Willi Ballenthin
c1d20764ad
use "span of calls" scope ( #973 )
...
* use sequence scope instead of thread scope for "static: function" rules
* use sequence scope instead of thread scope for "static: basic block" rules
* make runtime linking rules more concise
* doc: describe sequence scope
* rename "sequence" scope to "span of calls" scope
* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/get-geographical-location.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/file-managers/gather-classicftp-information.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/database/wmi/reference-wmi-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
* Update collection/database/sql/reference-sql-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
---------
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-01-29 10:27:13 +01:00
JJ
9e0ffdf7c5
Add rule compiled-with-dart.yml ( #906 )
...
* Add rule compiled-with-dart.yml
2024-06-05 11:40:32 +02:00
Moritz
82316f7d91
reduce FPs by adjusting go1. substring feature ( #891 )
...
* reduce FPs by adjusting `go1.` substring feature
2024-04-24 13:38:06 +02:00
mr-tz
2d3be8ec38
fix some dynamic unsupported rules
2023-11-24 11:35:05 +01:00
mr-tz
8a36231025
fix scopes for rules with subscopes 2
2023-11-24 11:35:03 +01:00
mr-tz
e18704545a
fix call/thread scopes manually
2023-11-24 11:35:00 +01:00
mr-tz
784c9dca53
upgrade rules using updated script
2023-11-24 11:34:28 +01:00
jtothej
1a5751691b
Update and promote compiled-with-cx_freeze.yml
2023-07-04 13:47:30 +08:00
Willi Ballenthin
9cda994949
Merge pull request #701 from wballenthin/patch-1
...
rust: add more strings
2023-02-15 11:55:19 +01:00
Willi Ballenthin (Google)
c3c2e0cd30
rust: add more strings
2023-02-15 10:07:53 +00:00
Moritz
106123eb61
Rules for the week ( #671 )
...
* add rules
* avoid FPs via mnemonics to ignore
* correct number logic
* add --onefile option strings
2023-01-27 09:56:12 +01:00
Willi Ballenthin
4b2b42d217
add compiled-with-nuitka
2023-01-04 09:09:26 +01:00
jtothej
f75b401014
Updated compiled-with-ps2exe.yml to match on files build using recent versions of ps2exe available @ https://github.com/MScholtes/PS2EXE
2022-07-26 13:46:23 +02:00
Moritz
7c802af22f
Update compiled-with-borland-delphi.yml
2022-06-23 14:29:02 +02:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
jtothej
9cc5be5ce4
Updated compiled-with-zig.yml - removed Windows specific logic
2022-03-22 10:44:36 +08:00
jtothej
22a7f2af3a
Adding compiled-with-v.yml and compiled-with-zig.yml
2022-03-21 17:38:15 +08:00
Stephen Eckels
954f22acd8
Add golang runtime pattern ( #518 )
...
* Add golang runtime pattern
* Fix lints
* fix filename lint
* merge go rules
* Update compiler/go/compiled-with-go.yml
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2021-12-23 17:34:11 +01:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
William Ballenthin
0ef69c4fbd
*: use substring features rather than unreadable regexes
...
closes #450
2021-08-24 12:47:26 -06:00
William Ballenthin
6a447d91a4
Merge branch 'master' of https://github.com/ruppde/capa-rules into ruppde-master
2021-08-18 14:35:54 -06:00
Willi Ballenthin
38298d876b
Update compiler/go/compiled-with-go.yml
2021-08-18 14:34:20 -06:00
Moritz Raabe
413d614557
add autohotkey limitation rule
2021-06-08 14:45:43 +02:00
William Ballenthin
f3a86f89c0
graduate "compiled with Nim"
2021-06-04 12:06:34 -06:00
Joshua Lee
99cafcab6f
Missed T in att&ck ID
2021-06-04 16:47:13 +08:00
Arnim Rupp
1262b0f18e
small fixes
2021-05-20 23:10:31 +02:00
William Ballenthin
6e501e8151
rules: convert inline comments to descriptions
...
