Skip to content

Add rule for PE stored as UUID#1158

Merged
mr-tz merged 6 commits into
mandiant:masterfrom
corkamig:master
May 20, 2026
Merged

Add rule for PE stored as UUID#1158
mr-tz merged 6 commits into
mandiant:masterfrom
corkamig:master

Conversation

@corkamig
Copy link
Copy Markdown
Contributor

No description provided.

Copy link
Copy Markdown
Collaborator

@mr-tz mr-tz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think a reference sample would be helpful for this rule.

Comment thread nursery/decode-pe-stored-as-uuid.yml Outdated
Comment thread nursery/decode-pe-stored-as-uuid.yml Outdated
Comment thread nursery/decode-pe-stored-as-uuid.yml Outdated
Comment thread nursery/decode-pe-stored-as-uuid.yml Outdated
@corkamig corkamig deleted the branch mandiant:master May 20, 2026 06:43
@corkamig corkamig closed this May 20, 2026
@corkamig corkamig deleted the master branch May 20, 2026 06:43
@corkamig corkamig restored the master branch May 20, 2026 06:45
@corkamig
Copy link
Copy Markdown
Contributor Author

Renaming the branch accidentally closed the PR.

@corkamig corkamig reopened this May 20, 2026
@mr-tz mr-tz merged commit 2a7f18b into mandiant:master May 20, 2026
2 checks passed
@corkamig
Copy link
Copy Markdown
Contributor Author

I prefer keeping the nops string in the first version of the rule:
they are frequent in PEs, and present in the sample.

00 and FF are extremly frequent, and 4d5a could happen randomly.
Let's test the waters and avoid unexpected FPs with a robust rule first, and adapt it and loosen it later accordingly.

@corkamig corkamig deleted the master branch May 20, 2026 07:13
@corkamig corkamig restored the master branch May 20, 2026 07:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants