mandiant / mandiant/capa-rules

Guards for rules with multiple "formats"

Open
#605 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

Create a standard to guard rules with multiple formats, e.g. binary, script, and .NET.

I like the idea of `matches: xyz technology` where we expect the former to be included in all rule blocks matching `xyz` technology. We can then maintain the one`xyz technology` rule.

_Originally posted by @mike-hunhoff in https://github.com/mandiant/capa-rules/pull/601#discussion_r941582347_

Options include
- format: ...
- matches:
- ...

## Refs
- https://github.com/mandiant/capa/discussions/1106#discussioncomment-3202916

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the discussion linked in the issue and the referenced discussion in capa, along with the discussion from pull request #601. Compare the listed options for guarding rules with multiple formats. Done means the project has an agreed standard for expressing shared format matches, with its scope and expected rule usage documented.

Written by the indexing model from the issue text.

Assessment

Domain
reverse-engineering, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.