CapaGap demo.exe
Synthetic example File demo.exe Arch amd64 OS windows
75% union coverage 3 / 4 comparable 2 runs High input confidence

Multi-run capability coverage

Capability matrix across baseline, interactive
Expand evidence Capability Namespace Statebaseline50%2 / 4interactive50%2 / 4 ATT&CK Priority
inject shellcode into remote processload-code/inject/processload-code/inject/processNever observedMissingMissingT1055high 69

Evidence for inject shellcode into remote process

Static evidence (2 locations)

Static evidence
VA / locationRVACopy
0x4040000x4000
0x4041000x4100
Image base0x400000
Matched features and rule logic

Branch states describe capa rule evaluation, not whether code executed.

Match at 0x404000

0x404000

  • Matchedor

    Synthetic alternatives for inspecting rule evidence

    • Matchedapi: kernel32.WriteProcessMemory
      0x404010 · 0x404000
    • Not matchedstring: synthetic alternative, not matched
Match at 0x404100

0x404100

  • Matchedor

    Synthetic alternatives for inspecting rule evidence

    • Matchedapi: kernel32.WriteProcessMemory
      0x404110 · 0x404100
    • Not matchedstring: synthetic alternative, not matched
ATT&CK
T1055
MBC
E1055
Static scope
function
Dynamic scope
thread
Observation by run
Observed in
None
Missing from
baseline, interactive

Suggested follow-up

Capture child-process memory and break on the supporting allocation/write/thread APIs near the static match.

Priority and context

Scores set investigation order, not severity or probability.

  • not observed in any of 2 dynamic runs
  • process-injection capability
  • mapped to MITRE ATT&CK
  • mapped to MBC
  • matched at 2 static locations
  • rule supports dynamic thread scope
  • the run also observed an anti-analysis capability
create scheduled taskpersistence/scheduled-taskpersistence/scheduled-taskSome runsMissingObservedT1053.005high 67
check for sandbox process namesanti-analysis/anti-vm/vm-detectionanti-analysis/anti-vm/vm-detectionSome runsObservedMissingT1497.001high 57
communicate over HTTPcommunication/httpcommunication/httpAll runsObservedObservedT1071.001info
Run contributions

Run contributions

Unique means observed in this run and no other supplied run. Baseline: baseline.

Run contributions
RunObservedUniqueUnique capabilitiesAdded vs baseline
baseline21check for sandbox process namesNone
interactive21create scheduled taskcreate scheduled task

Representative set

baseline, interactive

A deterministic greedy selection preserving the measured capability union; not a guaranteed minimum. Equivalent capability coverage does not establish equivalent behavior. Runs with no unique capabilities cannot necessarily all be removed together.

Run conditions

Run conditions

Declared inputs relative to baseline baseline. A changed setting does not establish causation.

Run coverage and conditions
RunCoverageRuntime-onlyInput confidenceDeclared conditionsChanged vs baseline
baseline50% (2/4)1highinteraction=offNone
interactive50% (2/4)1highinteraction=oninteraction
Evidence hotspots

Evidence hotspots

Findings at the same exact RVA. These are not inferred function boundaries or call-graph relationships.

Evidence hotspots
RVAFindingsMax priorityCapabilities
0x4000169
0x4100169
0x5000167
0x3000157
Input details

Input details

High input confidence describes consistency between the supplied documents. It is not a confidence score for a behavioral conclusion.

Static

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\evidence\static.json
Sample
demo.exe
capa version
9.4.0
Extractor
VivisectFeatureExtractor
Result SHA-256
6c38ace9f117747a9447a542d652032b9c98d1409fa715b636b8982ac8eb2f73
Analyzed at
2026-08-29T20:00:00Z
Invocation
capa demo.exe -j
Platform
windows / amd64 / pe

baseline

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\evidence\dynamic.json
Sample
cape-report.json
capa version
9.4.0
Extractor
CapeExtractor
Result SHA-256
1902bc08c68e640d246aa109affb89c7ec638634aa0aee13335fcfdc7d18987e
Analyzed at
2026-08-29T20:05:00Z
Invocation
capa cape-report.json -j
Platform
windows / amd64 / pe

interactive

SHA-256aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Report
examples\evidence\dynamic-interactive.json
Sample
interactive-cape-report.json
capa version
9.4.0
Extractor
CapeExtractor
Result SHA-256
777a893495557f4316f918bd52ceb665b50826070d2f18306af37f437dd114f8
Analyzed at
2026-08-29T20:15:00Z
Invocation
capa interactive-cape-report.json -j
Platform
windows / amd64 / pe

No ruleset manifest supplied.

Input diagnostics

Input diagnostics

No input-quality issues found.

Anti-analysis context

Anti-analysis context

  • baseline: check for sandbox process names

These observed matches add a small priority boost to other gaps. They do not establish that any check caused the missing behavior.

Copy text

Your browser blocked automatic copying. Select and copy the text below.