CapaGap demo.exe
Synthetic example File demo.exe Arch amd64 OS windows
50% observed coverage 2 / 4 comparable 1 run High input confidence

Static and dynamic capability coverage

Capability matrix across dynamic
Expand evidence Capability Namespace Statedynamic50%2 / 4 ATT&CK Priority
inject shellcode into remote processload-code/inject/processload-code/inject/processUnobservedMissingT1055high 69

Evidence for inject shellcode into remote process

Static evidence (2 locations)

Static evidence
VA / locationRVACopy
0x4040000x4000
0x4041000x4100
Image base0x400000
Matched features and rule logic

Branch states describe capa rule evaluation, not whether code executed.

Match at 0x404000

0x404000

  • Matchedor

    Synthetic alternatives for inspecting rule evidence

    • Matchedapi: kernel32.WriteProcessMemory
      0x404010 · 0x404000
    • Not matchedstring: synthetic alternative, not matched
Match at 0x404100

0x404100

  • Matchedor

    Synthetic alternatives for inspecting rule evidence

    • Matchedapi: kernel32.WriteProcessMemory
      0x404110 · 0x404100
    • Not matchedstring: synthetic alternative, not matched
ATT&CK
T1055
MBC
E1055
Static scope
function
Dynamic scope
thread
Observation by run
Observed in
None
Missing from
dynamic

Suggested follow-up

Capture child-process memory and break on the supporting allocation/write/thread APIs near the static match.

Priority and context

Scores set investigation order, not severity or probability.

  • statically present but absent from this dynamic result
  • process-injection capability
  • mapped to MITRE ATT&CK
  • mapped to MBC
  • matched at 2 static locations
  • rule supports dynamic thread scope
  • the run also observed an anti-analysis capability
create scheduled taskpersistence/scheduled-taskpersistence/scheduled-taskUnobservedMissingT1053.005high 61
check for sandbox process namesanti-analysis/anti-vm/vm-detectionanti-analysis/anti-vm/vm-detectionObservedObservedT1497.001info
communicate over HTTPcommunication/httpcommunication/httpObservedObservedT1071.001info
Run details

Run details

Coverage for the supplied dynamic result.

Run coverage and conditions
RunCoverageRuntime-onlyInput confidence
dynamic50% (2/4)1high
Evidence hotspots

Evidence hotspots

Findings at the same exact RVA. These are not inferred function boundaries or call-graph relationships.

Evidence hotspots
RVAFindingsMax priorityCapabilities
0x4000169
0x4100169
0x5000161
Input details

Input details

High input confidence describes consistency between the supplied documents. It is not a confidence score for a behavioral conclusion.

Static

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\evidence\static.json
Sample
demo.exe
capa version
9.4.0
Extractor
VivisectFeatureExtractor
Result SHA-256
6c38ace9f117747a9447a542d652032b9c98d1409fa715b636b8982ac8eb2f73
Analyzed at
2026-08-29T20:00:00Z
Invocation
capa demo.exe -j
Platform
windows / amd64 / pe

dynamic

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\evidence\dynamic.json
Sample
cape-report.json
capa version
9.4.0
Extractor
CapeExtractor
Result SHA-256
1902bc08c68e640d246aa109affb89c7ec638634aa0aee13335fcfdc7d18987e
Analyzed at
2026-08-29T20:05:00Z
Invocation
capa cape-report.json -j
Platform
windows / amd64 / pe

No ruleset manifest supplied.

Input diagnostics

Input diagnostics

No input-quality issues found.

Anti-analysis context

Anti-analysis context

  • dynamic: check for sandbox process names

These observed matches add a small priority boost to other gaps. They do not establish that any check caused the missing behavior.

Copy text

Your browser blocked automatic copying. Select and copy the text below.