Releases: mandiant/capa-rules
v2.0.0
Summary
Added: 94 rules
Modified: 77 rules
Renamed: 24 rules
Deleted: 0 rules
Detailed release changes: rules v1.6.1...v2.0.0
Added rules (94)
- anti-analysis/anti-forensic/impersonate-file-version-information.yml
- anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml
- anti-analysis/packer/amber/packed-with-amber.yml
- collection/acquire-credentials-from-windows-credential-manager.yml
- collection/file-managers/gather-3d-ftp-information.yml
- collection/file-managers/gather-alftp-information.yml
- collection/file-managers/gather-bitkinex-information.yml
- collection/file-managers/gather-blazeftp-information.yml
- collection/file-managers/gather-bulletproof-ftp-information.yml
- collection/file-managers/gather-classicftp-information.yml
- collection/file-managers/gather-coreftp-information.yml
- collection/file-managers/gather-cuteftp-information.yml
- collection/file-managers/gather-cyberduck-information.yml
- collection/file-managers/gather-direct-ftp-information.yml
- collection/file-managers/gather-directory-opus-information.yml
- collection/file-managers/gather-expandrive-information.yml
- collection/file-managers/gather-faststone-browser-information.yml
- collection/file-managers/gather-fasttrack-ftp-information.yml
- collection/file-managers/gather-ffftp-information.yml
- collection/file-managers/gather-filezilla-information.yml
- collection/file-managers/gather-flashfxp-information.yml
- collection/file-managers/gather-fling-ftp-information.yml
- collection/file-managers/gather-freshftp-information.yml
- collection/file-managers/gather-frigate3-information.yml
- collection/file-managers/gather-ftp-commander-information.yml
- collection/file-managers/gather-ftp-explorer-information.yml
- collection/file-managers/gather-ftp-voyager-information.yml
- collection/file-managers/gather-ftpgetter-information.yml
- collection/file-managers/gather-ftpinfo-information.yml
- collection/file-managers/gather-ftpnow-information.yml
- collection/file-managers/gather-ftprush-information.yml
- collection/file-managers/gather-ftpshell-information.yml
- collection/file-managers/gather-global-downloader-information.yml
- collection/file-managers/gather-goftp-information.yml
- collection/file-managers/gather-leapftp-information.yml
- collection/file-managers/gather-netdrive-information.yml
- collection/file-managers/gather-nexusfile-information.yml
- collection/file-managers/gather-nova-ftp-information.yml
- collection/file-managers/gather-robo-ftp-information.yml
- collection/file-managers/gather-securefx-information.yml
- collection/file-managers/gather-smart-ftp-information.yml
- collection/file-managers/gather-softx-ftp-information.yml
- collection/file-managers/gather-southriver-webdrive-information.yml
- collection/file-managers/gather-staff-ftp-information.yml
- collection/file-managers/gather-total-commander-information.yml
- collection/file-managers/gather-turbo-ftp-information.yml
- collection/file-managers/gather-ultrafxp-information.yml
- collection/file-managers/gather-winscp-information.yml
- collection/file-managers/gather-winzip-information.yml
- collection/file-managers/gather-wise-ftp-information.yml
- collection/file-managers/gather-ws-ftp-information.yml
- collection/file-managers/gather-xftp-information.yml
- collection/get-geographical-location.yml
- collection/password-manager/steal-keepass-passwords-using-keefarce.yml
- communication/http/client/create-bits-job.yml
- compiler/autohotkey/compiled-with-autohotkey.yml
- [data-manipulation/compression/decompress-data-using-aplib.yml](https://github.com/mandiant/capa-rules/blob/v2.0.0/data-manipulation/compression/decompress-da...
