capa-rules/persistence
xpzhxhm 5da642668e
Add new rule persist-via-shellserviceobjectdelayload-registry-key.yml (#1117)
* Create persist-via-shellserviceobjectdelayload-registry-key.yml

* Update persist-via-shellserviceobjectdelayload-registry-key.yml

Update rules and description, improve scope to function/basic block by adding HKLM constant, remove blank line.

* Update persist-via-shellserviceobjectdelayload-registry-key.yml

* Change the scope to function
2026-02-26 09:44:06 -07:00
..
authentication-process fix some dynamic unsupported rules 2023-11-24 11:35:05 +01:00
exchange use "span of calls" scope (#973) 2025-01-29 10:27:13 +01:00
iis fix some dynamic unsupported rules 2023-11-24 11:35:05 +01:00
office remove duplicate features from some rules (#984) 2025-01-28 12:54:17 +01:00
registry Add new rule persist-via-shellserviceobjectdelayload-registry-key.yml (#1117) 2026-02-26 09:44:06 -07:00
scheduled-tasks use "span of calls" scope for registry operations that span multiple calls, e.g. open registry key and set value (#999) 2025-02-20 14:02:16 -07:00
service add new rules to detect disabling system features via registry on Windows (#1034) 2025-03-24 10:38:19 -06:00
startup-folder use "span of calls" scope (#973) 2025-01-29 10:27:13 +01:00
act-as-dhcp-server-callout-dll.yml fix some dynamic unsupported rules 2023-11-24 11:35:05 +01:00
act-as-dns-server-plugin-dll.yml fix some dynamic unsupported rules 2023-11-24 11:35:05 +01:00
act-as-share-provider-dll.yml Add two new CAPA rules: act-as-share-provider-dll.yml and act-as-windbg-extension.yml 2024-05-31 16:20:01 +08:00
act-as-time-provider-dll.yml Add new rule act-as-time-provider-dll.yml 2024-06-01 12:14:24 +08:00
act-as-windbg-extension.yml Add two new CAPA rules: act-as-share-provider-dll.yml and act-as-windbg-extension.yml 2024-05-31 16:20:01 +08:00
create-shortcut-via-ishelllink.yml upgrade rules using updated script 2023-11-24 11:34:28 +01:00
persist-via-desktop-autostart.yml use "span of calls" scope (#973) 2025-01-29 10:27:13 +01:00
persist-via-shell-profile-or-rc-file.yml use "span of calls" scope (#973) 2025-01-29 10:27:13 +01:00