Skip to content

score: Reduce quality for DELIVRTO_SUSP_SVG_Foreignobject_Nov24 (Gatsby FPs)#83

Open
RuneCode14 wants to merge 1 commit intoYARAHQ:masterfrom
RuneCode14:fp-adjustments-20260401
Open

score: Reduce quality for DELIVRTO_SUSP_SVG_Foreignobject_Nov24 (Gatsby FPs)#83
RuneCode14 wants to merge 1 commit intoYARAHQ:masterfrom
RuneCode14:fp-adjustments-20260401

Conversation

@RuneCode14
Copy link
Copy Markdown
Contributor

@RuneCode14 RuneCode14 commented Apr 1, 2026

Summary

Scoring adjustment for 1 rule causing false positives on legitimate goodware.

Certutil_Decode_OR_Download was removed from this PR — fixed at source in Neo23x0/signature-base#396 with an FP exclusion string. Confirmed zero certutil FPs in today's rebuild.

Rule Adjusted

Rule FPs Quality Score Matched Files
DELIVRTO_SUSP_SVG_Foreignobject_Nov24 3 -20 60 Gatsby npm package SVG files

Verification

  • Rebuilt YARA-Forge from master after signature-base fix was merged
  • Certutil FPs: 0 (was 8) ✅
  • DelivrTo FPs: 3 (unchanged, needs scoring adjustment)
  • Total FPs: 246 (down from 253)

Generated by automated YARA-Forge daily build testing

…y FPs

Remove Certutil_Decode_OR_Download scoring adjustment — fixed at source
in Neo23x0/signature-base#396 with FP exclusion for AWS CLI docs.

Remaining adjustment: DELIVRTO_SUSP_SVG_Foreignobject_Nov24 (3 FPs on
Gatsby npm package SVG files).
@RuneCode14 RuneCode14 force-pushed the fp-adjustments-20260401 branch from 8c6a9f8 to 5e09191 Compare April 1, 2026 08:11
@RuneCode14 RuneCode14 changed the title score: Reduce quality scores for FP-prone rules (2026-04-01) score: Reduce quality for DELIVRTO_SUSP_SVG_Foreignobject_Nov24 (Gatsby FPs) Apr 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant