capa-rules icon indicating copy to clipboard operation
capa-rules copied to clipboard

Standard collection of rules for capa: the tool for enumerating the capabilities of programs

Results 184 capa-rules issues
Sort by recently updated
recently updated
newest added

Hi, what is the best way to create rule/rules to detect these suspicious libraries? ![2022-08-13 20_46_52-Configurações](https://user-images.githubusercontent.com/6247648/184516917-5e977afe-96e9-44e9-b449-1bcccf3695d7.png) Would it be a rule for each library? Ref.: https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-new-old-banking-trojan-brazil/

rule idea

Create a standard to guard rules with multiple formats, e.g. binary, script, and .NET. I like the idea of `matches: xyz technology` where we expect the former to be included...

see dfd6...c4e0 - number: 56 - bytes: see constant tables e.g. in https://github.com/libtom/libtomcrypt/blob/develop/src/ciphers/des.c

rule idea

I noticed that the current .NET rules missed a lot of functionality/API calls that the aspx test malware includes. I therefore modified the currently available rules and created new ones...

dont merge

link: https://github.com/yck1509/ConfuserEx/blob/master/Confuser.Runtime/antinet/AntiManagedProfiler.cs

good first issue
rule idea

https://github.com/Outbuilt/.NET-Anti-Debug

good first issue
rule idea

https://github.com/Mecanik/Anti-DebugNET

good first issue
rule idea

## Prerequisites * [x] Put an X between the brackets on this line if you have done all of the following: * Checked that your rule idea isn't already filed:...

rule idea

## Features - export: DllGetClassObject - (export: DllRegisterServer) ## Additional context https://docs.microsoft.com/en-us/windows/win32/api/combaseapi/nf-combaseapi-dllgetclassobject

rule idea