Skip to content

Commit b7cf955

Browse files
committed
Rhadamanthys anti-anti detonation bypass
1 parent c27e2b3 commit b7cf955

File tree

2 files changed

+18
-2
lines changed

2 files changed

+18
-2
lines changed

analyzer/windows/data/yara/Rhadamanthys.yar

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,3 +11,14 @@ rule Rhadamanthys
1111
condition:
1212
2 of them
1313
}
14+
15+
rule RhadaAnti
16+
{
17+
meta:
18+
author = "kevoreilly"
19+
cape_options = "bp0=$anti,action0=jmp,count=0,ntdll-protect=0,dump-limit=0"
20+
strings:
21+
$anti = {74 0E FF 75 ?? 8D 45 ?? 50 E8 [4] 59 59 8D 45 ?? 50 56 68 04 01 00 00}
22+
condition:
23+
all of them
24+
}

changelog.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,16 @@
1+
### [03.11.2025]
2+
* Rhadamanthys:
3+
* static config extraction - thanks @YungBinary
4+
* anti-anti detonation bypass
5+
16
### [22.10.2025]
7+
* Add monitor injection to previously unused RESUME: monitor message handler _handle_resume()
28
* Remove obsolete 'suspended' parameter from PROCESS monitor message
39
* Monitor updates:
410
* WriteMemoryHandler: prevent analysis log spam for small PE writes
511
* Cap per-process messages to prevent detonation slow-down & failure in e.g. 9f8333d81c13ea426953b758140836cff2cf7e7f32e36738f118c6257c6efd34
612
* Experimental debugger action 'guard' to trap on guard violation
7-
* (origin/capemon, origin/HEAD) YaraHarness: write rules canary detection to analysis log
8-
* YaraHarness: simplify 'dump' option
13+
* YaraHarness: write rules canary detection to analysis log & simplify 'dump' option
914
* Deprecate Win7 wow64 breakpoint workaround
1015
* Implement Gemini suggestions from #111
1116
* Merge pull request #111 from StephanTLavavej/unordered_map

0 commit comments

Comments
 (0)