49 Commits

Author SHA1 Message Date
Willi Ballenthin 15f01df0ad fix: add example offsets to a few rules
ref https://github.com/mandiant/capa/issues/3058
2026-05-07 12:13:02 +02:00
Still / Azaka fb3737b90a Loosen AFD driver usage detection (#1086)
* Move CreateEvent to optional

Signed-off-by: Still Hsu <dev@stillu.cc>
2025-12-04 13:10:46 +01:00
Dhruva Kumar Kaushal 6697513245 improve TCP/UDP socket creation matching #964 (#993)
* improve TCP/UDP socket creation matching #964

* Adding references

* adding IPPROTO_UDP

* relax rule

* function -> basic block

* adding bytes for indirect(0)

* adding bytes for indirect(0)

* back to default changes

* moved to nursery

* final change

* resolving comment

* indentation error
2025-03-14 11:45:36 -06:00
Hafiz Farhad 77f06fd049 Addresses #965: Create separate rules for socket connects (TCP/UDP) (#1017)
* Separate socket connection rules for TCP and UDP

- Introduce a generic "connect socket" rule capturing common connection APIs (connect, ws2_32.connect, WSAConnect, ConnectEx, and related ConnectEx setup patterns).
- Refactor the TCP connect rule to require a match on "create TCP socket" and the generic rule, preserving TCP-specific behaviors while maximizing reuse.
- Add a new UDP connect rule that requires a match on "create UDP socket" and the generic connect rule.

Closes #965.

* Update socket rule examples with correct offsets for UDP/TCP

* Updated suggested changes
2025-03-10 14:38:43 -06:00
Willi Ballenthin c1d20764ad use "span of calls" scope (#973)
* use sequence scope instead of thread scope for "static: function" rules

* use sequence scope instead of thread scope for "static: basic block" rules

* make runtime linking rules more concise

* doc: describe sequence scope

* rename "sequence" scope to "span of calls" scope

* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/get-geographical-location.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/file-managers/gather-classicftp-information.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/wmi/reference-wmi-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/sql/reference-sql-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-01-29 10:27:13 +01:00
vibhatsu b4e0c8cdf8 remove duplicate features from some rules (#984)
* remove duplicate features from some rules

* keep commented hex values to show AfdOpenPacketX structure

Signed-off-by: vibhatsu <maulikbarot2915@gmail.com>

---------

Signed-off-by: vibhatsu <maulikbarot2915@gmail.com>
2025-01-28 12:54:17 +01:00
JJ 99e100db28 Add new rule attach-bpf-to-socket-on-linux.yml (#922)
* Add new rule attach-bpf-to-socket-on-linux.yml

---------

Co-authored-by: Willi Ballenthin <wballenthin@google.com>
2024-08-14 10:48:04 +02:00
Willi Ballenthin 2c5c0ae60b add API features for ws2_32 ordinals (#893) 2024-04-23 14:20:28 +02:00
Moritz 4e725638a6 fix logic after dynamic update (#857)
* fix logic after dynamic update

---------

Co-authored-by: Yacine <16624109+yelhamer@users.noreply.github.com>
2023-12-08 22:40:40 +01:00
mr-tz 5e2dae155f update scopes 2023-11-24 11:35:09 +01:00
Willi Ballenthin 696287da05 vmci: tweak required vs optional APIs 2023-11-24 11:35:08 +01:00
Willi Ballenthin a6f3e4110a further dynamic scope tweaks 2023-11-24 11:35:06 +01:00
mr-tz 8a36231025 fix scopes for rules with subscopes 2 2023-11-24 11:35:03 +01:00
mr-tz e18704545a fix call/thread scopes manually 2023-11-24 11:35:00 +01:00
mr-tz 784c9dca53 upgrade rules using updated script 2023-11-24 11:34:28 +01:00
Mike Hunhoff 20d2218df7 init add of Xamarin rules (#824)
* init add of Xamarin rules

* Update and rename get-system-information-in-dotnet-on-android.yml to get-os-version-in-dotnet-on-android.yml
2023-11-22 11:05:26 -07:00
Mike Hunhoff 2a37df98f5 adding new rules based on private Linux sample(s) (#821)
* adding new rules based on private Linux sample(s)

