Detection Rule List

Rule Name Rule Type Technique Count Creation Date
CAPA_Detect_vmprotect CAPA 1 2 years, 3 months
CAPA_Detect_Petite CAPA 1 2 years, 3 months
CAPA_Detect_Themida CAPA 1 2 years, 3 months
CAPA_Detect_PeCompact CAPA 1 2 years, 3 months
CAPA_Detect_NSpack CAPA 1 2 years, 3 months
CAPA_Detect_ASPACK CAPA 1 2 years, 3 months
CAPA_Detect_UPX CAPA 1 2 years, 3 months
CAPA_Detect_QEMU CAPA 0 2 years, 3 months
CAPA_Check_SandboxProcess CAPA 1 2 years, 3 months
CAPA_Detect_FileMelt CAPA 1 2 years, 3 months
CAPA_Detect_Timestomp CAPA 1 2 years, 3 months
CAPA_FileVersion_Impersonation CAPA 1 2 years, 3 months
CAPA_check_PPID CAPA 1 2 years, 3 months
CAPA_Check_ICEBP CAPA 1 2 years, 3 months
CAPA_NtQueryInformation CAPA 1 2 years, 3 months
CAPA_Trap_Flag CAPA 1 2 years, 3 months
CAPA_Software_Breakpoint CAPA 1 2 years, 3 months
YARA_Detect_EventLogTampering YARA 1 2 years, 3 months
YARA_Detect_FindWindow YARA 1 2 years, 3 months
YARA_Detect_LocalSize YARA 1 2 years, 3 months
YARA_Detect_RDTSC YARA 1 2 years, 3 months
YARA_Detect_NtQueryInformationProcess YARA 1 2 years, 3 months
YARA_Detect_NtSetInformationThread YARA 1 2 years, 3 months
YARA_Detect_NtQueryObject YARA 1 2 years, 3 months
Yara_Detect_OutputDebugString YARA 1 2 years, 3 months
YARA_Detect_EventPairHandles YARA 1 2 years, 3 months
YARA_Detect_CsrGetProcessID YARA 1 2 years, 3 months
YARA_Detect_CloseHandle YARA 1 2 years, 3 months
Detect_EnumProcess YARA 1 2 years, 3 months
YARA_Detect_ExceptionHandler YARA 1 2 years, 3 months

Filter