Willi Ballenthin
c1d20764ad
use "span of calls" scope ( #973 )
...
* use sequence scope instead of thread scope for "static: function" rules
* use sequence scope instead of thread scope for "static: basic block" rules
* make runtime linking rules more concise
* doc: describe sequence scope
* rename "sequence" scope to "span of calls" scope
* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/get-geographical-location.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/file-managers/gather-classicftp-information.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/database/wmi/reference-wmi-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
* Update collection/database/sql/reference-sql-statements.yml
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
---------
Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com >
2025-01-29 10:27:13 +01:00
mr-tz
5430889902
update scopes
2023-11-24 11:51:37 +01:00
mr-tz
784c9dca53
upgrade rules using updated script
2023-11-24 11:34:28 +01:00
sara-rn
1178cd07b4
deleted old rule from installer/dotnet
2023-11-20 11:25:54 +01:00
sara-rn
dfa6f46b84
new file limitation rule for .net single file apps
2023-11-20 11:22:37 +01:00
Willi Ballenthin
7685a232d9
forwarded export: fmt
2023-08-02 14:41:35 +02:00
Ronnie Salomonsen
65ab87b292
Update executable/pe/export/forwarded-export.yml
...
Co-authored-by: Willi Ballenthin <wballenthin@google.com >
2023-07-19 14:54:12 +02:00
Ronnie Salomonsen
a8d00309c3
Add new rule for forwarded exports and update doc to with new characteristic and examples under export feature
2023-07-19 12:40:20 +02:00
Moritz
915c1f5e07
remove very common .rsrc section rule ( #761 )
...
* remove very common rule
2023-05-26 10:34:25 +02:00
Mike Hunhoff
52bbc8d698
adding "packaged as single-file .NET application" ( #699 )
...
* adding "packaged as single-file .NET application"
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com >
* add sample binary, move from nursery
2023-02-15 08:16:05 -07:00
Moritz
106123eb61
Rules for the week ( #671 )
...
* add rules
* avoid FPs via mnemonics to ignore
* correct number logic
* add --onefile option strings
2023-01-27 09:56:12 +01:00
Moritz
b48fcd5dd8
improve rules that often match ( #655 )
...
* improve rules that often match
2023-01-09 14:07:53 +01:00
johnk3r
3f298900d4
use .NET libraries ( #612 )
...
* Add files via upload
https://github.com/mandiant/capa-rules/issues/609
* Update load-suspicious-libraries.yml
* Delete load-suspicious-libraries.yml
* Create load-suspicious-libraries.yml
* Update load-suspicious-libraries.yml
* Update load-suspicious-libraries.yml
* embed dependencies as resources using Fody/Costura
https://github.com/mandiant/capa-rules/pull/612
* Delete embed-dependencies-as-resources-using-fody-costura.yml
* embed-dependencies-as-resources-using-fody-costura
https://github.com/mandiant/capa-rules/pull/612
* Rename embed-dependencies-as-resources-using-fody-costura.yml to embed-dependencies-as-resources-using-fodycostura.yml
* use-dotnet-library-encryptdecryptutils
https://github.com/mandiant/capa-rules/pull/612
* use-dotnet-library-newtonsoft.json
https://github.com/mandiant/capa-rules/pull/612
* use-dotnet-library-sharpclipboard
https://github.com/mandiant/capa-rules/pull/612
* use-dotnet-library-sharpvectors
https://github.com/mandiant/capa-rules/pull/612
* Delete load-suspicious-libraries.yml
* Rename use-dotnet-library-newtonsoft.json.yml to use-dotnet-library-newtonsoftjson.yml
* Update use-dotnet-library-newtonsoftjson.yml
* Update use-dotnet-library-sharpvectors.yml
* Update use-dotnet-library-encryptdecryptutils.yml
* Update use-dotnet-library-sharpclipboard.yml
* Rename anti-analysis/obfuscation/use-dotnet-library-encryptdecryptutils.yml to data-manipulation/encryption/aes/use-dotnet-library-encryptdecryptutils.yml
* Rename nursery/use-dotnet-library-newtonsoftjson.yml to data-manipulation/json/use-dotnet-library-newtonsoftjson.yml
* Rename nursery/use-dotnet-library-sharpvectors.yml to data-manipulation/svg/use-dotnet-library-sharpvectors.yml
* Update use-dotnet-library-sharpclipboard.yml
* Update use-dotnet-library-newtonsoftjson.yml
* Update use-dotnet-library-sharpvectors.yml
* Update use-dotnet-library-encryptdecryptutils.yml
* Update use-dotnet-library-newtonsoftjson.yml
* Update use-dotnet-library-sharpvectors.yml
* Update use-dotnet-library-encryptdecryptutils.yml
* Update embed-dependencies-as-resources-using-fodycostura.yml
* Update use-dotnet-library-encryptdecryptutils.yml
* Update use-dotnet-library-sharpvectors.yml
* Update use-dotnet-library-newtonsoftjson.yml
* Update use-dotnet-library-sharpclipboard.yml
2022-08-29 18:49:40 +02:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
Andrew
fbafd732e7
Update rule metadata for rules written by @recvfrom
...
Mostly just changes @recvfrom to awillia2@cisco.com , but
also updates the descriptions in a few places to be
more precise (I don't think I initially realized that
`api` has function scope and is for API calls whereas
`import` has file level scope and is just for the import)
2021-06-06 23:30:34 -04:00
Andrew
64e7452ae7
Add packaged-as-an-inno-setup-installer
...
Add packaged-as-an-inno-setup-installer which looks for simple strings
associated with Inno Setup installers. These strings appear to be
present in installers produced using at least Inno Setup version 3
through the latest (Inno Setup version 6).
2021-05-23 22:54:04 -04:00
Willi Ballenthin
b21ca8d120
embedded pe: via strings
...
closes #319
2021-04-14 12:34:57 -06:00
mike-hunhoff
eb8221d9ad
Merge pull request #305 from fireeye/enfore-string-format
...
enforce string formatting
2021-03-25 12:36:51 -06:00
Michael Hunhoff
20e1b8fd4c
enforce string formatting with double quotes + escaped special characters
2021-03-24 14:14:38 -06:00
Moritz Raabe
6c9f83dd7f
merge duplicate rules
2021-03-22 18:42:54 +01:00
Andrew
12ff221b68
Add packaged-as-an-iexpress-self-extracting-archive
2021-03-21 22:25:21 -04:00
Michael Hunhoff
750e164a41
removing ntdll requirement from function features exported by both ntdll and ntoskrnl
2021-02-16 18:28:05 -07:00
Desiree Beck
5d285c5651
mappings for additions to namespaces
2021-01-21 15:29:06 -05:00
Desiree Beck
490bc34a05
add method to pe area
2020-10-19 14:01:02 -04:00
William Ballenthin
4350ffad33
fix rule paths thanks to linter
2020-07-23 11:58:23 -06:00
William Ballenthin
54cfb05bd0
rules: address comments in #14
2020-06-26 17:45:56 -06:00
William Ballenthin
7b4f4d10fb
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9
rules: reorganize rule names, namespaces, and ATT&CK mappings
2020-06-21 17:25:43 -06:00