Willi Ballenthin
|
535ba622ae
|
Merge pull request #1422 from yelhamer/feature-symtab-os-guess
ELF OS detection: add support for guessing that's based on .symtab entries
|
2023-04-03 08:41:47 +02:00 |
|
Capa Bot
|
c6b634f3ae
|
Sync capa-testfiles submodule
|
2023-04-03 06:41:30 +00:00 |
|
Willi Ballenthin
|
386baec3c5
|
elf: hints and formatting
|
2023-04-03 08:40:41 +02:00 |
|
Yacine Elhamer
|
b2ead45ad4
|
tests: Add test for sample 2bf18d
|
2023-04-02 21:57:22 +01:00 |
|
Yacine Elhamer
|
74284e9dad
|
bugfix: potential reference to uninitialized variables
|
2023-04-02 21:56:28 +01:00 |
|
Yacine Elhamer
|
270077bc73
|
SymTab class: update get_symbols() type and add return-value comment
|
2023-04-02 20:59:09 +01:00 |
|
Yacine Elhamer
|
367a0c483c
|
rename the SYMTAB class to SymTab
|
2023-04-02 20:49:58 +01:00 |
|
Yacine Elhamer
|
8a272e92c7
|
format: removed tabs
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-04-02 20:38:44 +01:00 |
|
Yacine Elhamer
|
2d1105dba9
|
format: update elf.py to use isort and black format
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-04-02 20:36:34 +01:00 |
|
Yacine Elhamer
|
c798996f6e
|
detect_elf_os(): Integrate symbol-based guessing ability
|
2023-04-02 18:11:11 +01:00 |
|
Yacine Elhamer
|
ef0e4bd4fd
|
os-guessing: Add symtab-guessing capability
|
2023-04-02 18:07:46 +01:00 |
|
Yacine Elhamer
|
bfaee2c402
|
Add a class (SYMTAB) for the symbol table
|
2023-04-02 18:07:46 +01:00 |
|
Yacine Elhamer
|
1f6cd807a4
|
Shdr dataclass: add sh_entsize member
|
2023-04-02 18:07:22 +01:00 |
|
Willi Ballenthin
|
6f416dfefb
|
Merge pull request #1418 from stevemk14ebr/master
Remove dynsym library name for ELF imports
|
2023-04-01 13:54:07 +02:00 |
|
Capa Bot
|
06c71a7f2b
|
Sync capa rules submodule
|
2023-03-31 17:40:58 +00:00 |
|
Stephen Eckels
|
270350f8d1
|
Update CHANGELOG.md
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-03-31 13:26:41 -04:00 |
|
Stephen Eckels
|
c603b92bc5
|
Merge branch 'master' of https://github.com/stevemk14ebr/capa
|
2023-03-31 13:25:45 -04:00 |
|
Stephen Eckels
|
59be399dac
|
Revert line removal
|
2023-03-31 13:25:37 -04:00 |
|
Capa Bot
|
7f39cb1bc3
|
Sync capa rules submodule
|
2023-03-31 14:03:51 +00:00 |
|
Stephen Eckels
|
1921961cff
|
Update todo comment to link issue
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-03-30 13:23:29 -04:00 |
|
Stephen Eckels
|
3cd766630f
|
Update changelog
|
2023-03-30 13:21:37 -04:00 |
|
Willi Ballenthin
|
99ee317fd0
|
Merge pull request #1396 from ooprathamm/read-render
Towards improving read and rendering of results
|
2023-03-30 13:03:27 +02:00 |
|
Pratham Chauhan
|
456f6e0003
|
fix broken arch logic
|
2023-03-30 16:18:52 +05:30 |
|
Willi Ballenthin
|
1ccd2c4d0f
|
tests: fix proto tests on windows (#1417)
closes #1416
|
2023-03-30 11:45:03 +02:00 |
|
Willi Ballenthin
|
f42b5b1088
|
Merge pull request #1409 from mandiant/dependabot/pip/protobuf-4.22.1
build(deps): bump protobuf from 4.21.12 to 4.22.1
|
2023-03-30 11:17:14 +02:00 |
|
Pratham Chauhan
|
1b90a28acd