v1.6.1
Summary
Added: 16 rules
Modified: 88 rules
Renamed: 3 rules
Deleted: 0 rules
Detailed release changes: rules v1.6.0...v1.6.1
Added rules (16)
- data-manipulation/encryption/rc4/encrypt-data-using-rc4-with-custom-key-via-winapi.yml
- executable/installer/iexpress/packaged-as-an-iexpress-self-extracting-archive.yml
- host-interaction/registry/create-registry-key-via-offline-registry-library.yml
- host-interaction/registry/open-registry-key-via-offline-registry-library.yml
- host-interaction/registry/query-registry-key-via-offline-registry-library.yml
- host-interaction/registry/set-registry-key-via-offline-registry-library.yml
- load-code/pe/enumerate-pe-sections.yml
- load-code/pe/inject-dll-reflectively.yml
- load-code/pe/inspect-section-memory-permissions.yml
- load-code/pe/parse-pe-exports.yml
- load-code/pe/rebuild-import-table.yml
- nursery/delete-registry-key-via-offline-registry-library.yml
- nursery/encrypt-data-using-curve25519.yml
- nursery/get-user-security-identifier.yml
- nursery/listen-for-remote-procedure-calls.yml
- nursery/query-remote-server-for-available-data.yml
Modified rules (88)
- anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml
- anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml
- anti-analysis/anti-forensic/patch-process-command-line.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml
- anti-analysis/packer/aspack/packed-with-aspack.yml
- anti-analysis/packer/confuser/packed-with-confuser.yml
- anti-analysis/packer/upack/packed-with-upack.yml
- anti-analysis/packer/vmprotect/packed-with-vmprotect.yml
- c2/shell/execute-shell-command-and-capture-output.yml
- collection/browser/gather-firefox-profile-information.yml
- collection/network/capture-network-configuration-via-ipconfig.yml
- collection/network/get-mac-address.yml
- collection/screenshot/capture-screenshot.yml
- communication/http/client/check-http-status-code.yml
- communication/named-pipe/connect/connect-pipe.yml
- communication/named-pipe/read/read-pipe.yml
- communication/named-pipe/write/write-pipe.yml
- compiler/autoit/compiled-with-autoit.yml
- compiler/delphi/compiled-with-borland-delphi.yml
- compiler/exe4j/compiled-with-exe4j.yml
- compiler/mingw/compiled-with-mingw-for-windows.yml
- compiler/perl2exe/compiled-with-perl2exe.yml
- compiler/ps2exe/compiled-with-ps2exe.yml
- compiler/py2exe/compiled-with-py2exe.yml
- compiler/pyarmor/compiled-with-pyarmor.yml
- data-manipulation/compression/compress-data-via-winapi.yml
- data-manipulation/encoding/base64/encode-data-using-base64.yml
- data-manipulation/encryption/aes/encrypt-data-using-aes-via-net.yml
- data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml
- data-manipulation/hashing/fnv/hash-data-using-fnv.yml
- data-manipulation/hashing/murmur/hash-data-using-murmur3.yml
- host-interaction/file-system/windows-file-protection/bypass-windows-file-protection.yml
- host-interaction/gui/taskbar/find/find-taskbar.yml
- host-interaction/hardware/cdrom/manipulate-cd-rom-drive.yml
- host-interaction/hardware/cpu/get-number-of-processor-cores.yml
- host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml
- host-interaction/hardware/storage/get-disk-size.yml
- [host-interaction/process/create/create-a-process-with-modified-io-handles-and-window.yml](https://github.com/mandiant/capa-rules/blob/v1.6.1/host-in...
