Known signature string battery

signature_string_battery

Writes a set of public, inert detection-test strings (EICAR, GTUBE, Microsoft's AMSI test sample, credential-dumping command text, UTF-16 EICAR) and records which ones the scanner reacts to.

Severity low how bad it would be if it were real
Expected outcome Something should notice
Platforms 3 macOS, Linux, Windows
Isolation subprocess runs in its own process, so a kill is a measurement

What it needs before it will run

  • runs in --safe

    Observation only. It runs even in the inert mode, because it changes nothing and sends nothing.

Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.

ATT&CK techniques it exercises

MITRE ATT&CK techniques this test maps to.
Technique Name Tactic Across public reports
T1204.002 Malicious File Execution coverage statistics
T1588.001 Obtain Capabilities: Malware Resource Development coverage statistics

How often anything notices

Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.

Other detection-test strings tests

Other tests in the Detection-test strings category.
Test What it does Severity
Packaging and container evasion matrix packaging_evasion_matrix Wraps one payload (the EICAR test file) in twenty different containers and encodings — nested ZIPs from one to ten layers deep, a password-protected Z… medium
Extended signature battery signature_extended_battery Writes a wider set of public, inert detection-test material — EICAR in several encodings and document wrappers, offensive-tooling command strings, web… low

Catalogue generated from client 0.1.0. A test's behaviour can change between releases; this page describes the version named here.