Commit graph

31 commits

Author SHA1 Message Date
Saniya Fatima
7f70ec18ff
Flexible version of send HTTP request (#1110)
* Flexible version of send HTTP request

* Fix lint errors
2026-01-30 10:40:47 -07:00
Saniya Fatima
8caf489d8c
Fix false positive in send HTTP request (#1099) 2026-01-26 09:40:58 -07:00
Mike Hunhoff
7a52b6f9c0
dotnet: adding new rules based on recent samples (#1082)
* dotnet: adding new rules based on recent samples
2025-11-07 08:39:46 +01:00
Willi Ballenthin
36bf945aee fix scopes from lint errors
ref https://github.com/mandiant/capa/pull/2579
2025-01-29 18:54:25 +01:00
Willi Ballenthin
c1d20764ad
use "span of calls" scope (#973)
* use sequence scope instead of thread scope for "static: function" rules

* use sequence scope instead of thread scope for "static: basic block" rules

* make runtime linking rules more concise

* doc: describe sequence scope

* rename "sequence" scope to "span of calls" scope

* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/get-geographical-location.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/file-managers/gather-classicftp-information.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/wmi/reference-wmi-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/sql/reference-sql-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-01-29 10:27:13 +01:00
mr-tz
e18704545a fix call/thread scopes manually 2023-11-24 11:35:00 +01:00
mr-tz
784c9dca53 upgrade rules using updated script 2023-11-24 11:34:28 +01:00
Willi Ballenthin
ba2cc497f9 http request uri: move to nursery 2023-02-28 09:29:09 +01:00
Anushka Virgaonkar
95dc5eb27f
Add new dotnet rules that capture capabilites typically found in backdoors. (#579) 2022-07-07 13:39:51 -06:00
Willi Ballenthin
57e1732f5c
Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
This reverts commit d43a6ee544.
2022-06-28 15:23:20 -06:00
Mike Hunhoff
d4af075660
dotnet rule updates (#566) 2022-06-28 15:16:24 -06:00
Willi Ballenthin
838ca36067
*: fix blog links
ref: https://github.com/mandiant/capa/issues/800
2022-06-28 10:28:37 -06:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
William Ballenthin
d43a6ee544 Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
This reverts commit bc28847dd9, reversing
changes made to 82308c4109.
2022-04-27 06:23:36 -06:00
Willi Ballenthin
904bf3ef00
*: remove /x32 and /x64 flavors and use instruction scope 2022-04-05 12:25:14 -06:00
Michael Hunhoff
e7c2100400 updating download-url-to-file.yml 2021-12-06 10:35:03 -07:00
Desiree Beck
e190179ffd
Merge pull request #1 from MBCProject/ryan-patches1
Update patch-process-command-line.yml
2021-11-22 11:27:15 -05:00
William Ballenthin
18e48620b6 send file via http: fix example 2021-10-22 11:20:00 -06:00
Moritz Raabe
25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
Moritz Raabe
a69581c0a5 rule additions and updates 2021-09-10 16:04:25 +02:00
Ryan Xu
70f2af8563
Update create-bits-job.yml 2021-08-23 10:55:20 -05:00
William Ballenthin
d7dde41304 graduate "create BITS job" 2021-06-04 12:09:01 -06:00
William Ballenthin
6e501e8151 rules: convert inline comments to descriptions
closes #1
2021-05-18 10:45:41 -06:00
Moritz Raabe
77b737fcf0 rule tweaks based on PMA Lab 03-02.dll
see #296
2021-03-22 19:05:08 +01:00
Moritz Raabe
387334a603 reformated using capafmt 2021-01-27 15:30:59 +01:00
Moritz Raabe
15911402d8 comms and shellcode technique rules 2020-12-15 21:49:18 +01:00
Desiree Beck
69e7479e40 mapping capa rule updates 2020-09-29 15:05:11 -04:00
William Ballenthin
b878effef7 fix rules as documented in #49 2020-07-24 15:49:52 -06:00
William Ballenthin
54cfb05bd0 rules: address comments in #14 2020-06-26 17:45:56 -06:00
William Ballenthin
7b4f4d10fb rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better 2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9 rules: reorganize rule names, namespaces, and ATT&CK mappings 2020-06-21 17:25:43 -06:00