Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add capa rules create-thread-bypass-freeze.yml and check-thread-suspend-count-exceeded.yml to nursery. #912

Merged
merged 4 commits into from
Sep 16, 2024

Conversation

ejfocampo
Copy link
Contributor

Adding two capa rules - create-thread-bypass-freeze.yml and check-thread-suspend-count-exceeded.yml to the nursery. I did not find any public malware sample exhibiting the technique but I did test it with a basic POC code I created based on the referenced articles.

Copy link
Collaborator

@williballenthin williballenthin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

see two inline suggestions, then lets merge!

ejfocampo and others added 3 commits July 18, 2024 00:59
Co-authored-by: Willi Ballenthin <wballenthin@google.com>
Co-authored-by: Willi Ballenthin <wballenthin@google.com>
@ejfocampo
Copy link
Contributor Author

Inline suggestions applied and file renamed to create-thread-bypassing-process-freeze.yml

Copy link
Collaborator

@mr-tz mr-tz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@mr-tz mr-tz merged commit 534ee22 into mandiant:master Sep 16, 2024
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants