Skip to content

update screenshot rule: add display regex and GDI+ routines#1148

Open
cipherBT wants to merge 1 commit intomandiant:masterfrom
cipherBT:fix-issue-981-capture-screenshot
Open

update screenshot rule: add display regex and GDI+ routines#1148
cipherBT wants to merge 1 commit intomandiant:masterfrom
cipherBT:fix-issue-981-capture-screenshot

Conversation

@cipherBT
Copy link

closes #981
Hi! I'm an undergraduate student actively preparing a proposal for the Automated Rule Generation GSoC 2026 project. This PR fixes the false negatives for the screenshot capability by accurately implementing @williballenthin original suggestions.

I have verified it locally and ran it against the 2f8... sandbox report to ensure the GDI+ branch fires successfully. Since this is my first time modifying existing rule architecture, I would deeply appreciate any review or feedback on the formatting!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

false negative for screenshot

1 participant