Closed yelhamer closed 10 months ago
As mentioned by @mike-hunhoff , the rule in its current format can match if the number: 0x4 = PAGE_READWRITE feature is present in another call in the same thread. Setting the rule's dynamic scope to call helps prevent this.
number: 0x4 = PAGE_READWRITE
call
I've fixed two additional rules (allocate-memory.yml and change-memory-protection.yml) that were previously matching at thread level.
As mentioned by @mike-hunhoff , the rule in its current format can match if the
number: 0x4 = PAGE_READWRITE
feature is present in another call in the same thread. Setting the rule's dynamic scope tocall
helps prevent this.