mandiant / mandiant/capa

CAPE traced APIs vs. rule APIs

Open
#1,843 1 comment 0 reactions 0 assignees View on GitHub
cape dynamic enhancement
Dominant language
Python
Stars
6.2k
Forks
726
Avg merge
11d 11h
Merged PRs (30d)
7

Description

...
Sidebar: We'll also have to double check which APIs (at which level, e.g. ntdll vs. kernel32) are traced and potentially update various rules.
...

_Originally posted by @mr-tz in https://github.com/mandiant/capa/issues/1815#issuecomment-1770471003_

In addition to 1. above we should 2. work with the CAPE devs to get more APIs traced.

Contributor guide

Open the contributing guide

Research direction

Start by comparing the APIs traced by CAPE with the APIs referenced by capa rules, including the stated ntdll-versus-kernel32 levels. Coordinate with the CAPE developers to identify additional APIs that should be traced, then verify that the relevant capa rules recognize the expanded coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
reverse-engineering
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.