Run details
Coverage for the supplied dynamic result.
| Run | Coverage | Runtime-only | Input confidence |
|---|---|---|---|
| dynamic | 50% (2/4) | 1 | high |
| Expand evidence | Capability | Namespace | State | dynamic50%2 / 4 | ATT&CK | Priority | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| inject shellcode into remote processload-code/inject/process | load-code/inject/process | Unobserved | Missing | T1055 | high 69 | |||||||||||||
Evidence for inject shellcode into remote processStatic evidence (2 locations)
Image base 0x400000Matched features and rule logicBranch states describe capa rule evaluation, not whether code executed. Match at | ||||||||||||||||||
| create scheduled taskpersistence/scheduled-task | persistence/scheduled-task | Unobserved | Missing | T1053.005 | high 61 | |||||||||||||
Evidence for create scheduled taskStatic evidence (1 location)
Image base 0x400000Matched features and rule logicBranch states describe capa rule evaluation, not whether code executed. Match at | ||||||||||||||||||
| check for sandbox process namesanti-analysis/anti-vm/vm-detection | anti-analysis/anti-vm/vm-detection | Observed | Observed | T1497.001 | info | |||||||||||||
Evidence for check for sandbox process namesStatic evidence (1 location)
Image base 0x400000Matched features and rule logicBranch states describe capa rule evaluation, not whether code executed. Match at | ||||||||||||||||||
| Location | Address type | Copy |
|---|---|---|
ppid:4/pid:1001/tid:2000 | thread |
Branch states describe capa rule evaluation, not whether code executed.
ppid:4/pid:1001/tid:2000demo.exe · ppid:4/pid:1001/tid:2000
orSynthetic alternatives for inspecting rule evidence
api: kernel32.Process32FirstWppid:4/pid:1001/tid:2000/call:1 · demo.exe · ppid:4/pid:1001/tid:2000 · Process32FirstW(synthetic arguments)string: synthetic alternative, not matchedT1497.001B0009This capability was observed in every supplied dynamic result.
T1071.001| VA / location | RVA | Copy |
|---|---|---|
0x402000 | 0x2000 |
0x400000Branch states describe capa rule evaluation, not whether code executed.
0x4020000x402000
orSynthetic alternatives for inspecting rule evidence
api: wininet.HttpSendRequestA0x402010 · 0x402000string: synthetic alternative, not matched| Location | Address type | Copy |
|---|---|---|
ppid:4/pid:1000/tid:2000 | thread |
Branch states describe capa rule evaluation, not whether code executed.
ppid:4/pid:1000/tid:2000demo.exe · ppid:4/pid:1000/tid:2000
orSynthetic alternatives for inspecting rule evidence
api: wininet.HttpSendRequestAppid:4/pid:1000/tid:2000/call:1 · demo.exe · ppid:4/pid:1000/tid:2000 · HttpSendRequestA(synthetic arguments)string: synthetic alternative, not matchedT1071.001C0002This capability was observed in every supplied dynamic result.
T1059.003| Location | Address type | Copy |
|---|---|---|
ppid:4/pid:1002/tid:2000 | thread |
Branch states describe capa rule evaluation, not whether code executed.
ppid:4/pid:1002/tid:2000demo.exe · ppid:4/pid:1002/tid:2000
orSynthetic alternatives for inspecting rule evidence
api: kernel32.CreateProcessWppid:4/pid:1002/tid:2000/call:1 · demo.exe · ppid:4/pid:1002/tid:2000 · CreateProcessW(synthetic arguments)string: synthetic alternative, not matchedT1059.003Not mappedThis capability appears only in dynamic results. Runtime resolution, unpacking, or extractor differences may explain the additional match.
—| VA / location | RVA | Copy |
|---|---|---|
0x406000 | 0x6000 |
0x400000Branch states describe capa rule evaluation, not whether code executed.
0x4060000x406000
orSynthetic alternatives for inspecting rule evidence
api: advapi32.CryptEncrypt0x406010 · 0x406000string: synthetic alternative, not matchedNot mappedC0027This capability is excluded from the coverage denominator. The rule does not declare a supported dynamic scope.
Check the runtime-only and excluded views for other matches.
Coverage for the supplied dynamic result.
| Run | Coverage | Runtime-only | Input confidence |
|---|---|---|---|
| dynamic | 50% (2/4) | 1 | high |
Findings at the same exact RVA. These are not inferred function boundaries or call-graph relationships.
| RVA | Findings | Max priority | Capabilities |
|---|---|---|---|
0x4000 | 1 | 69 | inject shellcode into remote process |
0x4100 | 1 | 69 | inject shellcode into remote process |
0x5000 | 1 | 61 | create scheduled task |
High input confidence describes consistency between the supplied documents. It is not a confidence score for a behavioral conclusion.
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaexamples\evidence\static.jsondemo.exe6c38ace9f117747a9447a542d652032b9c98d1409fa715b636b8982ac8eb2f73capa demo.exe -jaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaexamples\evidence\dynamic.jsoncape-report.json1902bc08c68e640d246aa109affb89c7ec638634aa0aee13335fcfdc7d18987ecapa cape-report.json -jNo ruleset manifest supplied.
No input-quality issues found.
These observed matches add a small priority boost to other gaps. They do not establish that any check caused the missing behavior.