Defender Scan Pipeline — Stage 9
SIGNATURE_TYPE_BRUTE @ 0x10986D8C • HSTR_WEIGHT @ 0x1097C6D0 • mpengine.dll
Two complementary matching approaches: format-specific vs. format-agnostic
SIGNATURE_TYPE_PEHSTR @ 0x109869C8SIGNATURE_TYPE_BRUTE @ 0x10986D8CRolling hash with weighted scoring -- the core of BRUTE matching
Multiple weak indicators combine to exceed a threshold -- reducing false positives
GetHSTRCallerId @ 0x1097F460 — Different matching profiles per pipeline stage
BRUTE extracts format-specific features for ML classification and Lua analysis
!MTB/!ml detections, and Lua scripts (Stage 10) for complex logic
BRUTE is one of 10+ HSTR matching variants, each targeting different content types
BRUTE match results are the primary data source for Lua-based complex detection
Specialized BRUTE matching for deobfuscated script content
BRUTE matching is the format-agnostic safety net in the Defender pipeline. While format-specific engines provide fast targeted matching, BRUTE ensures that no content passes through without thorough raw-byte pattern analysis. Its weighted scoring and Lua integration enable detection of sophisticated polymorphic threats.
SIGNATURE_TYPE_BRUTE @ 0x10986D8C • HSTR_WEIGHT @ 0x1097C6D0 • 162 sig types • mpengine.dll