100 Commits

Author SHA1 Message Date
Tarang 03a20f69ae Split .NET features from windows file & process rules (#1130)
* remove .NET features

* create separate read-file-in-dotnet.yml

* remove .NET features

* create separate write-file-dotnet.yml

* split create process rule into windows & .NET

* change static scope to instruction

* change static scope to insn and add dotnet match

* change static & dynamic scope to insn & call and add dotnet match

* change static scope to insn
2026-03-12 11:41:24 -06:00
Paul fa246a4a9b terminate process with RestartMgr.RmShutdown (#1077)
* terminate process with RestartMgr.RmShutdown

* fix 'and' to 'api'
2025-09-23 14:17:49 -06:00
Mike Hunhoff 7a719809d1 new/updated rules from recent malware samples (#1063) 2025-08-12 10:21:05 -06:00
Mike Hunhoff c002c5cd96 remove FPs from allocate-or-change-rwx-memory.yml (#1027) 2025-03-18 08:01:36 -06:00
Elad Levi 3bd8cf7646 Improve Accuracy of Various Detections (#1010)
* Update impersonate-user.yml

* Update enumerate-processes-on-remote-desktop-session-host.yml

* Update enumerate-processes-on-remote-desktop-session-host.yml

* Update enumerate-processes-on-remote-desktop-session-host.yml

* Update nursery/impersonate-user.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update host-interaction/process/list/enumerate-processes-on-remote-desktop-session-host.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-03-10 14:19:23 -06:00
Mike Hunhoff 6221d9b72b add more APIs to remove use-process-replacement FNs (#1009) 2025-02-25 08:59:09 -07:00
Mike Hunhoff b444a585ca additional APIs to remove FNs for inject apc 2025-02-20 15:08:04 -07:00
Dhruva Kumar Kaushal c0aa922f20 extend terminate-process.yml to include exit_group #970 (#991) 2025-02-04 21:49:39 +01:00
Willi Ballenthin 36bf945aee fix scopes from lint errors
ref https://github.com/mandiant/capa/pull/2579
2025-01-29 18:54:25 +01:00
Willi Ballenthin c1d20764ad use "span of calls" scope (#973)
* use sequence scope instead of thread scope for "static: function" rules

* use sequence scope instead of thread scope for "static: basic block" rules

* make runtime linking rules more concise

* doc: describe sequence scope

* rename "sequence" scope to "span of calls" scope

* Update anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/get-geographical-location.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/file-managers/gather-classicftp-information.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/wmi/reference-wmi-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

* Update collection/database/sql/reference-sql-statements.yml

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>

---------

Co-authored-by: Mike Hunhoff <mike.hunhoff@gmail.com>
2025-01-29 10:27:13 +01:00
Mike Hunhoff ff9db74425 update create-process-suspended to include DEBUG_ONLY_THIS_PROCESS (#978) 2025-01-07 13:02:37 -07:00
Matt Williams 9917a93ee1 get-process-filename.yml: added reference, corrected structure element 2024-10-18 19:09:05 +00:00
Matt Williams 01e45dfcf9 get-process-filename.yml: added x86 support (#945)
* Added x86 support for get-process-filename.yml
2024-10-16 18:11:11 +02:00
Matt Williams 627395d6f1 Add rule get-process-filename.yml (#936) 2024-09-26 11:36:40 -06:00
Mike Hunhoff ea14b38fbf adding / updating linux / android rules (#907)
* adding / updating linux / android rules

* update statement

* apply review feedback

* add additional android rules

* fix feedback
2024-06-11 12:10:57 -06:00
Mike Hunhoff ded2744733 adding new and updating linux / android rules (#903)
* adding new and updating linux / android rules

* fix lints
2024-05-31 13:24:19 -04:00
mr-tz f344af3327 add android OS where applicable 2024-04-23 13:49:05 +02:00
sara-rn 4f27bfe758 Ghostly Hollowing process injection rule (#865)
* ghostly hollowing process injection rule

