mandiant / mandiant/capa-rules
obfuscated using Obfuscator-LLVM
Open
Nobody has claimed this yet.
rule idea
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
Or similar projects, see https://github.com/obfuscator-llvm/obfuscator
This often is cumbersome to analyze and results in FP rule hits.
I haven't looked into it in detail to find good detection spots yet.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the linked Obfuscator-LLVM project and the capa-rules repository. Identify reliable detection spots for its obfuscation patterns and define rules that avoid the false-positive hits described in the issue. Done means the relevant rules are specified and their behavior is validated against suitable samples.
Written by the indexing model from the issue text.
Assessment
- Domain
- reverse-engineering, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100