capa-rules
capa-rules copied to clipboard
add example binary for compiled-with-nim.yml
https://github.com/fireeye/capa-rules/blob/7b77a66e97e780a5fa41f9cef2afabf0a9dd6200/nursery/compiled-with-nim.yml#L1-L16
suggestions:
@williballenthin
5464d5b534614b03032f9b0a9c9e6e0e on VT might be an easy example?
nimThreadVarsSize ?
nimThreadVarsSize ?
Are you suggesting this as a good string to add?
Sorry. Yes, that's right.
Hi @johnk3r! Did you find an example Nim
binary containing the string nimThreadVarsSize
that wasn't detected by the existing rule?
Hello @mike-hunhoff ,
It was just an idea. The samples I tested were detected with your rule.
@mike-hunhoff ,
Do you need help with that?
I have a sample 580c37831fe98a254eb6c61c692c70d8
that I'll upload to capa-testfiles shortly.
Thanks, @re-fox, we just need to update the example and then can upgrade this rule!
Example was added and the rule moved out of nursery.