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2024-01-23 10:55:34 +01:00
Moritz eecc7e87a8 Update TLS namespaces (#863)
* move TLS rules
2023-12-18 07:53:42 +01:00
mr-tz 8a36231025 fix scopes for rules with subscopes 2 2023-11-24 11:35:03 +01:00
mr-tz e18704545a fix call/thread scopes manually 2023-11-24 11:35:00 +01:00
mr-tz 784c9dca53 upgrade rules using updated script 2023-11-24 11:34:28 +01:00
Moritz a39a2c0b52 Merge branch 'master' into update-alloc-rules 2023-10-11 12:03:42 +02:00
mr-tz 66f58dffa0 update match rule name 2023-10-11 11:20:23 +02:00
mr-tz 5f223ea5ce rename rules 2023-10-11 11:17:13 +02:00
mr-tz ed791c9b17 separate allocate and change memory protection 2023-10-11 11:14:14 +02:00
Mike Hunhoff 2a37df98f5 adding new rules based on private Linux sample(s) (#821)
* adding new rules based on private Linux sample(s)

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2023-10-09 18:27:33 +02:00
mr-tz 64d3a359d3 fix example function address 2023-08-19 11:27:55 +02:00
JJ 1d6c6cbc56 Update host-interaction/process/inject/inject-shellcode-using-window-subclass-procedure.yml
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
2023-07-06 18:56:09 +08:00
jtothej fb55d37726 Add inject-shellcode-using-extra-window-memory.yml and inject-shellcode-using-window-subclass-procedure.yml 2023-07-06 16:19:40 +08:00
Moritz 21077c2908 revert MBC
E1055.004 cannot be validated at the moment
2023-06-28 07:50:07 +02:00
ryan 153d4c0d2c Update Mappings for MBC 2023-06-21 10:45:01 -04:00
Moritz 977ad92ea3 improve debug detection features (#721) 2023-03-14 19:30:12 +01:00
Willi Ballenthin 5941a484b5 add section access/map rules (#681)
* add section access/map rules

closes #4

---------

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2023-02-02 09:11:46 +01:00
Ryan Xu 74596020b8 Update Mappings for MBC (part 10) (#674)
* Update capa mappings 01/2023

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-02-01 10:09:34 +01:00
Moritz b48fcd5dd8 improve rules that often match (#655)
* improve rules that often match
2023-01-09 14:07:53 +01:00
Mike Hunhoff 96a1abddca new/update .NET rules (#625) 2022-10-07 09:39:57 -06:00
Anushka Virgaonkar 1fbee15a3c Add dotnet rules having property features (#601) 2022-10-03 09:28:05 -06:00
Moritz e88db21de4 fix: rule logic (#592)
* fix: rule logic

* fix: rule logic
2022-07-12 18:09:51 +02:00
Anushka Virgaonkar 95dc5eb27f Add new dotnet rules that capture capabilites typically found in backdoors. (#579) 2022-07-07 13:39:51 -06:00
Willi Ballenthin 57e1732f5c Revert "Revert "Merge pull request #548 from mandiant/feature-remove-flavors""
This reverts commit d43a6ee544.
2022-06-28 15:23:20 -06:00
Mike Hunhoff d4af075660 dotnet rule updates (#566) 2022-06-28 15:16:24 -06:00
William Ballenthin 2d66aace99 *: add APIs used by .NET samples for basic interactions 2022-06-08 11:18:23 -06:00
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
William Ballenthin d43a6ee544 Revert "Merge pull request #548 from mandiant/feature-remove-flavors"
This reverts commit bc28847dd9, reversing
changes made to 82308c4109.
2022-04-27 06:23:36 -06:00
Willi Ballenthin 904bf3ef00 *: remove /x32 and /x64 flavors and use instruction scope 2022-04-05 12:25:14 -06:00
Michael Hunhoff 94f1639cb4 update hijack-thread-execution.yml to match additional scenarios 2022-03-23 09:01:25 -06:00
Baptistin Boilot efea9a37d9 Fix MBC names and IDs 2022-02-06 11:13:23 +01:00
jtothej bffb8e1233 Renaming inject-shellcode-using-mapping-injection.yml 2021-12-14 10:44:32 +08:00
jtothej b70a876a26 Adding inject-shellcode-using-mapping-injection.yml 2021-12-12 16:07:58 +08:00