closes #1
2021-05-18 10:45:41 -06:00
William Ballenthin
f1b450edf0
update ATT&CK and MBC mappings
...
thanks to Regina Elwell @ FireEye and @evandrix
closes #316
2021-04-13 09:37:10 -06:00
Michael Hunhoff
20e1b8fd4c
enforce string formatting with double quotes + escaped special characters
2021-03-24 14:14:38 -06:00
Willi Ballenthin
74f372149f
exe4j: remove ATT&CK mapping
2021-03-02 08:05:42 -07:00
Willi Ballenthin
72b0e07b70
Merge pull request #277 from johnk3r/master
...
compiled-with-exe4j.yml
2021-02-24 16:00:01 -07:00
johnk3r
e3772da804
Update compiler/exe4j/compiled-with-exe4j.yml
...
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
2021-02-24 19:09:06 -03:00
johnk3r
912428119d
Update compiled-with-exe4j.yml
2021-02-22 18:46:50 -03:00
Willi Ballenthin
ceca25cfab
Merge pull request #276 from fireeye/williballenthin-patch-1
...
add compiled-from-visual-basic.yml
2021-02-19 10:16:58 -07:00
Willi Ballenthin
cbb0a64cff
formatting
2021-02-19 10:12:38 -07:00
johnk3r
ba368f9015
Update compiled-with-exe4j.yml
2021-02-18 23:51:55 -03:00
johnk3r
60aac095b8
Create compiled-with-exe4j.yml
...
https://github.com/fireeye/capa-rules/issues/261
2021-02-18 23:48:16 -03:00
re-fox
d4261f3088
Update compiled-with-dmd.yml
...
Updated meta
2021-02-18 15:52:37 -05:00
Willi Ballenthin
be92ddec78
add compiled-from-visual-basic.yml
...
closes #274
2021-02-18 13:17:25 -07:00
re-fox
be9d27ccf9
Update compiled-with-dmd.yml
2021-02-18 13:07:48 -05:00
re-fox
42aa681adb
Create compiled-with-dmd.yml
2021-02-18 13:00:01 -05:00
re-fox
15dbc4745b
Update compiled-with-borland-delphi.yml
2021-02-18 11:53:20 -05:00
Moritz Raabe
387334a603
reformated using capafmt
2021-01-27 15:30:59 +01:00
Willi Ballenthin
96f27f2559
Merge pull request #218 from fireeye/re-fox-patch-2
...
Create compiled-with-perl2exe.yml
2021-01-12 11:29:59 -07:00
Willi Ballenthin
5c34f70573
Merge pull request #219 from re-fox/master
...
Create compiled-with-ps2exe.yml
2021-01-12 11:29:34 -07:00
Willi Ballenthin
d9b850824d
Merge pull request #221 from itsreallynick/patch-1
...
Create compiled-with-pyarmor.yml
2021-01-12 11:29:16 -07:00
Willi Ballenthin
d5cc23fc72
pyarmor: limit to a single example (the smaller one)
2021-01-12 11:27:44 -07:00
Nick Carr
24401d206b
Update compiled-with-pyarmor.yml
2021-01-12 13:20:14 -05:00
Nick Carr
b93543a902
Update compiled-with-pyarmor.yml
...
Updated capa rule name to match filename
2021-01-12 13:00:02 -05:00
Nick Carr
f1f529b3ec
Create compiled-with-pyarmor.yml
...
Coverage for Dashingsoft's pyarmor, as referenced in public communications from the Honorable Doctor Steven Miller of the FireEye Institute: https://twitter.com/stvemillertime/status/1349032548580483073
A basic rule to help people understand what may have obfuscated the file they are analyzing.
Fellow scientists may debate whether or not this is truly a compiler or an obfuscator belonging elsewhere in the namespace tree, but to them I say: 'ok sure I barely even know if I'm doing this right so, fine'
It may also be worth looking at https://github.com/liftoff/pyminifier and then just making a wider collection of PE obfuscator/compilers from scripting languages
2021-01-12 12:08:55 -05:00