Skip to content

[WIP] Add detection rule for zip files disguised as jpegs - #755

Closed
Giulia Stocco (gfs) with Copilot wants to merge 1 commit into
mainfrom
copilot/add-detection-rule-zip-jpeg
Closed

Giulia Stocco (gfs) with Copilot wants to merge 1 commit into
mainfrom
copilot/add-detection-rule-zip-jpeg

Conversation

Copilot AI commented Oct 21, 2025

Copy link
Copy Markdown

Thanks for assigning this issue to me. I'm starting to work on it and will keep this PR's description up to date as I form a plan and make progress.

Original prompt

This section details on the original issue you should resolve

<issue_title>Flag Zip files that are also jpegs</issue_title>
<issue_description>What does this rule detect?

It is possible to concatenation a zip on the end of a jpeg. It will still open and parse as a jpeg and it will also be able to be unzipped. This seems like an unusual thing that might be worth reporting on.

https://ostechnix.com/hide-files-inside-images-linux/

Why should this rule be added?

Does this require the addition of a new operation to the parser?

No.

Rule Json (optional)</issue_description>

<agent_instructions>Create the new AttackSurfaceAnalyzer rule to detect this strange kind of hybrid JPEG/ZIP file. I think ti would be possible to do with the data collected by the attack surface analyzer collectors and some kind of rule behavior.</agent_instructions>

Comments on the Issue (you are Copilot in this section)

Fixes #682


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Flag Zip files that are also jpegs

2 participants