Showing results for 
Search instead for 
Did you mean: 
Level 9

Custom signature for API calls


I try to create custom signature to limit using of specific API calls for specific applications.

For example in signatures of Class "Buffer_Overflow" one of parameters what can be used is: "API_Name"

However, when I try to use "API_Name" with classes "Files" or "Program", ePO interface hang on saving.

I guess the reason is mistake in syntax.

Can someone help me?


0 Kudos
1 Reply
Level 10

Re: Custom signature for API calls

API_Name can only be used the with Buffer Overflow class of rules. They are only ever observed when a buffer overflow happens as well. You cannot just look for  a process using a specific api call (sadly).

0 Kudos