rule: meta: name: set application hook namespace: host-interaction/gui authors: - michael.hunhoff@mandiant.com scope: function examples: - Practical Malware Analysis Lab 12-03.exe_:0x401000 features: - and: - or: - api: user32.SetWindowsHookEx - api: user32.UnhookWindowsHookEx