William Ballenthin
|
21adb2b9d1
|
tests: lancelot: formatting
|
2020-08-10 18:16:14 -06:00 |
|
William Ballenthin
|
5929c0652c
|
lancelot: insn: fs/gs
|
2020-08-10 18:15:10 -06:00 |
|
William Ballenthin
|
e7bf5bfceb
|
lancelot: insn: nzxor
|
2020-08-10 18:05:26 -06:00 |
|
William Ballenthin
|
c2f55fad12
|
tests: lancelot: construct assert message
|
2020-08-10 18:05:08 -06:00 |
|
William Ballenthin
|
7ac4cf47f7
|
lancelot: insn: pass f, bb, insn throughout
|
2020-08-10 18:04:37 -06:00 |
|
William Ballenthin
|
3f49a224f5
|
lancelot: off-by-one instruction enumerator
|
2020-08-10 18:03:40 -06:00 |
|
William Ballenthin
|
695f1bf55a
|
lancelot: insn: strings
|
2020-08-10 17:23:19 -06:00 |
|
William Ballenthin
|
10f5a54e1d
|
lancelot: insn: bytes
|
2020-08-10 17:08:28 -06:00 |
|
William Ballenthin
|
042654ee97
|
lancelot: insn: mnemonic
|
2020-08-10 13:50:46 -06:00 |
|
William Ballenthin
|
1da450001c
|
lancelot: insn: offset
|
2020-08-10 13:47:43 -06:00 |
|
William Ballenthin
|
7996e2efe7
|
tests: lancelot: remove old tests
|
2020-08-10 11:51:48 -06:00 |
|
William Ballenthin
|
5eded3c5cc
|
lancelot: insn: implement API features
|
2020-08-10 11:49:37 -06:00 |
|
William Ballenthin
|
cdae840519
|
lancelot: file: fix import address
|
2020-08-10 11:49:11 -06:00 |
|
William Ballenthin
|
fcb8c4a293
|
tests: lancelot: override parametrize for better naming
|
2020-08-09 15:46:34 -06:00 |
|
William Ballenthin
|
4e6b475ff6
|
tests: lancelot: add number tests
|
2020-08-08 13:55:52 -06:00 |
|
William Ballenthin
|
02a8ad1ea4
|
tests: add more lancelot feature tests
|
2020-08-08 13:52:22 -06:00 |
|
William Ballenthin
|
393b332f9c
|
feature: insn: better render negative offset
|
2020-08-08 13:52:01 -06:00 |
|
William Ballenthin
|
bf4a8dcd3e
|
setup: add dep on backports.lru
|
2020-08-08 13:51:50 -06:00 |
|
William Ballenthin
|
9bde11fa6f
|
extractor: lancelot: fix stackstring
|
2020-08-08 13:51:34 -06:00 |
|
William Ballenthin
|
43c6eec30b
|
extractors: begin to implement lancelot backend
|
2020-08-08 12:48:56 -06:00 |
|
Capa Bot
|
f7cd52826e
|
Sync capa rules submodule
|
2020-08-05 18:51:51 +00:00 |
|
Capa Bot
|
23d31c3c2c
|
Sync capa-testfiles submodule
|
2020-08-05 18:50:52 +00:00 |
|
Willi Ballenthin
|
732b47e845
|
changelog: fix @mike-hunhoff handle
|
2020-08-05 08:20:34 -06:00 |
|
Willi Ballenthin
|
12076eeda2
|
Merge pull request #222 from fireeye/release-v1.1.0
draft v1.1.0 release
v1.1.0
|
2020-08-05 08:11:08 -06:00 |
|
Willi Ballenthin
|
9af55292ab
|
changelog: fix feature name
|
2020-08-04 21:56:54 -06:00 |
|
Willi Ballenthin
|
9943de0746
|
Merge pull request #219 from fireeye/fix-218
ida: use a local context for cache instead of global
|
2020-08-04 21:55:50 -06:00 |
|
Capa Bot
|
1c3da73324
|
Sync capa rules submodule
|
2020-08-05 03:18:55 +00:00 |
|
William Ballenthin
|
a7484b9dbe
|
changelog: add download text
|
2020-08-04 16:28:49 -06:00 |
|
William Ballenthin
|
ea72454d74
|
init changelog
|
2020-08-04 16:27:43 -06:00 |
|
William Ballenthin
|
183f533efd
|
version: bump to v1.1.0
|
2020-08-04 15:50:13 -06:00 |
|
Willi Ballenthin
|
715c38b4ff
|
Merge pull request #221 from fireeye/fix-199
setup: bump viv version
|
2020-08-04 13:07:32 -06:00 |
|
William Ballenthin
|
fd92165f29
|
setup: bump viv version
|
2020-08-04 13:06:52 -06:00 |
|
Willi Ballenthin
|
36c26ab6ee
|
Merge pull request #220 from fireeye/fix-178
ci: enable pyinstaller builds upon gh release tagged
v1.1.0-rc1
|
2020-08-04 12:24:17 -06:00 |
|
William Ballenthin
|
9778a1de18
|
ci: build standalone exe upon release
|
2020-08-04 12:05:02 -06:00 |
|
William Ballenthin
|
328f27511b
|
ci: build standalone exe upon release
|
2020-08-04 12:04:15 -06:00 |
|
William Ballenthin
|
9751c66565
|
ci: demonstrate capa runs against test file
|
2020-08-04 11:56:05 -06:00 |
|
William Ballenthin
|
32e293f78f
|
ci: checkout submodules for rules
|
2020-08-04 11:53:13 -06:00 |
|
William Ballenthin
|
61afeb1b78
|
ci: upload artifacts upon build
|
2020-08-04 11:49:26 -06:00 |
|
William Ballenthin
|
0606666e08
|
ci: run capa on itself to demonstrate rules work
|
2020-08-04 11:44:41 -06:00 |
|
William Ballenthin
|
ae276d27ab
|
ci: configure win/macos os
|
2020-08-04 11:39:44 -06:00 |
|
William Ballenthin
|
dd74fae160
|
ci: attempt to configure gh actions for pyinstaller
|
2020-08-04 11:31:33 -06:00 |
|
William Ballenthin
|
4bb13d6075
|
tests: ida: fix offset arch test
|
2020-08-04 10:35:10 -06:00 |
|
William Ballenthin
|
6aa17782b7
|
extractors: ida: fix method signature
|
2020-08-04 10:33:45 -06:00 |
|
William Ballenthin
|
e74b80a318
|
extractors: ida: add helper method get_function
|
2020-08-04 10:32:24 -06:00 |
|
William Ballenthin
|
f993efb8f4
|
extractors: ida: cache data using shared context not globals
attempts to close #218
|
2020-08-04 10:23:47 -06:00 |
|
Willi Ballenthin
|
f670c25027
|
Merge pull request #216 from fireeye/fix-210
rules: add support for arch flavors of Number and Offset features
|
2020-08-04 10:14:03 -06:00 |
|
William Ballenthin
|
8b7a8b0956
|
rules: address comments in #216
|
2020-08-04 10:10:52 -06:00 |
|
William Ballenthin
|
e4acfd4852
|
merge
|
2020-08-04 09:48:26 -06:00 |
|
Willi Ballenthin
|
cab4cfa0e0
|
Merge pull request #217 from fireeye/fix-200
features: viv: extract strings/bytes from nested pointers
|
2020-08-04 09:41:14 -06:00 |
|
Capa Bot
|
e5921e9267
|
Sync capa rules submodule
|
2020-08-04 14:35:08 +00:00 |
|