Willi Ballenthin
|
8cd5e03e87
|
ci: pre-commit: show-diff-on-failure
|
2023-08-18 08:19:27 +00:00 |
|
Willi Ballenthin
|
120917e0b5
|
cape: models: tweaks from Avast dataset
|
2023-08-18 08:10:55 +00:00 |
|
Willi Ballenthin
|
3614ce1409
|
cape: fix test failures
|
2023-08-16 11:43:45 +00:00 |
|
Willi Ballenthin
|
c80542ded3
|
cape: call: fix argument type switch
|
2023-08-16 11:37:41 +00:00 |
|
Willi Ballenthin
|
724db83920
|
cape: require PE analysis
|
2023-08-16 13:23:00 +02:00 |
|
Willi Ballenthin
|
8788a40d12
|
Merge branch 'dynamic-feature-extraction' into feat/cape-pydantic
|
2023-08-16 13:13:29 +02:00 |
|
Willi Ballenthin
|
6f7bf96776
|
cape: use pydantic model
|
2023-08-16 11:12:05 +00:00 |
|
Willi Ballenthin
|
e943a71dff
|
cape: models: relax deserializing FlexibleModels
|
2023-08-16 10:04:20 +00:00 |
|
Willi Ballenthin
|
4be1c89c5b
|
cape: models: more data shapes
|
2023-08-16 09:50:13 +00:00 |
|
Willi Ballenthin
|
2eda053c79
|
cape: models: more data shapes
|
2023-08-16 09:41:36 +00:00 |
|
Willi Ballenthin
|
26539e68d9
|
cape: models: add tests
|
2023-08-16 08:57:54 +00:00 |
|
Willi Ballenthin
|
046427cf55
|
cape: model: document the data we'll use in cape
|
2023-08-16 08:57:17 +00:00 |
|
Willi Ballenthin
|
25aabcd7e4
|
cape: models: more shapes
|
2023-08-16 07:48:59 +00:00 |
|
Willi Ballenthin
|
d8bea816dd
|
cape: models: add more fields
|
2023-08-15 14:36:49 +00:00 |
|
Willi Ballenthin
|
bb2b1824a9
|
Merge branch 'master' into dynamic-feature-extraction
|
2023-08-15 14:01:30 +02:00 |
|
Willi Ballenthin
|
7e78133925
|
Merge pull request #1728 from mandiant/fix/issue-1719
fix deprecation warnings
|
2023-08-15 14:00:15 +02:00 |
|
Willi Ballenthin
|
59a129d6d6
|
cape: add pydantic model for v2.2
|
2023-08-15 11:54:15 +00:00 |
|
Willi Ballenthin
|
db40d9bc7a
|
wip: add initial CAPE model
|
2023-08-15 11:41:11 +00:00 |
|
Yacine
|
d71ecc7a79
|
Update tests/test_ida_features.py
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2023-08-15 12:26:19 +02:00 |
|
Yacine
|
a5a1a0bfee
|
Update CHANGELOG.md
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2023-08-15 12:26:02 +02:00 |
|
Willi Ballenthin
|
827b4b29b4
|
test_rules: fix rule scoping logic
|
2023-08-15 09:21:49 +00:00 |
|
Willi Ballenthin
|
2a31b16567
|
merge
|
2023-08-15 08:56:41 +00:00 |
|
Willi Ballenthin
|
8118a3f353
|
changelog
|
2023-08-15 08:46:18 +00:00 |
|
Willi Ballenthin
|
e6d64ef561
|
pydantic: remove use of deprecated routines
closes #1718
|
2023-08-15 08:41:56 +00:00 |
|
Willi Ballenthin
|
408c5076c6
|
tests: ida: don't collect tests as pytest tests
closes #1719
|
2023-08-15 08:26:59 +00:00 |
|
Willi Ballenthin
|
c001c883f7
|
Merge pull request #1714 from mandiant/fix/issue-1697-1
rule scoping tweaks
|
2023-08-15 10:16:01 +02:00 |
|
Willi Ballenthin
|
476c7ff749
|
main: provide encoding to open
fixes flake8 warning
|
2023-08-15 08:13:22 +00:00 |
|
Willi Ballenthin
|
4978aa74e7
|
tests: temporarily xfail script test
closes #1717
|
2023-08-15 08:13:14 +00:00 |
|
Yacine Elhamer
|
4411911664
|
Merge remote-tracking branch 'parentrepo/dynamic-feature-extraction' into fix/issue-1697-1
|
2023-08-15 09:57:13 +02:00 |
|
Yacine
|
0e1ce21488
|
Merge pull request #1715 from mandiant/fix/issue-1710
fix rendering of scope in vverbose mode
|
2023-08-15 09:51:53 +02:00 |
|
Yacine
|
88aa17fa7b
|
Merge pull request #1716 from mandiant/fix/issue-1697-2
remove dynamic return address concept
|
2023-08-15 08:55:12 +02:00 |
|
Willi Ballenthin
|
3169ee28e9
|
Merge pull request #1721 from mandiant/fix/issue-1704
elf: fix parsing of symtab from viv data
|
2023-08-14 17:13:50 +02:00 |
|
Willi Ballenthin
|
d648fdf6c0
|
Merge pull request #1713 from mandiant/fix/issue-1711
record and show the analysis flavor
|
2023-08-14 16:44:42 +02:00 |
|
Willi Ballenthin
|
3b9f5114ce
|
Merge pull request #1722 from mandiant/dependabot/pip/mypy-1.5.0
build(deps-dev): bump mypy from 1.4.1 to 1.5.0
|
2023-08-14 16:43:57 +02:00 |
|
dependabot[bot]
|
623fc270c1
|
build(deps-dev): bump mypy from 1.4.1 to 1.5.0
Bumps [mypy](https://github.com/python/mypy) from 1.4.1 to 1.5.0.