v1.6.0
Summary
Added: 12 rules
Modified: 17 rules
Renamed: 0 rules
Deleted: 1 rule
Detailed release changes: rules v1.5.1...v1.6.0
Added rules (12)
- anti-analysis/anti-forensic/patch-process-command-line.yml
- compiler/d/compiled-with-dmd.yml
- compiler/exe4j/compiled-with-exe4j.yml
- compiler/vb/compiled-from-visual-basic.yml
- nursery/capture-screenshot-in-go.yml
- nursery/compiled-with-nim.yml
- nursery/inspect-load-icon-resource.yml
- nursery/linked-against-go-process-enumeration-library.yml
- nursery/linked-against-go-registry-library.yml
- nursery/linked-against-go-static-asset-library.yml
- nursery/linked-against-go-wmi-library.yml
- nursery/linked-against-xzip.yml
Modified rules (17)
- anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml
- anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml
- compiler/delphi/compiled-with-borland-delphi.yml
- executable/resource/extract-resource-via-kernel32-functions.yml
- host-interaction/file-system/files/list/enumerate-files-via-ntdll-functions.yml
- host-interaction/file-system/write/write-file.yml
- host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml
- host-interaction/network/dns/resolve/resolve-dns.yml
- host-interaction/os/info/get-system-information.yml
- host-interaction/process/inject/inject-apc.yml
- host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml
- host-interaction/registry/delete/delete-registry-key.yml
- host-interaction/session/get-session-integrity-level.yml
- lib/allocate-memory.yml
- lib/open-process.yml
- lib/open-thread.yml
- load-code/pe/access-pe-header.yml
Deleted rules (1)
v1.5.1
Summary
Added: 1 rule
Modified: 3 rules
Renamed: 1 rule
Deleted: 0 rules
Detailed release changes: rules v1.5.0...v1.5.1
Added rules (1)
Modified rules (3)
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml
- communication/socket/tcp/connect-tcp-socket.yml
- nursery/reference-dns-over-https-endpoints.yml
Renamed rules (1)
v1.5.0
Summary
Added: 44 rules
Modified: 170 rules
Renamed: 13 rules
Deleted: 1 rule
Detailed release changes: rules v1.4.0...v1.5.0
Added rules (44)
- anti-analysis/anti-disasm/64-bit-execution-via-heavens-gate.yml
- anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml
- anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml
- anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml
- collection/microphone/capture-microphone-audio.yml
- collection/network/capture-public-ip.yml
- collection/network/get-domain-trust-relationships.yml
- communication/http/client/check-http-status-code.yml
- compiler/perl2exe/compiled-with-perl2exe.yml
- compiler/ps2exe/compiled-with-ps2exe.yml
- compiler/pyarmor/compiled-with-pyarmor.yml
- data-manipulation/prng/generate-random-numbers-via-winapi.yml
- host-interaction/file-system/files/list/enumerate-files-recursively.yml
- host-interaction/file-system/read/read-virtual-disk.yml
- host-interaction/filter/start-minifilter-driver.yml
- host-interaction/hardware/keyboard/simulate-ctrl-alt-del.yml
- host-interaction/process/inject/hijack-thread-execution.yml
- host-interaction/process/inject/inject-dll.yml
- host-interaction/process/inject/inject-pe.yml
- host-interaction/registry/delete/delete-registry-value.yml
- host-interaction/registry/query-or-enumerate-registry-key.yml
- host-interaction/thread/resume/resume-thread.yml
- host-interaction/thread/suspend/suspend-thread.yml
- lib/allocate-memory.yml
- lib/allocate-rw-memory.yml
- lib/contain-pusha-popa-sequence.yml
- lib/create-or-open-file.yml
- lib/open-process.yml
- lib/open-thread.yml
- linking/runtime-linking/get-kernel32-base-address.yml
- linking/runtime-linking/get-ntdll-base-address.yml
- nursery/check-for-windows-sandbox-via-mutex.yml
- nursery/encrypt-or-decrypt-data-via-bcrypt.yml
- nursery/generate-random-numbers-using-the-delphi-lcg.yml
- nursery/hash-data-via-bcrypt.yml
- nursery/migrate-process-to-active-window-station.yml
- nursery/patch-process-command-line.yml
- nursery/resolve-function-by-hash.yml
- persistence/registry/winlogon-helper/persist-via-winlogon-helper-dll-registry-key.yml
- persistence/scheduled-tasks/schedule-task-via-command-line.yml
Modified rules (170)
- anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
- anti-analysis/anti-vm/vm-detection/check-for-sandbox-username.yml
- anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml
- anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml
- anti-analysis/packer/aspack/packed-with-aspack.yml
- anti-analysis/packer/generic/packed-with-generic-packer.yml
- anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml
- anti-analysis/packer/nspack/packed-with-nspack.yml
- anti-analysis/packer/pebundle/packed-with-pebundle.yml
- anti-analysis/packer/pelocknt/packed-with-pelocknt.yml
- anti-analysis/packer/peshield/packed-with-peshield.yml
- anti-analysis/packer/petite/packed-with-petite.yml
- anti-analysis/packer/rlpack/packed-with-rlpack.yml
- anti-analysis/packer/upack/packed-with-upack.yml
- [anti-analysis/pack...
