mandiant / mandiant/capa-rules

check heap flags

Open
#1,187 0 comments 0 reactions 0 assignees View on GitHub
rule idea
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

we have rules for fetching the heap flags, but not how they are interpreted.

here's a reference: https://www.reverseengineering.app/en/techniques/heap-flags

Image

5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a:0x1400016FB does this:

Image

Contributor guide

Open the contributing guide

Research direction

Start by locating the existing rules that fetch heap flags, then read the linked heap-flags reference to understand their interpretation. Compare the behavior shown for 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a:0x1400016FB; done means rules cover the relevant heap-flag meanings and recognize that sample.

Written by the indexing model from the issue text.

Assessment

Domain
reverse-engineering
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.