mandiant / mandiant/capa-rules

disable AppInit_DLLs code signature enforcement

Open
#1,035 2 comments 0 reactions 0 assignees View on GitHub
false positive
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

I'm seeing FPs when matching _number(0)_, where the match is unrelated to the rule.

trigger: https://www.virustotal.com/gui/file/6904ff87d2604c5a3f0ed6f8328a613f8ef7f9204032438fb62c1fa7151a82b3/behavior

Contributor guide

Open the contributing guide

Research direction

Start with the linked VirusTotal behavior report and inspect the rule matching AppInit_DLLs code signature enforcement. Reproduce the false positive involving _number(0), then identify the relevant rule location; done means the unrelated match no longer triggers while the intended AppInit_DLLs detection remains covered.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.