Detection Rule List

Rule Name Rule Type Technique Count Creation Date
CAPA_Detect_QEMU CAPA 0 1 year, 8 months
CAPA_Check_SandboxProcess CAPA 1 1 year, 8 months
CAPA_Detect_FileMelt CAPA 1 1 year, 8 months
CAPA_Detect_Timestomp CAPA 1 1 year, 8 months
CAPA_FileVersion_Impersonation CAPA 1 1 year, 8 months
CAPA_check_PPID CAPA 1 1 year, 8 months
CAPA_Check_ICEBP CAPA 1 1 year, 8 months
CAPA_NtQueryInformation CAPA 1 1 year, 8 months
CAPA_Trap_Flag CAPA 1 1 year, 8 months
CAPA_Software_Breakpoint CAPA 1 1 year, 8 months
YARA_Detect_EventLogTampering YARA 1 1 year, 8 months
YARA_Detect_FindWindow YARA 1 1 year, 8 months
YARA_Detect_LocalSize YARA 1 1 year, 8 months
YARA_Detect_RDTSC YARA 1 1 year, 8 months
YARA_Detect_NtQueryInformationProcess YARA 1 1 year, 8 months
YARA_Detect_NtSetInformationThread YARA 1 1 year, 8 months
YARA_Detect_NtQueryObject YARA 1 1 year, 8 months
Yara_Detect_OutputDebugString YARA 1 1 year, 8 months
YARA_Detect_EventPairHandles YARA 1 1 year, 8 months
YARA_Detect_CsrGetProcessID YARA 1 1 year, 8 months
YARA_Detect_CloseHandle YARA 1 1 year, 8 months
Detect_EnumProcess YARA 1 1 year, 8 months
YARA_Detect_ExceptionHandler YARA 1 1 year, 8 months
Detect_Interrupts YARA 3 1 year, 8 months
Detect_OllyDbg_BadFormat_Trick YARA 1 1 year, 8 months
YARA_Detect_GuardPages YARA 1 1 year, 8 months
YARA_Detect_IsDebuggerPresent YARA 1 1 year, 8 months
YARA_Detect_SetDebugFilterState YARA 1 1 year, 8 months
YARA_Detect_SuspendThread YARA 1 1 year, 8 months
YARA_SHADOW_COPY_DELETION YARA 1 1 year, 8 months

Filter