mirror of
https://github.com/vee1e/capa-rules.git
synced 2026-09-03 11:57:25 +00:00
22 lines
817 B
YAML
22 lines
817 B
YAML
rule:
|
|
meta:
|
|
name: disable driver code integrity
|
|
namespace: host-interaction/driver
|
|
author: william.ballenthin@fireeye.com
|
|
scope: function
|
|
references:
|
|
- https://www.fuzzysecurity.com/tutorials/28.html
|
|
- https://j00ru.vexillium.org/2010/06/insight-into-the-driver-signature-enforcement/
|
|
examples:
|
|
- 31CEE4F66CF3B537E3D2D37A71F339F4:0x140004070
|
|
features:
|
|
- or:
|
|
- string: CiInitialize
|
|
description: exported symbol name used to resolve code integrity configuration
|
|
- string: /g_CiEnabled/
|
|
description: non-exported name for code integrity flag
|
|
- string: /g_CiOptions/
|
|
description: non-exported name for code integrity settings
|
|
- optional:
|
|
- string: /CI.dll/i
|
|
description: code integrity implementation DLL
|