Skip to content

Pull requests: mandiant/capa-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Add rule for LZMA decompression
#1152 opened Apr 13, 2026 by edeca Contributor Loading…
Add rule for zlib fast inflate
#1142 opened Mar 15, 2026 by priyank766 Loading…
rules: add nursery rule for systemd CLI interaction on Linux
#1141 opened Mar 14, 2026 by akshat4703 Contributor Loading…
add ProcDump-based LSASS memory dump detection
#1139 opened Mar 13, 2026 by akshat4703 Contributor Loading…
Add .NET Environment.TickCount timing anti-debug rule
#1137 opened Mar 12, 2026 by aryanyk Contributor Loading…
add general BITS usage detection
#1132 opened Mar 9, 2026 by akshat4703 Contributor Loading…
improve Heaven's Gate detection for computed selector variants
#1127 opened Feb 26, 2026 by akshat4703 Contributor Loading…
add word boundary to del regex to prevent false positives
#1120 opened Feb 18, 2026 by devarjya27 Contributor Loading…
warn if latest release and rules are not compatible
#933 opened Sep 24, 2024 by mr-tz Collaborator Loading…
Additional rules to support capa-scripts. dont merge Indicate a PR that is still being worked on
#603 opened Aug 4, 2022 by adamstorek Loading…
ProTip! Type g i on any issue or pull request to go back to the issue listing page.