Skip to content

Pull requests: mandiant/capa-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Sort

Pull requests list

add more APIs to remove use-process-replacement FNs
#1009 by mike-hunhoff was merged Feb 25, 2025 Loading…
Clearing Event Log with wevtapi functions
#1006 by JakePeralta7 was merged Feb 22, 2025 Loading…
Added related wevtapi functions
#1005 by JakePeralta7 was closed Feb 22, 2025 Loading…
tighten Windows mutex related rules
#1004 by mike-hunhoff was merged Feb 21, 2025 Loading…
add "change registry key timestamp"
#1003 by williballenthin was merged Feb 21, 2025 Loading…
additional APIs to remove FNs for inject apc
#1001 by mike-hunhoff was merged Feb 21, 2025 Loading…
persist via Run registry key: dynamic: thread
#995 by dhruvak001 was closed Feb 21, 2025 Loading…
remove testing rule
#989 by williballenthin was merged Feb 4, 2025 Loading…
remove redundant matches for dynamic scope
#987 by mike-hunhoff was merged Feb 4, 2025 Loading…
fix scope issues identified by new lint pass
#986 by williballenthin was merged Jan 29, 2025 Loading…
reduce fps for self-delete.yml
#985 by mike-hunhoff was merged Jan 29, 2025 Loading…
remove duplicate features from some rules
#984 by vibhatsu29 was merged Jan 28, 2025 Loading…
add dotnet limitation rule for dynamic samples
#983 by vibhatsu29 was merged Feb 4, 2025 Loading…
New rules: RSA & bigint
#982 by Ana06 was merged Jan 21, 2025 Loading…
Add CONTRIBUTING file & update ISSUE TEMPLATES
#980 by Ana06 was merged Jan 15, 2025 Loading…
use "span of calls" scope
#973 by williballenthin was merged Jan 29, 2025 Loading…
tmp: update to newscope (placeholder)
#972 by mr-tz was closed Dec 18, 2024 Loading…
extend rule features and rename
#969 by mr-tz was merged Dec 3, 2024 Loading…
enable namespace
#963 by mr-tz was merged Nov 19, 2024 Loading…
ProTip! Type g p on any issue or pull request to go back to the pull request listing page.