|
resolved merge conflicts
|
2023-03-30 11:05:32 +05:30 |
|
Pratham Chauhan
|
cd0e0ce4d1
|
remove unused import
|
2023-03-30 10:52:05 +05:30 |
|
Pratham Chauhan
|
7cb4ea9273
|
Fix lint issues
|
2023-03-30 10:35:31 +05:30 |
|
Stephen Eckels
|
66e374a343
|
Update changelog
|
2023-03-29 16:01:31 -04:00 |
|
Stephen Eckels
|
5e8262d3c0
|
Remove dynsym from elf entirely
|
2023-03-29 15:58:16 -04:00 |
|
Willi Ballenthin
|
6bb14d0874
|
Merge pull request #1415 from mandiant/f-strings
use f-strings as appropriate
|
2023-03-29 20:47:12 +02:00 |
|
Pratham Chauhan
|
c3fdab8ec5
|
Add new test test_rdoc_to_capa
|
2023-03-29 22:57:11 +05:30 |
|
Pratham Chauhan
|
237554d84a
|
Fix broken logic for FORMAT_FREEZE
|
2023-03-29 22:32:12 +05:30 |
|
Pratham Chauhan
|
6ed7aca5be
|
remove rule param
|
2023-03-29 19:50:07 +05:30 |
|
Pratham Chauhan
|
a13ce094b3
|
use rd/test json
|
2023-03-29 19:41:14 +05:30 |
|
Pratham Chauhan
|
6806b8f5a7
|
use pydantic.parse_file
|
2023-03-29 19:02:45 +05:30 |
|
dependabot[bot]
|
fbdf92367e
|
build(deps): bump protobuf from 4.21.12 to 4.22.1
Bumps [protobuf](https://github.com/protocolbuffers/protobuf) from 4.21.12 to 4.22.1.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](https://github.com/protocolbuffers/protobuf/commits/v4.22.1)
---
updated-dependencies:
- dependency-name: protobuf
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-03-29 12:52:59 +00:00 |
|
Willi Ballenthin
|
2ec96d7f13
|
Merge pull request #1408 from mandiant/dependabot/pip/pydantic-1.10.7
build(deps): bump pydantic from 1.10.6 to 1.10.7
|
2023-03-29 14:52:45 +02:00 |
|
Willi Ballenthin
|
1c457d3428
|
Merge pull request #1407 from mandiant/dependabot/pip/types-protobuf-4.22.0.0
build(deps-dev): bump types-protobuf from 4.21.0.5 to 4.22.0.0
|
2023-03-29 14:52:14 +02:00 |
|
Pratham Chauhan
|
fe1193f374
|
removes unused imports
|
2023-03-29 16:12:17 +05:30 |
|
Pratham Chauhan
|
abbf3db2ac
|
Revert "remove unused imports"
This reverts commit 9e12c563bc.
|
2023-03-29 16:11:21 +05:30 |
|
Pratham Chauhan
|
5a1009520d
|
Revert "Revert "introducing match strings constant for formats""
This reverts commit b49fb7fcf9.
|
2023-03-29 16:10:44 +05:30 |
|
Pratham Chauhan
|
b49fb7fcf9
|
Revert "introducing match strings constant for formats"
This reverts commit 530e28cbc3.
|
2023-03-29 16:06:20 +05:30 |
|
Pratham Chauhan
|
9e12c563bc
|
remove unused imports
|
2023-03-29 16:02:17 +05:30 |
|
Pratham Chauhan
|
530e28cbc3
|
introducing match strings constant for formats
|
2023-03-29 16:00:02 +05:30 |
|
Pratham Chauhan
|
637dd6bf0a
|
Added a unit test
|
2023-03-29 15:51:25 +05:30 |
|
Pratham Chauhan
|
fdc9530352
|
seperating loading json and to_capa logic
|
2023-03-29 08:34:06 +05:30 |
|
Capa Bot
|
b5f274bf56
|
Sync capa rules submodule
|
2023-03-28 14:07:51 +00:00 |
|
Willi Ballenthin
|
ac2d01a60a
|
use f-strings as appropriate
closes #600
|
2023-03-28 11:43:49 +02:00 |
|
Willi Ballenthin
|
95bdaf072b
|
Merge pull request #1399 from ggold7046/patch-15
Update utils.py
|
2023-03-28 09:47:11 +02:00 |
|