v1.4.0
Summary
Added: 69 rules
Modified: 96 rules
Renamed: 0 rules
Deleted: 0 rules
Detailed release changes: rules v1.3.0...v1.4.0
Added rules (69)
- anti-analysis/anti-forensic/clear-logs/clear-the-windows-event-log.yml
- anti-analysis/anti-forensic/crash-the-windows-event-logging-service.yml
- anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml
- anti-analysis/packer/nspack/packed-with-nspack.yml
- anti-analysis/packer/pebundle/packed-with-pebundle.yml
- anti-analysis/packer/pelocknt/packed-with-pelocknt.yml
- anti-analysis/packer/peshield/packed-with-peshield.yml
- anti-analysis/packer/petite/packed-with-petite.yml
- anti-analysis/packer/rlpack/packed-with-rlpack.yml
- anti-analysis/packer/upack/packed-with-upack.yml
- anti-analysis/packer/y0da/packed-with-y0da-crypter.yml
- compiler/rust/compiled-with-rust.yml
- data-manipulation/checksum/adler32/compute-adler32-checksum.yml
- data-manipulation/encryption/hc-128/encrypt-data-using-hc-128.yml
- host-interaction/console/manipulate-console.yml
- host-interaction/gui/logon/references-logon-banner.yml
- host-interaction/process/terminate/terminate-process-via-fastfail.yml
- impact/inhibit-system-recovery/delete-volume-shadow-copies.yml
- nursery/authenticate-hmac.yml
- nursery/compiled-from-epl.yml
- nursery/compiled-with-go.yml
- nursery/create-restart-manager-session.yml
- nursery/decode-data-using-base64-via-winapi.yml
- nursery/empty-recycle-bin-quietly.yml
- nursery/enumerate-network-shares.yml
- nursery/hook-routines-via-microsoft-detours.yml
- nursery/hooked-by-api-override.yml
- nursery/impersonate-user.yml
- nursery/packaged-as-a-createinstall-installer.yml
- nursery/packaged-as-a-pintool.yml
- nursery/packaged-as-a-winzip-self-extracting-archive.yml
- nursery/packed-with-ccg.yml
- nursery/packed-with-crunch.yml
- nursery/packed-with-dragon-armor.yml
- nursery/packed-with-enigma.yml
- nursery/packed-with-epack.yml
- nursery/packed-with-maskpe.yml
- nursery/packed-with-mew.yml
- nursery/packed-with-mpress.yml
- nursery/packed-with-neolite.yml
- nursery/packed-with-pecompact.yml
- nursery/packed-with-pepack.yml
- nursery/packed-with-perplex.yml
- nursery/packed-with-procrypt.yml
- nursery/packed-with-rpcrypt.yml
- nursery/packed-with-seausfx.yml
- nursery/packed-with-shrinker.yml
- nursery/packed-with-simple-pack.yml
- nursery/packed-with-starforce.yml
- nursery/packed-with-svkp.yml
- nursery/packed-with-themida.yml
- nursery/packed-with-tsuloader.yml
- nursery/packed-with-vprotect.yml
- nursery/packed-with-wwpack.yml
- nursery/rebuilt-by-imprec.yml
- nursery/reference-114dns-dns-server.yml
- nursery/reference-alidns-dns-server.yml
- nursery/reference-cloudflare-dns-server.yml
- nursery/reference-comodo-secure-dns-server.yml
- nursery/reference-dns-over-https-endpoints.yml
- nursery/reference-google-public-dns-server.yml
- nursery/reference-hurricane-electric-dns-server.yml
- nursery/reference-kornet-dns-server.yml
- nursery/reference-l3-dns-server.yml
- nursery/reference-opendns-dns-server.yml
- nursery/reference-quad9-dns-server.yml
- nursery/reference-verisign-dns-server.yml
- nursery/run-as-service.yml
- nursery/schedule-task-via-itaskservice.yml
Modified rules (96)
- [anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml](https://github.com/mandiant/capa-rules/blob/v...
