mandiant / mandiant/capa-rules

stream path rule: filename::$DATA (unnamed default data stream)

Open
#719 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

> Also, what about filename::$DATA (unnamed default data stream)?

I think we should create a separate rule for this, with a feature like `substring: ":$DATA"`

_Originally posted by @williballenthin in https://github.com/mandiant/capa-rules/pull/718#discussion_r1123073312_

Contributor guide

Open the contributing guide

Research direction

Locate the existing stream path rule and review the pull-request discussion referenced in the issue to understand how comparable rules are structured. Add a separate rule for the unnamed default data stream using the requested `substring: ":$DATA"` feature, and verify that it matches the intended filename::$DATA path.

Written by the indexing model from the issue text.

Assessment

Domain
tooling
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.