diff --git a/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml b/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml index d35238a55..87466688d 100644 --- a/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml +++ b/anti-analysis/anti-forensic/clear-logs/clear-windows-event-logs.yml @@ -28,7 +28,7 @@ rule: - api: wevtapi.EvtOpenSession - basic block: - and: - - string: /wevtutil(\.exe)?\s+(clear-log|cl)/i + - string: /\bwevtutil(\.exe)?\s+(clear-log|cl)/i - call: - and: - - string: /wevtutil(\.exe)?\s+(clear-log|cl)/i + - string: /\bwevtutil(\.exe)?\s+(clear-log|cl)/i diff --git a/anti-analysis/reference-analysis-tools-strings.yml b/anti-analysis/reference-analysis-tools-strings.yml index 42ca34d91..416aa756d 100644 --- a/anti-analysis/reference-analysis-tools-strings.yml +++ b/anti-analysis/reference-analysis-tools-strings.yml @@ -15,81 +15,81 @@ rule: - al-khaser_x86.exe_ features: - or: - - string: /ollydbg(\.exe)?/i - - string: /ProcessHacker(\.exe)?/i - - string: /tcpview(\.exe)?/i - - string: /autoruns(\.exe)?/i - - string: /autorunsc(\.exe)?/i - - string: /filemon(\.exe)?/i - - string: /procmon(\.exe)?/i - - string: /regmon(\.exe)?/i - - string: /procexp(\.exe)?/i - - string: /(?