mirror of
https://github.com/mandiant/capa.git
synced 2025-12-12 15:49:46 -08:00
support maec/malware-family meta
This commit is contained in:
@@ -9,6 +9,7 @@
|
||||
- engine: optimize rule evaluation by skipping rules that can't match #830 @williballenthin
|
||||
- support python 3.10 #816 @williballenthin
|
||||
- support aarch64 #683
|
||||
- rules: support maec/malware-family meta #841 @mr-tz
|
||||
|
||||
### Breaking Changes
|
||||
|
||||
|
||||
@@ -60,6 +60,8 @@ def capability_rules(doc):
|
||||
continue
|
||||
if rule["meta"].get("maec/analysis-conclusion-ov"):
|
||||
continue
|
||||
if rule["meta"].get("maec/malware-family"):
|
||||
continue
|
||||
if rule["meta"].get("maec/malware-category"):
|
||||
continue
|
||||
if rule["meta"].get("maec/malware-category-ov"):
|
||||
|
||||
@@ -51,6 +51,7 @@ META_KEYS = (
|
||||
"rule-category",
|
||||
"maec/analysis-conclusion",
|
||||
"maec/analysis-conclusion-ov",
|
||||
"maec/malware-family",
|
||||
"maec/malware-category",
|
||||
"maec/malware-category-ov",
|
||||
"author",
|
||||
|
||||
Reference in New Issue
Block a user