v1.3.0
Summary
Added: 4 rules
Modified: 45 rules
Renamed: 0 rules
Deleted: 0 rules
Detailed release changes: rules v1.2.0...v1.3.0
Added rules (4)
- compiler/py2exe/compiled-with-py2exe.yml
- data-manipulation/compression/decompress-data-using-quicklz.yml
- data-manipulation/encryption/sosemanuk/encrypt-data-using-sosemanuk.yml
- host-interaction/cli/resolve-path-using-msvcrt.yml
Modified rules (45)
- anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml
- anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml
- anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml
- anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml
- anti-analysis/anti-forensic/self-deletion/self-delete-via-comspec-environment-variable.yml
- anti-analysis/anti-forensic/timestomp/timestomp-file.yml
- anti-analysis/anti-vm/vm-detection/check-for-sandbox-username.yml
- anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml
- anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml
- anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml
- anti-analysis/packer/aspack/packed-with-aspack.yml
- anti-analysis/packer/confuser/packed-with-confuser.yml
- anti-analysis/packer/generic/packed-with-generic-packer.yml
- anti-analysis/packer/upx/packed-with-upx.yml
- anti-analysis/packer/vmprotect/packed-with-vmprotect.yml
- anti-analysis/reference-analysis-tools-strings.yml
- data-manipulation/encryption/des/encrypt-data-using-des.yml
- data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml
- data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml
- data-manipulation/hashing/murmur/hash-data-using-murmur3.yml
- data-manipulation/hashing/tiger/hash-data-using-tiger.yml
- host-interaction/environment-variable/query-environment-variable.yml
- host-interaction/network/dns/resolve/resolve-dns.yml
- lib/validate-credit-card-number-using-luhn-algorithm-with-lookup-table.yml
- lib/validate-credit-card-number-using-luhn-algorithm-with-no-lookup-table.yml
- [nursery/hide-thread-from-debugger.yml](https://github.com/mandiant/capa-rules/blob/v1.3.0/nursery/...
v1.2.0
Summary
Added: 48 rules
Modified: 12 rules
Renamed: 2 rules
Deleted: 0 rules
Detailed release changes: rules v1.1.0...v1.2.0
Added rules (48)
- anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml
- anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml
- anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml
- anti-analysis/anti-vm/vm-detection/check-for-sandbox-username.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml
- anti-analysis/packer/aspack/packed-with-aspack.yml
- anti-analysis/reference-analysis-tools-strings.yml
- collection/database/wmi/reference-wmi-statements.yml
- communication/icmp/send-icmp-echo-request.yml
- data-manipulation/checksum/luhn/validate-credit-card-number-using-luhn-algorithm.yml
- data-manipulation/encryption/rsa/reference-public-rsa-key.yml
- host-interaction/hardware/cpu/get-number-of-processor-cores.yml
- host-interaction/hardware/cpu/get-number-of-processors.yml
- host-interaction/hardware/storage/enumerate-disk-properties.yml
- host-interaction/hardware/storage/get-disk-size.yml
- host-interaction/process/get-process-heap-flags.yml
- host-interaction/process/get-process-heap-force-flags.yml
- host-interaction/process/list/get-explorer-pid.yml
- host-interaction/uac/bypass/bypass-uac-via-appinfo-alpc.yml
- host-interaction/uac/bypass/bypass-uac-via-token-manipulation.yml
- lib/delay-execution.yml
- lib/peb-access.yml
- lib/validate-credit-card-number-using-luhn-algorithm-with-no-lookup-table.yml
- linking/runtime-linking/link-many-functions-at-runtime.yml
- nursery/check-for-process-debug-object.yml
- nursery/check-license-value.yml
- nursery/check-processdebugflags.yml
- nursery/check-processdebugport.yml
- nursery/check-systemkerneldebuggerinformation.yml
- nursery/check-thread-yield-allowed.yml
- nursery/delete-internet-cache.yml
- nursery/enumerate-internet-cache.yml
- nursery/enumerate-system-firmware-tables.yml
- nursery/get-system-firmware-table.yml
- nursery/hash-data-using-fnv.yml
- nursery/hide-thread-from-debugger.yml
Modified rules (12)
- anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml
- data-manipulation/compression/decompress-data-via-iencodingfilterfactory.yml
- data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml
- data-manipulation/encryption/rc4/encrypt-data-using-rc4-ksa.yml
- [data-manipulation/encryption/rc4/encry...
