Skip to content

fn: dynamic: "reference analysis tools strings" #1083

@mike-hunhoff

Description

@mike-hunhoff

We should update the dynamic scope from file to call to take advantage of detecting these strings at execution for packed samples.

rule: https://github.com/mandiant/capa-rules/blob/b0b486fe0c94cca8e75bc8ed5b3080b5c3fd432e/anti-analysis/reference-analysis-tools-strings.yml

Metadata

Metadata

Assignees

Labels

false negativerule expected to match but doesnt

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions