Coverage for the supplied dynamic result.
| Run | Coverage | Runtime-only | Input confidence |
|---|---|---|---|
| dynamic | 50% (2/4) | 1 | high |
| Expand evidence | Capability | Namespace | State | dynamic50%2 / 4 | ATT&CK | Priority | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| inject shellcode into remote processload-code/inject/process | load-code/inject/process | Unobserved | Missing | T1055 | high 69 | ||||||||||
Evidence for inject shellcode into remote processStatic evidence (2 locations)
Image base 0x400000
Observation by run
Suggested follow-upCapture child-process memory and break on the supporting allocation/write/thread APIs near the static match. Priority and contextScores set investigation order, not severity or probability.
| |||||||||||||||
| create scheduled taskpersistence/scheduled-task | persistence/scheduled-task | Unobserved | Missing | T1053.005 | high 61 | ||||||||||
Evidence for create scheduled taskStatic evidence (1 location)
Image base 0x400000
Observation by run
Suggested follow-upRepeat with the required privilege and longer runtime; inspect registry, service, task, and startup artifacts. Priority and contextScores set investigation order, not severity or probability.
| |||||||||||||||
| check for sandbox process namesanti-analysis/anti-vm/vm-detection | anti-analysis/anti-vm/vm-detection | Observed | Observed | T1497.001 | info | ||||||||||
Evidence for check for sandbox process namesStatic evidence (1 location)
Image base 0x400000
Observation by run
ObservationThis capability was observed in every supplied dynamic result. | |||||||||||||||
| communicate over HTTPcommunication/http | communication/http | Observed | Observed | T1071.001 | info | ||||||||||
Evidence for communicate over HTTPStatic evidence (1 location)
Image base 0x400000
Observation by run
ObservationThis capability was observed in every supplied dynamic result. | |||||||||||||||
| execute shell commandload-code/execute | load-code/execute | Runtime-only | Observed | T1059.003 | info | ||||||||||
Evidence for execute shell commanddynamic evidence (1 location)
Observation by run
Runtime observationThis capability appears only in dynamic results. Runtime resolution, unpacking, or extractor differences may explain the additional match. | |||||||||||||||
| encrypt data using AESdata-manipulation/encryption/aes | data-manipulation/encryption/aes | Static-only | Not comparable | — | info | ||||||||||
Evidence for encrypt data using AESStatic evidence (1 location)
Image base 0x400000
Coverage boundaryThis capability is excluded from the coverage denominator. The rule does not declare a supported dynamic scope. | |||||||||||||||
Check the runtime-only and excluded views for other matches.
Coverage for the supplied dynamic result.
| Run | Coverage | Runtime-only | Input confidence |
|---|---|---|---|
| dynamic | 50% (2/4) | 1 | high |
Findings at the same exact RVA. These are not inferred function boundaries or call-graph relationships.
| RVA | Findings | Max priority | Capabilities |
|---|---|---|---|
0x4000 | 1 | 69 | inject shellcode into remote process |
0x4100 | 1 | 69 | inject shellcode into remote process |
0x5000 | 1 | 61 | create scheduled task |
High input confidence describes consistency between the supplied documents. It is not a confidence score for a behavioral conclusion.
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaexamples\static.jsondemo.exeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaexamples\dynamic.jsoncape-report.jsonNo ruleset manifest supplied.
These observed matches add a small priority boost to other gaps. They do not establish that any check caused the missing behavior.