v1.1.0
Summary
Added: 33 rules
Modified: 11 rules
Renamed: 9 rules
Deleted: 1 rule
Detailed release changes: rules v1.0.0...v1.1.0
Added rules (33)
- anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml
- collection/browser/gather-firefox-profile-information.yml
- collection/credit-card/parse-credit-card-information.yml
- collection/network/capture-network-configuration-via-ipconfig.yml
- data-manipulation/checksum/luhn/validate-credit-card-number-with-luhn-algorithm.yml
- data-manipulation/encryption/blowfish/encrypt-data-using-blowfish.yml
- data-manipulation/encryption/camellia/encrypt-data-using-camellia.yml
- data-manipulation/encryption/des/encrypt-data-using-des-via-winapi.yml
- data-manipulation/encryption/des/encrypt-data-using-des.yml
- data-manipulation/encryption/import-public-key.yml
- data-manipulation/encryption/skipjack/encrypt-data-using-skipjack.yml
- data-manipulation/encryption/twofish/encrypt-data-using-twofish.yml
- data-manipulation/hashing/hash-data-via-wincrypt.yml
- data-manipulation/hashing/tiger/hash-data-using-tiger.yml
- host-interaction/file-system/meta/get-file-attributes.yml
- host-interaction/file-system/read/read-ini-file.yml
- host-interaction/gui/session/wallpaper/change-the-wallpaper.yml
- host-interaction/gui/window/hide/hide-graphical-window.yml
- host-interaction/mutex/check-mutex-and-exit.yml
- host-interaction/process/allocate-thread-local-storage.yml
- host-interaction/process/list/enumerate-processes-via-ntquerysysteminformation.yml
- host-interaction/process/set-thread-local-storage-value.yml
- host-interaction/session/get-session-integrity-level.yml
- nursery/acquire-debug-privileges.yml
- nursery/add-file-to-cabinet-file.yml
- nursery/flush-cabinet-file.yml
- nursery/get-socket-information.yml
- nursery/get-thread-local-storage-value.yml
- nursery/hash-data-using-sha1-via-x86-extensions.yml
- nursery/hash-data-using-sha256-via-x86-extensions.yml
- nursery/open-cabinet-file.yml
- nursery/set-graphical-window-text.yml
- nursery/terminate-process-by-name.yml
Modified rules (11)
- collection/screenshot/capture-screenshot.yml
- communication/http/client/read-data-from-internet.yml
- communication/tcp/serve/start-tcp-server.yml
- data-manipulation/encryption/encrypt-or-decrypt-via-wincrypt.yml
- host-interaction/file-system/copy/copy-file.yml
- host-interaction/gui/taskbar/hide/hide-the-windows-taskbar.yml
- host-interaction/process/terminate/terminate-process.yml
- host-interaction/service/list/enumerate-services.yml
- host-interaction/service/modify/modify-service.yml
- nursery/get-file-version-info.yml
- nursery/read-process-memory.yml
Renamed rules (9)
- data-manipulation/encryption/aes/encrypt-data-using-aes-via-net.yml (was data-manipulation/encryption/aes/encrypt-data-using-aes-via-.net.yml)
- data-manipulation/hashing/murmur/hash-data-using-murmur3.yml (was nursery/hash-data-using-murmur3.yml)
- executable/pe/section/rsrc/contain-a-resource-rsrc-section.yml (was executable/pe/section/rsrc/contain-a-resource-.rsrc-section.yml)
- executable/pe/section/tls/contain-a-thread-local-storage-tls-section.yml (was executable/pe/section/tls/contain-a-thread-local-storage-.tls-section.yml)
- nursery/get-mac-address.yml (was host-interaction/network/mac-address/get-mac-address.yml)
- nursery/reference-processor-manufacturer-constants.yml (was anti-analysis/anti-vm/vm-detection/reference-processor-manufacturer-constants.yml)
- nursery/set-global-application-hook.yml (was host-interaction/gui/set-global-application-hook.yml)
- [persistence/startup-folder/get-st...
