mandiant / mandiant/capa-rules

add coverage for process manipulation via WMI Win32_Process

Open
#471 1 comment 0 reactions 0 assignees View on GitHub
rule idea
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

> The Win32_Process WMI class represents a process on an operating system.

https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/create-method-in-class-win32-process
https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/terminate-method-in-class-win32-process

Contributor guide

Open the contributing guide

Research direction

Review the linked Microsoft documentation for the Win32_Process Create and Terminate methods. Determine how capa-rules represents process manipulation through WMI, then add coverage for those behaviors and verify that the resulting rules recognize them.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.