mandiant / mandiant/capa-rules
Guards for rules with multiple "formats"
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
Create a standard to guard rules with multiple formats, e.g. binary, script, and .NET.
I like the idea of `matches: xyz technology` where we expect the former to be included in all rule blocks matching `xyz` technology. We can then maintain the one`xyz technology` rule.
_Originally posted by @mike-hunhoff in https://github.com/mandiant/capa-rules/pull/601#discussion_r941582347_
Options include
- format: ...
- matches:
- ...
## Refs
- https://github.com/mandiant/capa/discussions/1106#discussioncomment-3202916
Contributor guide
Research direction
Start by reviewing the discussion linked in the issue and the referenced discussion in capa, along with the discussion from pull request #601. Compare the listed options for guarding rules with multiple formats. Done means the project has an agreed standard for expressing shared format matches, with its scope and expected rule usage documented.
Written by the indexing model from the issue text.
Assessment
- Domain
- reverse-engineering, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100