mandiant / mandiant/capa-rules
check heap flags
Open
rule idea
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
we have rules for fetching the heap flags, but not how they are interpreted.
here's a reference: https://www.reverseengineering.app/en/techniques/heap-flags
5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a:0x1400016FB does this:
Contributor guide
Research direction
Start by locating the existing rules that fetch heap flags, then read the linked heap-flags reference to understand their interpretation. Compare the behavior shown for 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a:0x1400016FB; done means rules cover the relevant heap-flag meanings and recognize that sample.
Written by the indexing model from the issue text.
Assessment
- Domain
- reverse-engineering
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100