Skip to content

add rule for detecting opening of service by ransomwares#1146

Open
cipherBT wants to merge 1 commit intomandiant:masterfrom
cipherBT:issue-1048-ransomware-sevices-detection
Open

add rule for detecting opening of service by ransomwares#1146
cipherBT wants to merge 1 commit intomandiant:masterfrom
cipherBT:issue-1048-ransomware-sevices-detection

Conversation

@cipherBT
Copy link
Copy Markdown

Resolves issue #1048. Hi, my name is Fatiu and I'm taking a look at some good first issues for GSoC 2026. This PR adds a rule to detect when a binary attempts to open/control services consistently targeted by ransomware compiled from the Netskope IOC list mentioned in the issue.
Currently, the examples section is blank as I don't have a direct sample hash hitting it. I'd appreciate any feedback. Thank you

@google-cla
Copy link
Copy Markdown

google-cla bot commented Mar 21, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@cipherBT
Copy link
Copy Markdown
Author

Hi @mike-hunhoff
I just wanted to leave a quick note to introduce myself. I'm an undergraduate student preparing a proposal for the Automated Rule Generation GSoC 2026 project, and I'm very excited to start contributing to the repository early!
This is my very first PR addressing Issue #1048. Whenever you have a free moment, could you please approve the workflow run for this PR?
Since I'm still learning the capa formatting rules, I'd love to see if the CI catches any strict syntax mistakes I made so I can quickly fix them for you.

Thanks for your time!

@mike-hunhoff
Copy link
Copy Markdown
Collaborator

@cipherBT please post a screenshot of the unit tests passing locally before we give this a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants