Willi Ballenthin
|
8a2276f398
|
smda: implement operand number/offset features
cause its not too hard
|
2022-04-07 12:48:25 -06:00 |
|
Willi Ballenthin
|
6b810a1f72
|
ida: insn: look for numbers in displ, not phrase
|
2022-04-06 15:41:17 -06:00 |
|
Willi Ballenthin
|
c36bde0f2d
|
ida: insn: ignore numbers when SIB present
|
2022-04-06 15:38:04 -06:00 |
|
Willi Ballenthin
|
1a44dd8a2b
|
insn: better detect offset/numbers
|
2022-04-06 15:12:59 -06:00 |
|
Willi Ballenthin
|
1c7b6bcf7d
|
fixtures: use function that IDA doesn't recognize as lib func
|
2022-04-06 15:07:35 -06:00 |
|
Willi Ballenthin
|
e2c6f5e393
|
ida: insn: use .ea not .va
|
2022-04-06 15:03:24 -06:00 |
|
Willi Ballenthin
|
85d5043992
|
changelog
|
2022-04-06 14:59:24 -06:00 |
|
Willi Ballenthin
|
47dfeafdc8
|
ida, viv: implement extra offset/number extraction
|
2022-04-06 14:57:51 -06:00 |
|
Willi Ballenthin
|
b843cef986
|
tests: add tests for #320
|
2022-04-06 14:38:56 -06:00 |
|
Willi Ballenthin
|
0e95691cde
|
tests: fixtures: enable assertions against instruction scope
|
2022-04-06 14:38:33 -06:00 |
|
Willi Ballenthin
|
587202ce43
|
ci: build: update pip and setuptools
|
2022-04-06 14:03:44 -06:00 |
|
Willi Ballenthin
|
6b2529bc80
|
Merge pull request #916 from mandiant/dependabot/pip/pytest-7.1.1
build(deps-dev): bump pytest from 7.0.1 to 7.1.1
|
2022-04-06 13:44:40 -06:00 |
|
Willi Ballenthin
|
52137f310a
|
Merge pull request #974 from mandiant/feature-vverbose-subscope
in vverbose mode, show subscope name
|
2022-04-06 13:44:15 -06:00 |
|
Willi Ballenthin
|
ad90145aa7
|
Merge pull request #973 from mandiant/feature-remove-example-vverbose
vverbose: don't show examples in output
|
2022-04-06 13:42:12 -06:00 |
|
Willi Ballenthin
|
05f7ac0802
|
Merge pull request #972 from mandiant/feature-many-rule-paths-meta
render: meta: display rule paths on separate lines
|
2022-04-06 13:41:48 -06:00 |
|
Willi Ballenthin
|
fccca823c5
|
verbose: make rule path multiline more concise
|
2022-04-06 13:41:05 -06:00 |
|
Willi Ballenthin
|
441373ea13
|
vverbose: render subscope name, like "basic block:"
closes #963
|
2022-04-06 13:33:56 -06:00 |
|
Capa Bot
|
57d2df4922
|
Sync capa rules submodule
|
2022-04-06 19:28:26 +00:00 |
|
Willi Ballenthin
|
632e778376
|
vverbose: don't show examples in output
closes #970
|
2022-04-06 13:24:36 -06:00 |
|
Willi Ballenthin
|
d47b1503b2
|
render: verbose: add doc
|
2022-04-06 13:21:11 -06:00 |
|
Willi Ballenthin
|
938c75737b
|
render: meta: display rule paths on separate lines
closes #971
|
2022-04-06 13:18:06 -06:00 |
|
Willi Ballenthin
|
55a5d10859
|
Merge pull request #961 from mandiant/feature-remove-flavors
remove /x32 and /x64 flavors of number and offset features
|
2022-04-06 12:57:18 -06:00 |
|
Willi Ballenthin
|
0c354cf268
|
capa2yara: fix rules paths
|
2022-04-06 12:36:28 -06:00 |
|
Willi Ballenthin
|
485600801c
|
ida: readme: remove python 3.6 support
|
