diff --git a/capa/features/extractors/ida/helpers.py b/capa/features/extractors/ida/helpers.py index dbb9bd1d..a6068451 100644 --- a/capa/features/extractors/ida/helpers.py +++ b/capa/features/extractors/ida/helpers.py @@ -90,8 +90,10 @@ def get_file_imports() -> Dict[int, Tuple[str, str, int]]: if not library: continue - # IDA uses section names for the library of ELF imports, like ".dynsym" - library = library.lstrip(".") + # IDA uses section names for the library of ELF imports, like ".dynsym". + # These are not useful to us, we may need to expand this list over time (TODO: exhaust this list) + if library == ".dynsym": + library = "" def inspect_import(ea, function, ordinal): if function and function.startswith("__imp_"):