capa-rules
capa-rules copied to clipboard
FPs encrypt-data-using-rc4-ksa.yml
Summary
False positive on RC4 KSA rule
Examples
8333822ed41d9f2b302cf8e21b126efc:0x40646a
Possible improvements
modulo key lengthrule could be inside a basic block that is also a tight loop and also checks for0x100and/or0xFFinstead of checking against the whole function?