Commit graph

10 commits

Author SHA1 Message Date
Willi Ballenthin
c1d20764ad
use "span of calls" scope (#973)
* use sequence scope instead of thread scope for "static: function" rules

* use sequence scope instead of thread scope for "static: basic block" rules

* make runtime linking rules more concise

* doc: describe sequence scope

* rename "sequence" scope to "span of calls" scope

* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/get-geographical-location.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/file-managers/gather-classicftp-information.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/wmi/reference-wmi-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/sql/reference-sql-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-01-29 10:27:13 +01:00
mr-tz
784c9dca53 upgrade rules using updated script 2023-11-24 11:34:28 +01:00
Willi Ballenthin
07c10dd26b des: add more constants from libtomcrypt 2023-01-24 12:13:46 +01:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
Moritz Raabe
387334a603 reformated using capafmt 2021-01-27 15:30:59 +01:00
Desiree Beck
a0f10b4cf2 add mappings 2020-10-19 14:04:15 -04:00
Moritz Raabe
33ae14eb53 use new description syntax 2020-09-30 17:48:02 +02:00
Moritz Raabe
1fcec06e7e comment out description blocks for statements
discussed in #312
2020-09-14 11:53:01 +02:00
re-fox
ff739c3246
Create encrypt-data-using-des-via-winapi.yml 2020-07-28 15:17:07 -04:00
re-fox
b4e531a10b
Create encrypt-data-using-des.yml 2020-07-28 10:04:22 -04:00