William Ballenthin
682bb14b99
submodule: testfiles update
2020-07-24 15:23:34 -06:00
William Ballenthin
12cff3599a
submodule: testfiles update
2020-07-23 17:20:16 -06:00
Capa Bot
20673a3166
Sync capa-testfiles submodule
2020-07-23 17:27:15 +00:00
Capa Bot
662a750c71
Sync capa-testfiles submodule
2020-07-22 21:37:43 +00:00
William Ballenthin
baeea5b6ec
*: update license header to reference Apache 2.0
...
closes #173
2020-07-22 15:05:24 -06:00
Capa Bot
c5626b695b
Sync capa-testfiles submodule
2020-07-22 18:07:40 +00:00
Capa Bot
f383181fed
Sync capa-testfiles submodule
2020-07-17 17:34:44 +00:00
Ana María Martínez Gómez
07764fb31f
Use isort 5
...
Run `isort --profile black --length-sort --line-width 120 .`
Update documentation as well.
2020-07-16 22:02:53 +02:00
William Ballenthin
f1fa4e134a
submodule: testfiles update
2020-07-15 19:11:39 -06:00
Ana María Martínez Gómez
78dae308c2
Add test for RegExp descriptions
...
Now that RegExp are a feature, ensure that descriptions are working.
2020-07-15 22:37:38 +02:00
William Ballenthin
3faf175da7
*: add license header
...
closes #144
2020-07-15 14:14:53 -06:00
William Ballenthin
61264bc500
submodule: update
2020-07-14 09:06:59 -06:00
William Ballenthin
867de57062
main: find_capabilities: extract feature counts per item, too
...
closes #95
closes #96
2020-07-03 10:12:03 -06:00
William Ballenthin
5317e1e11e
feature extractor: null: add get_base_address()
...
closes #88
2020-07-03 09:32:37 -06:00
Michael Hunhoff
d5a8c844db
remove format changes added by black
2020-07-03 12:30:33 -06:00
Michael Hunhoff
f09e683ef5
removing stale imports
2020-07-03 12:24:17 -06:00
Moritz
6730eb1c5e
Merge pull request #83 from fireeye/fix-count-bb
...
fix #78 count bb
2020-07-03 08:55:09 +02:00
William Ballenthin
a50bd4c394
pep8
2020-07-02 15:51:08 -06:00
William Ballenthin
9ad52da6d0
add test for #78
2020-07-02 15:50:56 -06:00
Moritz Raabe
8b5f58bf31
ensure string feature values are strings, tests
2020-07-02 23:44:39 +02:00
William Ballenthin
612eefe2e8
dos2unix
2020-07-02 11:08:21 -06:00
William Ballenthin
8f7cb6dad0
pep8
2020-07-02 11:01:18 -06:00
William Ballenthin
41c32013bb
Merge branch 'master' into fmt-black
2020-07-02 11:00:14 -06:00
William Ballenthin
1188103d1c
pep8: isort
2020-07-02 10:52:05 -06:00
Moritz Raabe
c37365f045
fix render, cleanup feature string display
2020-07-02 18:48:14 +02:00
William Ballenthin
5fda3c467f
tests: fix freeze test that was broken during merge
2020-07-02 10:40:16 -06:00
William Ballenthin
c185e9ef09
pep8: black
2020-07-02 10:32:26 -06:00
William Ballenthin
db2b1caeae
Merge branch 'master' into fmt-black
2020-07-02 10:25:24 -06:00
Ana María Martínez Gómez
152129cc25
Add tests for description feature
...
Test if the parsing of feature succeeds with every time of description.
2020-07-02 16:50:28 +02:00
Ana María Martínez Gómez
64124c0b64
Remove True from Characteristic rules and output
...
Get rid of `True` in characteristic (rules, output and json) as it is
implicit. This way, the same syntax is used for characteristic as for
the rest of the features.
Co-authored-by: William Ballenthin <william.ballenthin@fireeye.com >
2020-07-02 16:50:15 +02:00
William Ballenthin
d23ef48bb6
pep8
2020-07-01 12:33:13 -06:00
William Ballenthin
9aba2eb3a5
rules: range: correct handling of range with min==0
...
closes #57
2020-06-30 00:44:22 -06:00
William Ballenthin
970977ade5
tests: demonstrate a bit more depth to namespace matching
2020-06-30 00:20:40 -06:00
William Ballenthin
e2296f0f40
Merge branch 'master' of github.com:fireeye/capa into match-namespaces
2020-06-30 00:18:44 -06:00
Moritz Raabe
5cee0d9b80
add lint negative numbers and cleanup tests
2020-06-30 22:17:42 +02:00
William Ballenthin
990c2010e9
pep8
2020-06-29 05:57:46 -06:00
William Ballenthin
3d0bd64e1b
engine, rules: support matching namespaces, not just rule names
...
closes #37
2020-06-29 05:54:56 -06:00
William Ballenthin
07daf3d46b
rule: fmt: support pulling meta from the rule instance
2020-06-21 16:57:58 -06:00
William Ballenthin
23037ad763
tests: fmt: fix expected format
2020-06-21 16:56:17 -06:00
William Ballenthin
fea1177c5e
add tests for formatting
2020-06-21 13:03:07 -06:00
Ana María Martínez Gómez
7e1e9e6618
Get rid of the Element class
...
The `Element` class is just used for testing. By using `Element` we are
not testing the actual code. Also, every time we implement a new feature
for the `Feature` class, we need to implement it for `Element` as well.
Replace `Element` by `Integer`.
2020-06-24 18:05:52 +02:00
Willi Ballenthin
53f374024b
Merge branch 'master' into doc/code-review-improvements
2020-06-24 08:22:52 -06:00
Moritz Raabe
beba3fb3c7
double to single quotes
2020-06-24 15:00:35 +02:00
Moritz Raabe
d2d1f26e7b
update documentation
2020-06-24 12:55:35 +02:00
William Ballenthin
60d7c87379
sync testfiles
2020-06-18 11:30:01 -06:00
William Ballenthin
add3537447
import source files, forgetting about 938 prior commits
2020-06-18 09:13:19 -06:00
William Ballenthin
b7bb912f46
update submodules
2020-06-17 16:15:16 -06:00
William Ballenthin
632e5b23f6
init
2020-06-17 16:08:47 -06:00