- [Commits](https://github.com/python/mypy/compare/v1.4.1...v1.5.0)
---
updated-dependencies:
- dependency-name: mypy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-08-14 14:43:40 +00:00 |
|
Willi Ballenthin
|
1199fb94d4
|
Merge pull request #1723 from mandiant/dependabot/pip/tqdm-4.66.1
build(deps-dev): bump tqdm from 4.65.0 to 4.66.1
|
2023-08-14 16:43:18 +02:00 |
|
Willi Ballenthin
|
26fdbbd442
|
Merge pull request #1725 from mandiant/dependabot/pip/ruff-0.0.284
build(deps-dev): bump ruff from 0.0.282 to 0.0.284
|
2023-08-14 16:42:26 +02:00 |
|
Willi Ballenthin
|
737fab7969
|
elf: use equality not bit masking
|
2023-08-14 16:40:45 +02:00 |
|
dependabot[bot]
|
f6ee465a0a
|
build(deps-dev): bump ruff from 0.0.282 to 0.0.284
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.0.282 to 0.0.284.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/BREAKING_CHANGES.md)
- [Commits](https://github.com/astral-sh/ruff/compare/v0.0.282...v0.0.284)
---
updated-dependencies:
- dependency-name: ruff
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-08-14 14:16:45 +00:00 |
|
dependabot[bot]
|
82f352f719
|
build(deps-dev): bump tqdm from 4.65.0 to 4.66.1
Bumps [tqdm](https://github.com/tqdm/tqdm) from 4.65.0 to 4.66.1.
- [Release notes](https://github.com/tqdm/tqdm/releases)
- [Commits](https://github.com/tqdm/tqdm/compare/v4.65.0...v4.66.1)
---
updated-dependencies:
- dependency-name: tqdm
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-08-14 14:16:16 +00:00 |
|
Yacine Elhamer
|
846bd62817
|
Merge remote-tracking branch 'parentrepo/dynamic-feature-extraction' into fix/issue-1711
|
2023-08-14 16:05:20 +02:00 |
|
Yacine
|
84cddc70fd
|
Merge pull request #1709 from mandiant/fix/issue-1702
fix rendering of call and return addresses
|
2023-08-14 16:00:16 +03:00 |
|
Willi Ballenthin
|
2dc5295c0c
|
Merge branch 'master' into fix/issue-1704
|
2023-08-14 13:15:23 +02:00 |
|
Willi Ballenthin
|
8479bc2f1f
|
Merge pull request #1720 from mandiant/fix/issue-1705
elf: detect Android OS via note and dependencies
|
2023-08-14 13:11:23 +02:00 |
|
Capa Bot
|
7c1522d84d
|
Sync capa-testfiles submodule
|
2023-08-14 11:11:05 +00:00 |
|
Willi Ballenthin
|
9afe19a096
|
changelog
|
2023-08-14 11:10:06 +00:00 |
|
Willi Ballenthin
|
bd5c65d22c
|
elf: fix parsing of symtab from viv
closes #1704
|
2023-08-14 11:08:19 +00:00 |
|
Willi Ballenthin
|
e6cb3d3b3b
|
os: detect Android via dependencies, too
|
2023-08-14 10:27:19 +00:00 |
|
Willi Ballenthin
|
18058beb0a
|
changelog
|
2023-08-14 10:20:30 +00:00 |
|
Willi Ballenthin
|
8003547414
|
elf: detect Android OS via note
closes #1705
|
2023-08-14 10:13:42 +00:00 |
|