Skip to content

add create tcp socket via raw AFD driver#680

Merged
williballenthin merged 1 commit intomasterfrom
ntsockets
Feb 1, 2023
Merged

add create tcp socket via raw AFD driver#680
williballenthin merged 1 commit intomasterfrom
ntsockets

Conversation

@williballenthin
Copy link
Collaborator

@williballenthin williballenthin added the enhancement New feature or request label Feb 1, 2023
@williballenthin
Copy link
Collaborator Author

tbh i dont expect to match that often/ever, but its an interesting technique and a good exercise to translate into a capa rule.

Copy link
Collaborator

@mr-tz mr-tz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

neat rule indeed!

@williballenthin williballenthin merged commit a281c52 into master Feb 1, 2023
@williballenthin williballenthin deleted the ntsockets branch February 1, 2023 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

communicate directly with afd.sys to create TCP sockets

2 participants