support maec/malware-family meta

This commit is contained in:
Moritz Raabe
2021-12-15 10:32:21 +01:00
parent bda76c22ec
commit 4e7f0b4591
3 changed files with 4 additions and 0 deletions

View File

@@ -9,6 +9,7 @@
- engine: optimize rule evaluation by skipping rules that can't match #830 @williballenthin
- support python 3.10 #816 @williballenthin
- support aarch64 #683
- rules: support maec/malware-family meta #841 @mr-tz
### Breaking Changes

View File

@@ -60,6 +60,8 @@ def capability_rules(doc):
continue
if rule["meta"].get("maec/analysis-conclusion-ov"):
continue
if rule["meta"].get("maec/malware-family"):
continue
if rule["meta"].get("maec/malware-category"):
continue
if rule["meta"].get("maec/malware-category-ov"):

View File

@@ -51,6 +51,7 @@ META_KEYS = (
"rule-category",
"maec/analysis-conclusion",
"maec/analysis-conclusion-ov",
"maec/malware-family",
"maec/malware-category",
"maec/malware-category-ov",
"author",