Skip to content

Add FIPS query sig and rename crypto_apis.py to cryptography.py#561

Merged
kevoreilly merged 2 commits into
CAPESandbox:masterfrom
kevross33:patch-622144
Apr 29, 2026
Merged

Add FIPS query sig and rename crypto_apis.py to cryptography.py#561
kevoreilly merged 2 commits into
CAPESandbox:masterfrom
kevross33:patch-622144

Conversation

@kevross33
Copy link
Copy Markdown
Contributor

Sample 113a05106b85844a4fcc943e5b06af75bb45c22cec1e6aa30400a13e00dcfc22 (this activity is coming from unbacked memory too)
image

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces the QueryFipsReconnaissance signature to detect and report processes probing the FIPS cryptography policy registry key. The feedback identifies a potential compatibility issue with f-strings in environments running older Python versions and suggests using the .format() method instead.

Comment thread modules/signatures/windows/cryptography.py Outdated
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@kevoreilly kevoreilly merged commit 738769f into CAPESandbox:master Apr 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants