Skip to content

Comments

feat(rules): New Process creation via direct syscall rule#599

Merged
rabbitstack merged 1 commit intomasterfrom
process-creation-via-direct-syscall
Feb 17, 2026
Merged

feat(rules): New Process creation via direct syscall rule#599
rabbitstack merged 1 commit intomasterfrom
process-creation-via-direct-syscall

Conversation

@rabbitstack
Copy link
Owner

What is the purpose of this PR / why it is needed?

Identifies process creation initiated via direct system call, a technique commonly used by malware to bypass user-mode API hooks and evade security monitoring.

What type of change does this PR introduce?


Uncomment one or more /kind <> lines:

/kind feature (non-breaking change which adds functionality)

/kind bug-fix (non-breaking change which fixes an issue)

/kind refactor (non-breaking change that restructures the code, while not changing the original functionality)

/kind breaking (fix or feature that would cause existing functionality to not work as expected

/kind cleanup

/kind improvement

/kind design

/kind documentation

/kind other (change that doesn't pertain to any of the above categories)

Any specific area of the project related to this PR?


Uncomment one or more /area <> lines:

/area instrumentation

/area telemetry

/area rule-engine

/area filters

/area yara

/area event

/area captures

/area alertsenders

/area outputs

/area rules

/area filaments

/area config

/area cli

/area tests

/area ci

/area build

/area docs

/area deps

/area evasion

/area other

Special notes for the reviewer


Does this PR introduce a user-facing change?


@rabbitstack rabbitstack added the rules Anything related to detection rules label Feb 6, 2026
@rabbitstack rabbitstack force-pushed the process-creation-via-direct-syscall branch from 716afaa to cbd450c Compare February 6, 2026 16:50
Identifies process creation initiated via direct system call, a technique
commonly used by malware to bypass user-mode API hooks and evade security monitoring.
@rabbitstack rabbitstack merged commit 4894a7f into master Feb 17, 2026
10 of 11 checks passed
@rabbitstack rabbitstack deleted the process-creation-via-direct-syscall branch February 17, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rules Anything related to detection rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant