Commit Graph

45 Commits

Author SHA1 Message Date
Moritz 7c802af22f Update compiled-with-borland-delphi.yml 2022-06-23 14:29:02 +02:00
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
jtothej 9cc5be5ce4 Updated compiled-with-zig.yml - removed Windows specific logic 2022-03-22 10:44:36 +08:00
jtothej 22a7f2af3a Adding compiled-with-v.yml and compiled-with-zig.yml 2022-03-21 17:38:15 +08:00
Stephen Eckels 954f22acd8 Add golang runtime pattern (#518)
* Add golang runtime pattern

* Fix lints

* fix filename lint

* merge go rules

* Update compiler/go/compiled-with-go.yml

Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
2021-12-23 17:34:11 +01:00
Moritz Raabe 25938ca10c change to mandiant.com 2021-09-28 12:21:11 +02:00
William Ballenthin 0ef69c4fbd *: use substring features rather than unreadable regexes
closes #450
2021-08-24 12:47:26 -06:00
William Ballenthin 6a447d91a4 Merge branch 'master' of https://github.com/ruppde/capa-rules into ruppde-master 2021-08-18 14:35:54 -06:00
Willi Ballenthin 38298d876b Update compiler/go/compiled-with-go.yml 2021-08-18 14:34:20 -06:00
Moritz Raabe 413d614557 add autohotkey limitation rule 2021-06-08 14:45:43 +02:00
William Ballenthin f3a86f89c0 graduate "compiled with Nim" 2021-06-04 12:06:34 -06:00
Joshua Lee 99cafcab6f Missed T in att&ck ID 2021-06-04 16:47:13 +08:00
Arnim Rupp 1262b0f18e small fixes 2021-05-20 23:10:31 +02:00
William Ballenthin 6e501e8151 rules: convert inline comments to descriptions
closes #1
2021-05-18 10:45:41 -06:00
William Ballenthin f1b450edf0 update ATT&CK and MBC mappings
thanks to Regina Elwell @ FireEye and @evandrix
closes #316
2021-04-13 09:37:10 -06:00
Michael Hunhoff 20e1b8fd4c enforce string formatting with double quotes + escaped special characters 2021-03-24 14:14:38 -06:00
Willi Ballenthin 74f372149f exe4j: remove ATT&CK mapping 2021-03-02 08:05:42 -07:00
Willi Ballenthin 72b0e07b70 Merge pull request #277 from johnk3r/master
compiled-with-exe4j.yml
2021-02-24 16:00:01 -07:00
johnk3r e3772da804 Update compiler/exe4j/compiled-with-exe4j.yml
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
2021-02-24 19:09:06 -03:00
johnk3r 912428119d Update compiled-with-exe4j.yml 2021-02-22 18:46:50 -03:00
Willi Ballenthin ceca25cfab Merge pull request #276 from fireeye/williballenthin-patch-1
add compiled-from-visual-basic.yml
2021-02-19 10:16:58 -07:00
Willi Ballenthin cbb0a64cff formatting 2021-02-19 10:12:38 -07:00
johnk3r ba368f9015 Update compiled-with-exe4j.yml 2021-02-18 23:51:55 -03:00
johnk3r 60aac095b8 Create compiled-with-exe4j.yml
https://github.com/fireeye/capa-rules/issues/261
2021-02-18 23:48:16 -03:00
re-fox d4261f3088 Update compiled-with-dmd.yml
Updated meta
2021-02-18 15:52:37 -05:00
Willi Ballenthin be92ddec78 add compiled-from-visual-basic.yml
closes #274
2021-02-18 13:17:25 -07:00
re-fox be9d27ccf9 Update compiled-with-dmd.yml 2021-02-18 13:07:48 -05:00
re-fox 42aa681adb Create compiled-with-dmd.yml 2021-02-18 13:00:01 -05:00
re-fox 15dbc4745b Update compiled-with-borland-delphi.yml 2021-02-18 11:53:20 -05:00
Moritz Raabe 387334a603 reformated using capafmt 2021-01-27 15:30:59 +01:00
Willi Ballenthin 96f27f2559 Merge pull request #218 from fireeye/re-fox-patch-2
Create compiled-with-perl2exe.yml
2021-01-12 11:29:59 -07:00
Willi Ballenthin 5c34f70573 Merge pull request #219 from re-fox/master
Create compiled-with-ps2exe.yml
2021-01-12 11:29:34 -07:00
Willi Ballenthin d9b850824d Merge pull request #221 from itsreallynick/patch-1
Create compiled-with-pyarmor.yml
2021-01-12 11:29:16 -07:00
Willi Ballenthin d5cc23fc72 pyarmor: limit to a single example (the smaller one) 2021-01-12 11:27:44 -07:00
Nick Carr 24401d206b Update compiled-with-pyarmor.yml 2021-01-12 13:20:14 -05:00
Nick Carr b93543a902 Update compiled-with-pyarmor.yml
Updated capa rule name to match filename
2021-01-12 13:00:02 -05:00
Nick Carr f1f529b3ec Create compiled-with-pyarmor.yml
Coverage for Dashingsoft's pyarmor, as referenced in public communications from the Honorable Doctor Steven Miller of the FireEye Institute: https://twitter.com/stvemillertime/status/1349032548580483073
A basic rule to help people understand what may have obfuscated the file they are analyzing.
Fellow scientists may debate whether or not this is truly a compiler or an obfuscator belonging elsewhere in the namespace tree, but to them I say: 'ok sure I barely even know if I'm doing this right so, fine'
It may also be worth looking at https://github.com/liftoff/pyminifier and then just making a wider collection of PE obfuscator/compilers from scripting languages
2021-01-12 12:08:55 -05:00
re-fox acbea9b4ea Create compiled-with-ps2exe.yml 2021-01-08 09:52:08 -05:00
re-fox 3d92a85ce6 Create compiled-with-perl2exe.yml 2021-01-07 16:31:02 -05:00
William Ballenthin f8a3de9367 update attack mappings 2021-01-02 11:46:20 -07:00
re-fox a4a0bcb6c3 Update and rename nursery/compiled-with-go.yml to compiler/go/compiled-with-go.yml 2020-12-11 10:13:05 -05:00
re-fox f016d0b7f0 Create compiled-with-rust.yml 2020-09-18 15:44:31 -04:00
re-fox b10f212045 Create compiled-with-py2exe.yml 2020-08-31 16:48:54 -04:00
William Ballenthin 7b4f4d10fb rules: remove empty ATT&CK/MBC tags, format ATT&CK tags better 2020-06-21 17:54:01 -06:00
William Ballenthin 5f57dbdbc9 rules: reorganize rule names, namespaces, and ATT&CK mappings 2020-06-21 17:25:43 -06:00