I try to create custom signature to limit using of specific API calls for specific applications.
For example in signatures of Class "Buffer_Overflow" one of parameters what can be used is: "API_Name"
However, when I try to use "API_Name" with classes "Files" or "Program", ePO interface hang on saving.
I guess the reason is mistake in syntax.
Can someone help me?
API_Name can only be used the with Buffer Overflow class of rules. They are only ever observed when a buffer overflow happens as well. You cannot just look for a process using a specific api call (sadly).