Willi Ballenthin
|
2989af0a3f
|
features: use ABC to denote abstract classes
|
2022-04-04 11:49:51 -06:00 |
|
Willi Ballenthin
|
85b1d50945
|
isort
|
2022-03-31 10:40:48 -06:00 |
|
Willi Ballenthin
|
856443319c
|
viv: insn: fix OperandNumber reference
|
2022-03-31 10:39:18 -06:00 |
|
Willi Ballenthin
|
9da4ff10da
|
*: rename OperandImmediate to OperandNumber
|
2022-03-31 10:37:06 -06:00 |
|
Willi Ballenthin
|
76831e9b9d
|
changelog
|
2022-03-30 13:20:51 -06:00 |
|
Willi Ballenthin
|
997daf537e
|
viv: insn: extract OperandOffset and OperandImmediate
|
2022-03-30 13:14:08 -06:00 |
|
Willi Ballenthin
|
c7aadca25c
|
tests: demonstrate OperandOffset and OperandImmediate
|
2022-03-30 13:13:50 -06:00 |
|
Willi Ballenthin
|
6cbbd4d97f
|
rules: parse OperandOffset and OperandImmediate features
|
2022-03-30 13:13:30 -06:00 |
|
Willi Ballenthin
|
e4c5ec278d
|
features: insn: define OperandImmediate and OperandOffset
|
2022-03-30 13:13:07 -06:00 |
|
Willi Ballenthin
|
cce1e41519
|
formatting
|
2022-03-30 13:12:49 -06:00 |
|
Willi Ballenthin
|
b942050c4e
|
features: viv: factor out operand feature extraction
|
2022-03-30 09:58:08 -06:00 |
|
Willi Ballenthin
|
d8d671e36f
|
rules: add global scope features to file scope
|
2022-03-30 09:40:43 -06:00 |
|
Willi Ballenthin
|
49adb8de0c
|
pep8
|
2022-03-29 13:00:28 -06:00 |
|
Willi Ballenthin
|
fb6b60bee3
|
tests: add tests demonstrating instruction (sub)scope matching
|
2022-03-29 12:58:38 -06:00 |
|
Willi Ballenthin
|
e0fca277f2
|
rules: update valid features per scope
|
2022-03-29 12:58:27 -06:00 |
|
Willi Ballenthin
|
0effb5f8b0
|
changelog
|
2022-03-29 12:33:55 -06:00 |
|
Willi Ballenthin
|
1839746bf8
|
main: factor out matching at instruction scope
|
2022-03-29 12:29:54 -06:00 |
|
Willi Ballenthin
|
1a28c324f1
|
rules: doc
|
2022-03-29 12:26:39 -06:00 |
|
Willi Ballenthin
|
c1b28f58d0
|
rules: don't use global features to downselect rules
closes #931
|
2022-03-29 12:25:27 -06:00 |
|
Willi Ballenthin
|
565e4e0a2f
|
Merge branch 'feature-insn-scope' of github.com:mandiant/capa into feature-insn-scope
|
2022-03-29 11:52:45 -06:00 |
|
Willi Ballenthin
|
7487da89a1
|
Merge branch 'master' into feature-insn-scope
|
2022-03-29 11:51:14 -06:00 |
|
Willi Ballenthin
|
fe5d88585c
|
setup: bump black to 22.3.0 to fix CI
|
2022-03-29 11:40:34 -06:00 |
|
Willi Ballenthin
|
bd6e62e9bf
|
Update scripts/lint.py
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2022-03-29 11:26:21 -06:00 |
|
Willi Ballenthin
|
b76930d2a3
|
main: split out basic block feature, match extraction
|
2022-03-28 13:47:53 -06:00 |
|
Willi Ballenthin
|
00d439f681
|
main: rename find_code_capabilities
|
2022-03-28 13:29:06 -06:00 |
|
Willi Ballenthin
|
963cfbf380
|
pep8
|
2022-03-28 13:17:35 -06:00 |
|
Willi Ballenthin
|
031ea167e8
|
add pycodestyle config
|
2022-03-28 13:17:18 -06:00 |
|
Willi Ballenthin
|
dde52f2bc8
|
pep8
|
2022-03-28 13:04:44 -06:00 |
|
Willi Ballenthin
|
46cc681eba
|
tests: demonstrate instruct subscope rule extraction
|
2022-03-28 13:04:13 -06:00 |
|
Willi Ballenthin
|
b0619f4f01
|
rules: index instruction rules in ruleset
|
2022-03-28 13:03:58 -06:00 |
|
Willi Ballenthin
|
2baf05acdb
|
