Moritz
7c802af22f
Update compiled-with-borland-delphi.yml
2022-06-23 14:29:02 +02:00
Willi Ballenthin
88c9c786ca
*: use meta.authors everywhere
2022-05-26 11:56:31 -06:00
jtothej
9cc5be5ce4
Updated compiled-with-zig.yml - removed Windows specific logic
2022-03-22 10:44:36 +08:00
jtothej
22a7f2af3a
Adding compiled-with-v.yml and compiled-with-zig.yml
2022-03-21 17:38:15 +08:00
Stephen Eckels
954f22acd8
Add golang runtime pattern ( #518 )
...
* Add golang runtime pattern
* Fix lints
* fix filename lint
* merge go rules
* Update compiler/go/compiled-with-go.yml
Co-authored-by: Moritz <mr-tz@users.noreply.github.com >
2021-12-23 17:34:11 +01:00
Moritz Raabe
25938ca10c
change to mandiant.com
2021-09-28 12:21:11 +02:00
William Ballenthin
0ef69c4fbd
*: use substring features rather than unreadable regexes
...
closes #450
2021-08-24 12:47:26 -06:00
William Ballenthin
6a447d91a4
Merge branch 'master' of https://github.com/ruppde/capa-rules into ruppde-master
2021-08-18 14:35:54 -06:00
Willi Ballenthin
38298d876b
Update compiler/go/compiled-with-go.yml
2021-08-18 14:34:20 -06:00
Moritz Raabe
413d614557
add autohotkey limitation rule
2021-06-08 14:45:43 +02:00
William Ballenthin
f3a86f89c0
graduate "compiled with Nim"
2021-06-04 12:06:34 -06:00
Joshua Lee
99cafcab6f
Missed T in att&ck ID
2021-06-04 16:47:13 +08:00
Arnim Rupp
1262b0f18e
small fixes
2021-05-20 23:10:31 +02:00
William Ballenthin
6e501e8151
rules: convert inline comments to descriptions
...
closes #1
2021-05-18 10:45:41 -06:00
William Ballenthin
f1b450edf0
update ATT&CK and MBC mappings
...
thanks to Regina Elwell @ FireEye and @evandrix
closes #316
2021-04-13 09:37:10 -06:00
Michael Hunhoff
20e1b8fd4c
enforce string formatting with double quotes + escaped special characters
2021-03-24 14:14:38 -06:00
Willi Ballenthin
74f372149f
exe4j: remove ATT&CK mapping
2021-03-02 08:05:42 -07:00
Willi Ballenthin
72b0e07b70
Merge pull request #277 from johnk3r/master
...
compiled-with-exe4j.yml
2021-02-24 16:00:01 -07:00
johnk3r
e3772da804
Update compiler/exe4j/compiled-with-exe4j.yml
...
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com >
2021-02-24 19:09:06 -03:00
johnk3r
912428119d
Update compiled-with-exe4j.yml
2021-02-22 18:46:50 -03:00
Willi Ballenthin
ceca25cfab
Merge pull request #276 from fireeye/williballenthin-patch-1
...
add compiled-from-visual-basic.yml
2021-02-19 10:16:58 -07:00
Willi Ballenthin
cbb0a64cff
formatting
2021-02-19 10:12:38 -07:00
johnk3r
ba368f9015
Update compiled-with-exe4j.yml
2021-02-18 23:51:55 -03:00
johnk3r
60aac095b8
Create compiled-with-exe4j.yml
...
https://github.com/fireeye/capa-rules/issues/261
2021-02-18 23:48:16 -03:00
re-fox
d4261f3088
Update compiled-with-dmd.yml
...
Updated meta
2021-02-18 15:52:37 -05:00
Willi Ballenthin
be92ddec78
add compiled-from-visual-basic.yml
...
closes #274
2021-02-18 13:17:25 -07:00
re-fox
be9d27ccf9
Update compiled-with-dmd.yml
2021-02-18 13:07:48 -05:00
re-fox
42aa681adb
Create compiled-with-dmd.yml
2021-02-18 13:00:01 -05:00
re-fox
15dbc4745b
Update compiled-with-borland-delphi.yml
2021-02-18 11:53:20 -05:00
Moritz Raabe
387334a603
reformated using capafmt
2021-01-27 15:30:59 +01:00
Willi Ballenthin
96f27f2559
Merge pull request #218 from fireeye/re-fox-patch-2
...
Create compiled-with-perl2exe.yml
2021-01-12 11:29:59 -07:00
Willi Ballenthin
5c34f70573
Merge pull request #219 from re-fox/master
...
Create compiled-with-ps2exe.yml
2021-01-12 11:29:34 -07:00
Willi Ballenthin
d9b850824d
Merge pull request #221 from itsreallynick/patch-1
...
Create compiled-with-pyarmor.yml
2021-01-12 11:29:16 -07:00
Willi Ballenthin
d5cc23fc72
pyarmor: limit to a single example (the smaller one)
2021-01-12 11:27:44 -07:00
Nick Carr
24401d206b
Update compiled-with-pyarmor.yml
2021-01-12 13:20:14 -05:00
Nick Carr
b93543a902
Update compiled-with-pyarmor.yml
...
Updated capa rule name to match filename
2021-01-12 13:00:02 -05:00
Nick Carr
f1f529b3ec
Create compiled-with-pyarmor.yml
...
Coverage for Dashingsoft's pyarmor, as referenced in public communications from the Honorable Doctor Steven Miller of the FireEye Institute: https://twitter.com/stvemillertime/status/1349032548580483073
A basic rule to help people understand what may have obfuscated the file they are analyzing.
Fellow scientists may debate whether or not this is truly a compiler or an obfuscator belonging elsewhere in the namespace tree, but to them I say: 'ok sure I barely even know if I'm doing this right so, fine'
It may also be worth looking at https://github.com/liftoff/pyminifier and then just making a wider collection of PE obfuscator/compilers from scripting languages
2021-01-12 12:08:55 -05:00
re-fox
acbea9b4ea
Create compiled-with-ps2exe.yml
2021-01-08 09:52:08 -05:00
re-fox
3d92a85ce6
Create compiled-with-perl2exe.yml
2021-01-07 16:31:02 -05:00
William Ballenthin
f8a3de9367
update attack mappings
2021-01-02 11:46:20 -07:00
re-fox
a4a0bcb6c3
Update and rename nursery/compiled-with-go.yml to compiler/go/compiled-with-go.yml
2020-12-11 10:13:05 -05:00
re-fox
f016d0b7f0
Create compiled-with-rust.yml
2020-09-18 15:44:31 -04:00
re-fox
b10f212045
Create compiled-with-py2exe.yml
2020-08-31 16:48:54 -04:00
William Ballenthin
7b4f4d10fb
rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better
2020-06-21 17:54:01 -06:00
William Ballenthin
5f57dbdbc9
rules: reorganize rule names, namespaces, and ATT&CK mappings
2020-06-21 17:25:43 -06:00