Maybe of interest for you: I extracted the ASR rules from Defender. They are written in LUA. Check the .txt files in [defender2db_data/asr_lua](https://github.com/dobin/defender2db_data/tree/main/asr_lua). [example](https://github.com/dobin/defender2db_data/blob/main/asr_lua/asr_lua_23.bin.txt)