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2023-10-09 18:27:33 +02:00
jtothej 098dacbae1 Add create-vmci-socket.yml 2023-07-04 14:24:29 +08:00
ryan 153d4c0d2c Update Mappings for MBC 2023-06-21 10:45:01 -04:00
Mike Hunhoff 63a4c6d5db improve .NET detections incl. sockets, files, directories (#708) 2023-02-23 09:45:49 +01:00
Mike Hunhoff c9f7f685dd update recieve-data-on-socket for .NET (#707) 2023-02-22 12:24:16 -07:00
Blas 005f9ced10 Rule for raw socket creation (#696)
* Create create-raw-socket-in-windows.yml

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2023-02-15 17:45:38 +01:00
Willi Ballenthin 4658e8dd4c add create tcp socket via raw AFD driver
closes #537
2023-02-01 11:47:52 +01:00
Mike Hunhoff dda76eadde new/update rules using .NET ctor method (#626) 2022-10-13 08:36:31 -06:00
Anushka Virgaonkar 1fbee15a3c Add dotnet rules having property features (#601) 2022-10-03 09:28:05 -06:00
Anushka Virgaonkar 95dc5eb27f Add new dotnet rules that capture capabilites typically found in backdoors. (#579) 2022-07-07 13:39:51 -06:00
Willi Ballenthin 57e1732f5c Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
This reverts commit d43a6ee544.
2022-06-28 15:23:20 -06:00
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
idiom 49ac35dbe7 Update rules to use a list item instead of a string value for references. 2022-05-11 10:39:42 -04:00
William Ballenthin d43a6ee544 Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
This reverts commit bc28847dd9, reversing
changes made to 82308c4109.
2022-04-27 06:23:36 -06:00
Willi Ballenthin 904bf3ef00 *: remove /x32 and /x64 flavors and use instruction scope 2022-04-05 12:25:14 -06:00
Desiree Beck ed3661b379 add mbc and att&ck tags 2021-12-14 16:16:07 -05:00
Moritz Raabe 25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
jlepore-fe 92972fd988 update function ptr size comments 2021-09-08 10:05:27 -04:00
jlepore-fe 9d1338113b transmitpackets callback function via wsaioctl (#456)
* transmitpackets callback function via wsaioctl

* Update communication/socket/tcp/send/wsaioctl_transmitpackets_callbackfunc.yml

Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>

* Update and rename wsaioctl_transmitpackets_callbackfunc.yml to obtain-transmitpackets-callback-function-via-wsaioctl

* Rename obtain-transmitpackets-callback-function-via-wsaioctl to obtain-transmitpackets-callback-function-via-wsaioctl.yml

* Update obtain-transmitpackets-callback-function-via-wsaioctl.yml

* Update obtain-transmitpackets-callback-function-via-wsaioctl.yml

Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
2021-08-30 18:30:14 +02:00
Joakim Kennedy 78fbf5f3c5 Fix linting errors 2021-08-05 15:35:27 +01:00
Joakim Kennedy 765e182553 A set of rules for Linux ELFs 2021-08-04 15:47:00 +01:00
Willi Ballenthin 1f48bd02a6 whitespace 2021-02-04 16:38:09 -07:00
Willi Ballenthin ebb14294b1 whitespace 2021-02-04 16:28:13 -07:00
Willi Ballenthin 06984304e4 connect-tcp-socket: add SO_UPDATE_CONNECT_CONTEXT 2021-02-04 16:25:44 -07:00
Willi Ballenthin b7809dae41 connect-tcp-socket: add SIO_GET_EXTENSION_FUNCTION_POINTER 2021-02-04 16:22:51 -07:00
Willi Ballenthin 0f6e2dacb3 connect-tcp-socket: fix lint issue 2021-02-04 16:20:27 -07:00
Willi Ballenthin f44903cb53 connect-tcp-socket: add ConnectEx via WSAID_CONNECTEX 2021-02-04 16:18:01 -07:00
William Ballenthin f8a3de9367 update attack mappings 2021-01-02 11:46:20 -07:00
Moritz Raabe 47c1b485c0 fix mbc objective 2020-10-01 10:30:08 +02:00
Desiree Beck 69e7479e40 mapping capa rule updates 2020-09-29 15:05:11 -04:00
Moritz Raabe b585c0ef73 update to basic block scope 2020-07-11 14:02:30 +02:00
William Ballenthin 7b4f4d10fb rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better 2020-06-21 17:54:01 -06:00
William Ballenthin 5f57dbdbc9 rules: reorganize rule names, namespaces, and ATT&CK mappings 2020-06-21 17:25:43 -06:00