mandiant / mandiant/capa-rules
CP Malware Evasion Encyclopedia
Open
Nobody has claimed this yet.
migrated-rule
rule idea
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
@mr-tz
We launched our new Malware Evasion Encyclopedia, which contains over 50 techniques used by various malwares to detect virtualized and sandboxed environments. We hope this effort would allow for better understanding and analysis of modern attacks.
@mr-tz
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the Check Point Malware Evasion Encyclopedia at evasions.checkpoint.com and the linked CheckPlease repository. The issue does not identify a capa-rules file, requested change, acceptance criteria, or a definition of done, so the intended contribution needs clarification before work can begin.
Written by the indexing model from the issue text.
Assessment
- Domain
- reverse-engineering, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100