Commit Graph

433 Commits

Author SHA1 Message Date
Mike Hunhoff b68be0c2ce dotnet: emit namespace/class features for type references (#1242)
* dotnet: emit namespace/class features for type references

* dotnet: pre-compute .NET token caches
2022-12-21 15:59:29 -07:00
Mike Hunhoff 50490e6a93 dotnet: emit namespace/class features for ldvirtftn/ldftn instructions (#1241)
* dotnet: emit namespace/class features for ldvirtftn/ldftn instructions

* dotnet: add unit tests for ldftn/ldvirtftn namespace/class features
2022-12-20 13:29:29 -07:00
Mike Hunhoff 4ece47c64c dotnet: emit calls to/from MethodDef methods (#1236)
* dotnet: emit calls to/from MethodDef methods

* dotnet: update function.py copyright header
2022-12-19 15:06:16 -07:00
Mike Hunhoff e0491097b0 dotnet: emit API features for generic methods (#1231)
* dotnet: emit API features for generic methods

* dotnet: improve type checking

* dotnet: emit namespace/class features for generic methods

* dotnet: update for dnfile 0.13.0

* dotnet: refactor property extraction
2022-12-19 14:45:21 -07:00
Willi Ballenthin 613c185428 tests: fix broken test 2022-12-14 11:51:25 +01:00
Willi Ballenthin 81500a4d1d black 2022-12-14 10:48:00 +01:00
Willi Ballenthin b819033da0 lots of mypy 2022-12-14 10:37:39 +01:00
Willi Ballenthin ee72ed4b53 tests: os: fix test 2022-12-12 14:06:17 +01:00
Capa Bot 5cd7f33d00 Sync capa-testfiles submodule 2022-12-12 12:29:44 +00:00
Willi Ballenthin d6674c7548 Merge pull request #1222 from mandiant/fix/issue-1221
elf: better detect linux ELF files
2022-12-12 13:28:59 +01:00
Capa Bot a46d7b3262 Sync capa-testfiles submodule 2022-12-12 12:18:01 +00:00
Willi Ballenthin 22bef146f8 tests: add OS detection tests 2022-12-12 11:40:43 +01:00
Willi Ballenthin b26ed47ab8 tests: add OS detection tests 2022-12-12 11:40:32 +01:00
mr-tz 97f633312f skip smda tests until we remove the backend 2022-12-07 16:44:52 +01:00
Willi Ballenthin 1f091a4ccd tests: add tests demonstrating vverbose feature rendering 2022-12-07 12:58:10 +00:00
Capa Bot 0f99592903 Sync capa-testfiles submodule 2022-11-08 19:58:11 +00:00
Mike Hunhoff 20c7949be3 dotnet: emit features from newobj instruction (#1186) 2022-10-13 08:35:29 -06:00
Capa Bot 87455ed6dd Sync capa-testfiles submodule 2022-09-20 19:34:29 +00:00
Mike Hunhoff e1735f0a5e update pydantic models to guarantee type coercion (#1176)
* add CompoundStatement to fix Pydantic typing bug

* explorer: fix #1151

* explorer: support rendering operand number/offset
2022-09-20 08:38:19 -06:00
Capa Bot 8521f85742 Sync capa-testfiles submodule 2022-09-19 14:26:32 +00:00
Mike Hunhoff 3c1cd67f60 dotnet: support property feature extraction (#1168) 2022-09-09 12:09:41 -06:00
Moritz 2441c18a85 fix: use int instead of Token to decouple extractor and features (#1158) 2022-09-08 11:09:17 -06:00
Moritz 3976e5858d feat: verify rule metadata format on load (#1160) 2022-09-08 10:56:59 -06:00
Capa Bot cac041b869 Sync capa-testfiles submodule 2022-08-24 10:47:31 +00:00
Capa Bot f4171c32cf Sync capa-testfiles submodule 2022-08-15 08:31:20 +00:00
Capa Bot 5823d421fd Sync capa-testfiles submodule 2022-08-01 20:50:09 +00:00
Capa Bot 045a64496e Sync capa-testfiles submodule 2022-08-01 20:36:11 +00:00
Capa Bot b8905e3e48 Sync capa-testfiles submodule 2022-08-01 20:35:55 +00:00
Capa Bot 7c6f27c6d7 Sync capa-testfiles submodule 2022-08-01 20:35:14 +00:00
Capa Bot 995b144f0b Sync capa-testfiles submodule 2022-08-01 20:34:46 +00:00
Capa Bot ba93803d3f Sync capa-testfiles submodule 2022-08-01 20:30:55 +00:00
Capa Bot 6764830f2d Sync capa-testfiles submodule 2022-07-08 18:59:42 +00:00
Capa Bot 9015761d4d Sync capa-testfiles submodule 2022-06-30 15:16:42 +00:00
Capa Bot 7387c56af9 Sync capa-testfiles submodule 2022-06-29 17:47:36 +00:00
Willi Ballenthin 91818a116d scripts/capa_as_library: use new ResultDocument
closes #1071
2022-06-28 15:53:37 -06:00
Moritz Raabe a7c4761fef isort, black 2022-06-28 15:53:10 +02:00
Moritz Raabe e2156c3854 refactor: parametrize test 2022-06-28 15:49:21 +02:00
Willi Ballenthin a453258a51 tests: fix render test for MBC 2022-06-20 14:25:18 -06:00
Willi Ballenthin 246ef58e7b tests: fix render test for ATT&CK metadata 2022-06-20 14:24:01 -06:00
William Ballenthin c417b5dd79 merge master 2022-06-14 17:05:46 -06:00
Willi Ballenthin 3103307601 tests: fix reference error 2022-06-10 14:58:26 -06:00
Capa Bot c653dd7e72 Sync capa-testfiles submodule 2022-06-10 20:48:49 +00:00
Willi Ballenthin 1c771da848 pep8 2022-06-10 14:47:23 -06:00
William Ballenthin c3418fddb5 tests: json: fix address representation 2022-06-08 13:29:04 -06:00
William Ballenthin faf414e3d8 tests: add more dotnet tests 2022-06-08 13:28:53 -06:00
Willi Ballenthin 0987141970 tests: add tests demonstrating rending of .NET samples 2022-06-06 15:13:20 -06:00
Willi Ballenthin c73db051c1 fixtures: add path to extractors 2022-06-06 15:13:11 -06:00
Willi Ballenthin 1a290a38c4 Merge branch 'master' into feature-981 2022-06-06 14:07:51 -06:00
Moritz d8e68255a0 Merge pull request #1044 from mandiant/fix/rules-meta-authors
fix!: authors instead of author
2022-06-01 14:12:31 +02:00
Capa Bot 781ec74310 Sync capa-testfiles submodule 2022-06-01 12:12:01 +00:00