rules: parse instruction subscope with implied AND
|
2022-03-28 12:55:09 -06:00 |
|
Willi Ballenthin
|
890870bf45
|
rules: let subscope blocks have descriptions
|
2022-03-28 12:54:54 -06:00 |
|
Willi Ballenthin
|
9da9c3aceb
|
rules: add valid features for insn scope
|
2022-03-28 12:40:10 -06:00 |
|
Willi Ballenthin
|
c8fedb0f70
|
gitignore
|
2022-03-28 12:39:58 -06:00 |
|
Willi Ballenthin
|
a203f56bdb
|
rules: add new scope "instruction"
|
2022-03-28 12:14:07 -06:00 |
|
Willi Ballenthin
|
18880c40d5
|
Merge pull request #927 from mandiant/dependabot/pip/mypy-0.942
build(deps-dev): bump mypy from 0.941 to 0.942
|
2022-03-28 11:26:06 -06:00 |
|
Willi Ballenthin
|
bd62661ef3
|
Merge pull request #928 from mandiant/dependabot/pip/types-requests-2.27.15
build(deps-dev): bump types-requests from 2.27.12 to 2.27.15
|
2022-03-28 11:25:57 -06:00 |
|
Willi Ballenthin
|
8d285c03ad
|
Merge pull request #929 from mandiant/dependabot/pip/tqdm-4.63.1
build(deps): bump tqdm from 4.63.0 to 4.63.1
|
2022-03-28 11:25:25 -06:00 |
|
dependabot[bot]
|
7a4ee78805
|
build(deps): bump tqdm from 4.63.0 to 4.63.1
Bumps [tqdm](https://github.com/tqdm/tqdm) from 4.63.0 to 4.63.1.
- [Release notes](https://github.com/tqdm/tqdm/releases)
- [Commits](https://github.com/tqdm/tqdm/compare/v4.63.0...v4.63.1)
---
updated-dependencies:
- dependency-name: tqdm
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-03-28 14:13:45 +00:00 |
|
dependabot[bot]
|
6105d2a36c
|
build(deps-dev): bump types-requests from 2.27.12 to 2.27.15
Bumps [types-requests](https://github.com/python/typeshed) from 2.27.12 to 2.27.15.
- [Release notes](https://github.com/python/typeshed/releases)
- [Commits](https://github.com/python/typeshed/commits)
---
updated-dependencies:
- dependency-name: types-requests
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-03-28 14:13:39 +00:00 |
|
dependabot[bot]
|
7db90ba35e
|
build(deps-dev): bump mypy from 0.941 to 0.942
Bumps [mypy](https://github.com/python/mypy) from 0.941 to 0.942.
- [Release notes](https://github.com/python/mypy/releases)
- [Commits](https://github.com/python/mypy/compare/v0.941...v0.942)
---
updated-dependencies:
- dependency-name: mypy
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-03-28 14:13:37 +00:00 |
|
Mike Hunhoff
|
fb34b1674b
|
improve handling _ prefix added to library functions as compile/link artifact (#924)
|
2022-03-25 13:34:39 -06:00 |
|
Capa Bot
|
eaf978da0a
|
Sync capa rules submodule
|
2022-03-24 09:43:38 +00:00 |
|
Capa Bot
|
ecea572192
|
Sync capa-testfiles submodule
|
2022-03-24 09:30:26 +00:00 |
|
Capa Bot
|
5552baa5e2
|
Sync capa rules submodule
|
2022-03-24 08:16:48 +00:00 |
|
Capa Bot
|
3b86ccc1a4
|
Sync capa rules submodule
|
2022-03-23 17:57:09 +00:00 |
|
Mike Hunhoff
|
8fd81d1098
|
Merge pull request #922 from mandiant/pin-smda-version-171
update pinned smda version
|
2022-03-22 12:46:35 -06:00 |
|
Mike Hunhoff
|
b7badede86
|
update pinned smda version
|
2022-03-22 12:25:41 -06:00 |
|
Mike Hunhoff
|
4c4e633395
|
Merge pull request #919 from mandiant/fix/917
fixes #917
|
2022-03-22 07:15:40 -06:00 |
|
Capa Bot
|
1cd5e89f85
|
Sync capa-testfiles submodule
|
2022-03-22 07:22:11 +00:00 |
|