-
Notifications
You must be signed in to change notification settings - Fork 226
Pull requests: mandiant/capa-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat(rules): detect ReadDirectoryChanges shellcode via callback and APC (#1095)
#1143
opened Mar 15, 2026 by
sherkhanz
Loading…
rules: add nursery rule for systemd CLI interaction on Linux
#1141
opened Mar 14, 2026 by
akshat4703
Loading…
rules: add nursery rule for shellcode execution via ReadDirectoryChanges
#1140
opened Mar 14, 2026 by
akshat4703
Loading…
dump-lsass-memory-via-openprocess-and-minidumpwritedump
#1138
opened Mar 13, 2026 by
akshat4703
Loading…
improve Heaven's Gate detection for computed selector variants
#1127
opened Feb 26, 2026 by
akshat4703
Loading…
persistence: restrict registry-based service detection to service-specific values (fix #1100)
#1126
opened Feb 25, 2026 by
reyyanxahmed
Loading…
add word boundaries to regex patterns to reduce false positives
#1125
opened Feb 24, 2026 by
Shaktisinhchavda
Loading…
reduce false positives in credential manager, credit-card parsing, an…
#1123
opened Feb 23, 2026 by
akshat4703
Loading…
Add new rule to detect ransomware disabling backup/recovery services
#1122
opened Feb 22, 2026 by
0ameyasr
Loading…
add word boundary to del regex to prevent false positives
#1120
opened Feb 18, 2026 by
devarjya27
Loading…
Additional rules to support capa-scripts.
dont merge
Indicate a PR that is still being worked on
#603
opened Aug 4, 2022 by
adamstorek
Loading…
ProTip!
Find all pull requests that aren't related to any open issues with -linked:issue.