CapaGap demo.exe
Synthetic example File demo.exe Arch amd64 OS windows
50% observed coverage 2 / 4 comparable 1 run High input confidence

Static and dynamic capability coverage

Capability matrix across dynamic
Expand evidence Capability Namespace Statedynamic50%2 / 4 ATT&CK Priority
inject shellcode into remote processload-code/inject/processload-code/inject/processUnobservedMissingT1055high 69

Evidence for inject shellcode into remote process

Static evidence (2 locations)

Static evidence
VA / locationRVACopy
0x4040000x4000
0x4041000x4100
Image base0x400000
ATT&CK
T1055
MBC
E1055
Static scope
function
Dynamic scope
thread
Observation by run
Observed in
None
Missing from
dynamic

Suggested follow-up

Capture child-process memory and break on the supporting allocation/write/thread APIs near the static match.

Priority and context

Scores set investigation order, not severity or probability.

  • statically present but absent from this dynamic result
  • process-injection capability
  • mapped to MITRE ATT&CK
  • mapped to MBC
  • matched at 2 static locations
  • rule supports dynamic thread scope
  • the run also observed an anti-analysis capability
create scheduled taskpersistence/scheduled-taskpersistence/scheduled-taskUnobservedMissingT1053.005high 61
check for sandbox process namesanti-analysis/anti-vm/vm-detectionanti-analysis/anti-vm/vm-detectionObservedObservedT1497.001info
communicate over HTTPcommunication/httpcommunication/httpObservedObservedT1071.001info
Run details

Coverage for the supplied dynamic result.

Run coverage and conditions
RunCoverageRuntime-onlyInput confidence
dynamic50% (2/4)1high
Evidence hotspots

Findings at the same exact RVA. These are not inferred function boundaries or call-graph relationships.

Evidence hotspots
RVAFindingsMax priorityCapabilities
0x4000169
0x4100169
0x5000161
Input details

High input confidence describes consistency between the supplied documents. It is not a confidence score for a behavioral conclusion.

Static

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\static.json
Sample
demo.exe
capa version
9.4.0
Extractor
VivisectFeatureExtractor
Platform
windows / amd64 / pe

dynamic

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\dynamic.json
Sample
cape-report.json
capa version
9.4.0
Extractor
CapeExtractor
Platform
windows / amd64 / pe

No ruleset manifest supplied.

Anti-analysis context
  • dynamic: check for sandbox process names

These observed matches add a small priority boost to other gaps. They do not establish that any check caused the missing behavior.

Copy text

Your browser blocked automatic copying. Select and copy the text below.