2022-04-06 12:16:06 -06:00 |
|
Willi Ballenthin
|
4916933139
|
main: bail if python 3.6 or below
closes #964
|
2022-04-06 12:14:53 -06:00 |
|
Capa Bot
|
73f1eb9c30
|
Sync capa rules submodule
|
2022-04-06 18:08:02 +00:00 |
|
Willi Ballenthin
|
e788384d42
|
main: better handle multiple rules paths
|
2022-04-06 12:05:01 -06:00 |
|
Capa Bot
|
633d8df1a4
|
Sync capa-testfiles submodule
|
2022-04-06 17:21:09 +00:00 |
|
Willi Ballenthin
|
aff72ad983
|
capa_as_library: fix rules path is list now
|
2022-04-06 11:07:34 -06:00 |
|
Willi Ballenthin
|
c9763c4d70
|
Merge branch 'master' into feature-remove-flavors
|
2022-04-06 11:05:05 -06:00 |
|
Capa Bot
|
931a13e505
|
Sync capa rules submodule
|
2022-04-06 17:04:16 +00:00 |
|
Willi Ballenthin
|
7370a8f296
|
changelog
|
2022-04-05 17:21:04 -06:00 |
|
Willi Ballenthin
|
11b773573e
|
lint: fix rules path
|
2022-04-05 17:17:44 -06:00 |
|
Willi Ballenthin
|
67dc2cb0fa
|
main: fix removal of default rules path
|
2022-04-05 17:17:35 -06:00 |
|
Willi Ballenthin
|
bad9ecf3b1
|
main: accept multiple paths to rules
|
2022-04-05 17:14:53 -06:00 |
|
Willi Ballenthin
|
ef835649fd
|
vverbose: show lib rule matches
|
2022-04-05 16:57:36 -06:00 |
|
Willi Ballenthin
|
e9bb56f3cf
|
API: better support A/W functions
|
2022-04-05 14:54:15 -06:00 |
|
Willi Ballenthin
|
58acc9c2b7
|
rules: fix max operand index (4)
|
2022-04-05 14:53:58 -06:00 |
|
Willi Ballenthin
|
f923a4ea9b
|
linter: accept instruction scope
|
2022-04-05 12:24:41 -06:00 |
|
Willi Ballenthin
|
5957dfecf0
|
Merge branch 'feature-remove-flavors' of github.com:mandiant/capa into feature-remove-flavors
|
2022-04-05 10:41:41 -06:00 |
|
Willi Ballenthin
|
aee61b35e4
|
*: remove more references to /x32 and /x64
|
2022-04-05 10:41:03 -06:00 |
|
Willi Ballenthin
|
169d5ab826
|
Merge branch 'master' into feature-remove-flavors
|
2022-04-05 10:37:18 -06:00 |
|
Willi Ballenthin
|
de312d87dc
|
Merge pull request #960 from mandiant/feature-py37
upgrade min python version to 3.7
|
2022-04-05 10:36:33 -06:00 |
|
Willi Ballenthin
|
ecabd557a7
|
*: remove /x32 and /x64 flavors from number and offset features
|
2022-04-05 10:35:41 -06:00 |
|
Willi Ballenthin
|
f246a01484
|
changelog
|
2022-04-05 10:24:55 -06:00 |
|
Willi Ballenthin
|
0617b87f36
|
ci: no longer test against py3.6
|
2022-04-05 10:19:09 -06:00 |
|
Willi Ballenthin
|
715ac64ae6
|
changelog
|
2022-04-05 10:19:04 -06:00 |
|
Willi Ballenthin
|
78c0afe006
|
setup: min python version is now 3.7
|
2022-04-05 10:18:55 -06:00 |
|
Willi Ballenthin
|
df03932f89
|
gitignore
|
2022-04-04 16:54:51 -06:00 |
|
dependabot[bot]
|
15196c847a
|
build(deps-dev): bump pytest from 7.0.1 to 7.1.1
Bumps [pytest](https://github.com/pytest-dev/pytest) from 7.0.1 to 7.1.1.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/7.0.1...7.1.1)
---
updated-dependencies:
- dependency-name: pytest
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-04-04 22:43:41 +00:00 |
|