mandiant / mandiant/capa-rules
disable AppInit_DLLs code signature enforcement
Open
false positive
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
I'm seeing FPs when matching _number(0)_, where the match is unrelated to the rule.
trigger: https://www.virustotal.com/gui/file/6904ff87d2604c5a3f0ed6f8328a613f8ef7f9204032438fb62c1fa7151a82b3/behavior
Contributor guide
Research direction
Start with the linked VirusTotal behavior report and inspect the rule matching AppInit_DLLs code signature enforcement. Reproduce the false positive involving _number(0), then identify the relevant rule location; done means the unrelated match no longer triggers while the intended AppInit_DLLs detection remains covered.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100