mandiant / mandiant/capa-rules
stream path rule: filename::$DATA (unnamed default data stream)
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
> Also, what about filename::$DATA (unnamed default data stream)?
I think we should create a separate rule for this, with a feature like `substring: ":$DATA"`
_Originally posted by @williballenthin in https://github.com/mandiant/capa-rules/pull/718#discussion_r1123073312_
Contributor guide
Research direction
Locate the existing stream path rule and review the pull-request discussion referenced in the issue to understand how comparable rules are structured. Add a separate rule for the unnamed default data stream using the requested `substring: ":$DATA"` feature, and verify that it matches the intended filename::$DATA path.
Written by the indexing model from the issue text.
Assessment
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100