced to 6.
Verbose error logging is DISABLED.
Please use the --verbose command line argument if you need more context for your error or file a bug report.
Validation errors when comparing detection stanzas in current and previous build: (102 sub-exceptions)

Copy link
Copy Markdown
Contributor

@pyth0n1c pyth0n1c left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good in testing. This change will cut through a lot of poor versioning experience noise.

@pyth0n1c pyth0n1c merged commit d78668d into main Apr 22, 2025
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants