Skip to content

[pull] master from kevoreilly:master - #545

Merged
pull[bot] merged 1 commit into
threatcode:masterfrom
kevoreilly:master
Sep 29, 2026
Merged

pull[bot] merged 1 commit into
threatcode:masterfrom
kevoreilly:master

Conversation

@pull

@pull pull Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

…egistry write tracking (#3261)

- Fix Summary.event_apicall to pass (srcfilename or filename) instead of
  srcfilename (which is None for file_read) when recording read_files and
  per-process file_activities["read_files"].
- Include NtSetValueKey, RegSetValueA, and RegSetValueW in Enhanced registry
  write API list alongside RegSetValueExA/W.
- Only emit Enhanced registry write events for RegCreateKeyExA/W when
  Disposition == 1 (REG_CREATED_NEW_KEY), ignoring Disposition == 2
  (REG_OPENED_EXISTING_KEY).
- Add unit tests in tests/test_behavior.py covering Summary read_files and
  Enhanced registry writes.
@pull pull Bot locked and limited conversation to collaborators Sep 29, 2026
@pull pull Bot added the ⤵️ pull label Sep 29, 2026
@pull
pull Bot merged commit e30f2d6 into threatcode:master Sep 29, 2026
1 check passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant