From 06631fc39dbd0683a597582017fdbdbd085027e3 Mon Sep 17 00:00:00 2001 From: Mike Hunhoff Date: Fri, 12 Jul 2024 18:42:42 -0600 Subject: [PATCH] vmray: remove call feature extraction for out parameters --- capa/features/extractors/vmray/call.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/capa/features/extractors/vmray/call.py b/capa/features/extractors/vmray/call.py index e0f1059a..e20805bf 100644 --- a/capa/features/extractors/vmray/call.py +++ b/capa/features/extractors/vmray/call.py @@ -36,9 +36,12 @@ def extract_call_features(ph: ProcessHandle, th: ThreadHandle, ch: CallHandle) - for param in call.params_in.params: yield from get_call_param_features(param, ch) + """ + # TODO (meh): params_out stores return value, not sure where to emit this?? https://github.com/mandiant/capa/issues/2148 if call.params_out: for param in call.params_out.params: yield from get_call_param_features(param, ch) + """ yield API(call.name), ch.address