v1.0.0
Summary
Added: 261 rules
Modified: 0 rules
Renamed: 0 rules
Deleted: 0 rules
Detailed release changes: rules 77124b5...v1.0.0
Added rules (261)
- anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml
- anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml
- anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml
- anti-analysis/anti-forensic/self-deletion/self-delete-via-comspec-environment-variable.yml
- anti-analysis/anti-forensic/timestomp/timestomp-file.yml
- anti-analysis/anti-vm/vm-detection/execute-anti-vm-instructions.yml
- anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml
- anti-analysis/anti-vm/vm-detection/reference-processor-manufacturer-constants.yml
- anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml
- anti-analysis/packer/confuser/packed-with-confuser.yml
- anti-analysis/packer/generic/packed-with-generic-packer.yml
- anti-analysis/packer/upx/packed-with-upx.yml
- anti-analysis/packer/vmprotect/packed-with-vmprotect.yml
- c2/file-transfer/download-and-write-a-file.yml
- c2/file-transfer/write-and-execute-a-file.yml
- c2/shell/create-reverse-shell.yml
- c2/shell/execute-shell-command-and-capture-output.yml
- collection/database/sql/reference-sql-statements.yml
- collection/keylog/log-keystrokes-via-application-hook.yml
- collection/keylog/log-keystrokes-via-polling.yml
- collection/keylog/log-keystrokes.yml
- collection/screenshot/capture-screenshot.yml
- communication/ftp/send/send-file-using-ftp-via-wininet.yml
- communication/http/client/connect-to-http-server.yml
- communication/http/client/connect-to-url.yml
- communication/http/client/create-http-request.yml
- communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml
- communication/http/client/download-url-to-file.yml
- communication/http/client/extract-http-body.yml
- communication/http/client/get-http-document-via-iwebbrowser2.yml
- communication/http/client/get-http-response-content-encoding.yml
- communication/http/client/prepare-http-request.yml
- communication/http/client/read-data-from-internet.yml
- communication/http/client/receive-http-response.yml
- communication/http/client/send-file-via-http.yml
- communication/http/client/send-http-request.yml
- communication/http/initialize-iwebbrowser2.yml
- communication/http/initialize-winhttp-library.yml
- communication/http/read-http-header.yml
- communication/http/server/receive-http-request.yml
- communication/http/server/send-http-response.yml
- communication/http/server/start-http-server.yml
- communication/http/set-http-header.yml
- communication/named-pipe/connect/connect-pipe.yml
- communication/named-pipe/create/create-pipe.yml
- communication/named-pipe/create/create-two-anonymous-pipes.yml
- communication/named-pipe/read/read-pipe.yml
- communication/named-pipe/write/write-pipe.yml
- communication/receive-data.yml
- communication/send-data.yml
- communication/socket/get-socket-status.yml
- communication/socket/initialize-winsock-library.yml
- communication/socket/receive/receive-data-on-socket.yml
- communication/socket/send/send-data-on-socket.yml
- [communication/socket/set-socket-configuration.yml](https://github.com/mandiant/capa-rules/blob/v1.0.0/communication/socket/set-socket...