pnx@pyrite
|
1e25604b0b
|
replacement test for nested x64 thunks - still needs to be verified for vivisect
|
2020-11-05 16:31:47 +01:00 |
|
pnx@pyrite
|
3a43ffa641
|
adjusted identification of thunks via SMDA.
|
2020-11-05 12:58:07 +01:00 |
|
Daniel Plohmann (jupiter)
|
6bcdf64f67
|
formatting
|
2020-10-30 15:34:02 +01:00 |
|
Daniel Plohmann (jupiter)
|
d276a07a71
|
comments on a test where disassembly differs among backends
|
2020-10-30 15:29:38 +01:00 |
|
Daniel Plohmann (jupiter)
|
f3b59b342a
|
Merge branch 'backend-smda' of github.com:danielplohmann/capa into backend-smda
|
2020-10-30 15:25:45 +01:00 |
|
Daniel Plohmann (jupiter)
|
4a0f1f22ba
|
test fixes
|
2020-10-30 15:25:42 +01:00 |
|
Jon Crussell
|
0c85e7604c
|
use magical derefs
Found derefs in viv/insn.py, does exactly what we need!
|
2020-10-30 07:23:24 -07:00 |
|
Jon Crussell
|
8f6a46e2d8
|
add check for pointer to string
Check if memory referenced is a pointer to a string. Fixes mimikatz
string test.
|
2020-10-30 07:01:07 -07:00 |
|
Daniel Plohmann (jupiter)
|
74b2c18296
|
down to 14 failed
|
2020-10-29 20:05:50 +01:00 |
|
Jon Crussell
|
b12d0b6424
|
tests: add smda backend test
40 failed, 73 passed.
|
2020-10-29 09:56:28 -07:00 |
|
Daniel Plohmann (jupiter)
|
60ddf0400e
|
addressing review
|
2020-10-29 17:47:10 +01:00 |
|
Daniel Plohmann (jupiter)
|
669d3484c0
|
Merge remote-tracking branch 'origin/master' into backend-smda
|
2020-10-29 17:38:21 +01:00 |
|
William Ballenthin
|
5420ad97a3
|
sync submodules
|
2020-10-29 09:42:56 -06:00 |
|
Daniel Plohmann (jupiter)
|
36822926af
|
initial commit for backend-smda
|
2020-10-29 11:28:22 +01:00 |
|
Capa Bot
|
eef8f2e781
|
Sync capa rules submodule
|
2020-10-29 03:50:40 +00:00 |
|
Capa Bot
|
31ac667623
|
Sync capa rules submodule
|
2020-10-27 15:16:07 +00:00 |
|
Capa Bot
|
868ceb25bf
|
Sync capa rules submodule
|
2020-10-27 15:15:30 +00:00 |
|
Capa Bot
|
ee3ab94774
|
Sync capa rules submodule
|
2020-10-27 15:15:04 +00:00 |
|
Capa Bot
|
1c47877a8c
|
Sync capa rules submodule
|
2020-10-27 15:14:22 +00:00 |
|
Capa Bot
|
84698462f3
|
Sync capa rules submodule
|
2020-10-27 15:13:25 +00:00 |
|
Capa Bot
|
da7dc793e7
|
Sync capa rules submodule
|
2020-10-27 15:12:51 +00:00 |
|
Capa Bot
|
044ee83fbc
|
Sync capa-testfiles submodule
|
2020-10-26 16:48:15 +00:00 |
|
Capa Bot
|
aea324c4a8
|
Sync capa rules submodule
|
2020-10-26 16:47:44 +00:00 |
|
Capa Bot
|
4d05b20830
|
Sync capa rules submodule
|
2020-10-26 16:46:53 +00:00 |
|
Willi Ballenthin
|
276928951c
|
build: event published/edited, not created
|
2020-10-23 15:17:32 -06:00 |
|
Willi Ballenthin
|
9486654e77
|
changelog: v1.4.1
v1.4.1
|
2020-10-23 15:13:22 -06:00 |
|
Willi Ballenthin
|
2a2b4cbb06
|
Merge pull request #351 from fireeye/ci-build-windows-vcpython27
fix build on windows-latest
|
2020-10-23 15:10:56 -06:00 |
|
Willi Ballenthin
|
3ba4a8cdd8
|
Update build.yml
|
2020-10-23 15:07:13 -06:00 |
|
Willi Ballenthin
|
8820dabab9
|
Update build.yml
|
2020-10-23 14:59:34 -06:00 |
|
Willi Ballenthin
|
f9d89301df
|
Update build.yml
|
2020-10-23 14:58:44 -06:00 |
|
Willi Ballenthin
|
7edb93d3ad
|
Update build.yml
|
2020-10-23 14:57:14 -06:00 |
|
Moritz
|
5c5d9974e1
|
Merge pull request #350 from fireeye/release-1.4.0
release v1.4.0
v1.4.0
|
2020-10-23 22:31:00 +02:00 |
|
Moritz Raabe
|
b0bf4f8f8e
|
prepare new release
|
2020-10-23 22:24:50 +02:00 |
|
Capa Bot
|
04ea03caf6
|
Sync capa rules submodule
|
2020-10-23 18:50:52 +00:00 |
|
Capa Bot
|
cf0841bdcc
|
Sync capa-testfiles submodule
|
2020-10-23 18:49:05 +00:00 |
|
Capa Bot
|
cc4f5f66d8
|
Sync capa-testfiles submodule
|
2020-10-23 18:42:54 +00:00 |
|
Capa Bot
|
e6d75ee7c4
|
Sync capa rules submodule
|
2020-10-23 16:46:53 +00:00 |
|
Moritz
|
61986fc98c
|
Merge pull request #333 from fireeye/improve-packaging-setup
add long description and other improvements
|
2020-10-23 13:16:13 +02:00 |
|
Moritz
|
0e009c7c12
|
Merge pull request #347 from fireeye/fix/non-ascii-char-filename
get decoded sample path
|
2020-10-23 13:15:36 +02:00 |
|
Moritz
|
425613ee42
|
Merge pull request #346 from fireeye/extract/api-jmps
Extract/api jmps
|
2020-10-23 13:15:10 +02:00 |
|
Moritz Raabe
|
679316946e
|
addressing Willi's feedback
|
2020-10-22 20:10:47 +02:00 |
|
Moritz
|
8bb305038b
|
Merge pull request #343 from fireeye/fix/file-imports-ordinal-name
extract ordinal and name imports
|
2020-10-22 20:07:42 +02:00 |
|
Moritz Raabe
|
fbe104d254
|
get decoded sample path
closes #328
|
2020-10-22 19:56:41 +02:00 |
|
Capa Bot
|
cb44cb0ee2
|
Sync capa-testfiles submodule
|
2020-10-22 17:49:54 +00:00 |
|
Capa Bot
|
2163f64877
|
Sync capa-testfiles submodule
|
2020-10-22 17:49:18 +00:00 |
|
Capa Bot
|
a14d958ef0
|
Sync capa-testfiles submodule
|
2020-10-22 13:17:55 +00:00 |
|
Capa Bot
|
c65ef12783
|
Sync capa rules submodule
|
2020-10-22 04:02:25 +00:00 |
|
Capa Bot
|
8eb1727c76
|
Sync capa rules submodule
|
2020-10-21 15:54:41 +00:00 |
|
William Ballenthin
|
fafe24295a
|
Merge branch 'master' of github.com:fireeye/capa
|
2020-10-21 09:53:09 -06:00 |
|
William Ballenthin
|
d900a6c145
|
render: default: sanity check MBC
|
2020-10-21 09:52:40 -06:00 |
|