capa-rules
capa-rules copied to clipboard
parse-credit-card-information -> mimikatz.exe_:0x444E02
parse-credit-card-information match reported for mimikatz.exe_:0x444E02
I've noticed FPs for this rule for other internal binaries as well. The character checks detected by this rule (=
, ?
, etc.) are also found in common processing for things like URIs, etc..