capa-rules
capa-rules copied to clipboard
Create and open section
NtCreateSection, ZwCreateSection, NtOpenSection, ZwOpenSection
- https://ired.team/offensive-security/code-injection-process-injection/ntcreatesection-+-ntmapviewofsection-code-injection
- https://www.cyberbit.com/blog/endpoint-security/malware-mitigation-when-direct-system-calls-are-used/
Please let me help you with that.