rule UPX_Packed { meta: description = "Detects UPX packed executable" severity = "medium" strings: $upx1 = "UPX0" ascii $upx2 = "UPX1" ascii $upx3 = "UPX!" ascii condition: any of them } rule Suspicious_Process_Injection { meta: description = "Detects process injection techniques" severity = "high" strings: $s1 = "VirtualAllocEx" ascii nocase $s2 = "WriteProcessMemory" ascii nocase $s3 = "CreateRemoteThread" ascii nocase condition: 2 of them } rule Keylogger_Indicators { meta: description = "Detects potential keylogger behavior" severity = "high" strings: $s1 = "SetWindowsHookEx" ascii nocase $s2 = "GetAsyncKeyState" ascii nocase $s3 = "keybd_event" ascii nocase condition: any of them } rule Ransomware_Indicators { meta: description = "Detects potential ransomware behavior" severity = "high" strings: $s1 = "CryptEncrypt" ascii nocase $s2 = "CryptDecrypt" ascii nocase $s3 = "vssadmin delete shadows" ascii nocase $s4 = "bcdedit /set" ascii nocase condition: any of them } rule Embedded_Executable { meta: description = "Detects embedded executable (dropper)" severity = "high" strings: $mz = { 4D 5A } condition: #mz > 1 } rule Network_Downloader { meta: description = "Detects network download capabilities" severity = "medium" strings: $s1 = "URLDownloadToFile" ascii nocase $s2 = "InternetOpen" ascii nocase $s3 = "HttpSendRequest" ascii nocase $s4 = "WinHttpOpen" ascii nocase condition: 2 of them } rule Anti_Debug { meta: description = "Detects anti-debugging techniques" severity = "medium" strings: $s1 = "IsDebuggerPresent" ascii nocase $s2 = "CheckRemoteDebuggerPresent" ascii nocase $s3 = "NtQueryInformationProcess" ascii nocase condition: any of them } rule Suspicious_Registry { meta: description = "Detects suspicious registry operations" severity = "medium" strings: $s1 = "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run" ascii nocase $s2 = "RegSetValueEx" ascii nocase condition: all of them }