Skip to content

vidar - #4217

Merged
nasbench merged 7 commits into
developfrom
vidar
Aug 19, 2026
Merged

vidar#4217
nasbench merged 7 commits into
developfrom
vidar

Conversation

@tccontre

@tccontre tccontre commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Tagged

    modified:   detections/endpoint/executables_or_script_creation_in_suspicious_path.yml
    modified:   detections/endpoint/executables_or_script_creation_in_temp_path.yml
    modified:   detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml
    modified:   detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml
    modified:   detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml
    modified:   detections/endpoint/windows_credentials_from_password_stores_chrome_extension_access.yml
    modified:   detections/endpoint/windows_credentials_from_password_stores_chrome_localstate_access.yml
    modified:   detections/endpoint/windows_credentials_from_password_stores_chrome_login_data_access.yml
    modified:   detections/endpoint/windows_disable_or_stop_browser_process.yml
    modified:   detections/endpoint/windows_indicator_removal_via_rmdir.yml
    modified:   detections/endpoint/windows_process_injection_remote_thread.yml
    modified:   detections/endpoint/windows_query_registry_uninstall_program_list.yml
    modified:   detections/endpoint/windows_screen_capture_in_temp_folder.yml
    modified:   detections/endpoint/windows_suspicious_process_file_path.yml

New Detections

    new file:   detections/endpoint/windows_cloud_sensitive_file_read_access_by_uncommon_process

Story

    new file:   stories/vidar_stealer.yml

Comment thread detections/endpoint/windows_azure_token_store_access.yml Outdated

@onurmerdogan onurmerdogan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great, just a few minor points and suggestion regarding increased scope for Cloud credential theft.

Comment thread detections/endpoint/windows_azure_profile_reconnaissance.yml Outdated
Comment thread detections/endpoint/windows_azure_profile_reconnaissance.yml Outdated
Comment thread detections/endpoint/windows_azure_profile_reconnaissance.yml Outdated
Comment thread detections/endpoint/windows_azure_profile_reconnaissance.yml Outdated
nasbench
nasbench previously approved these changes Aug 19, 2026

@nasbench nasbench left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I applied recommendations from Onur as well as other metadata/logic updates. Basically we have a single detections now that cover cloud sensitive file read access. Please keep updating it with additional paths and filters.

@nasbench
nasbench merged commit 4fede6c into develop Aug 19, 2026
6 checks passed
@nasbench
nasbench deleted the vidar branch August 19, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants