Willi Ballenthin
|
d4b83e3f8a
|
ci: pyinstaller: update to use ubuntu 20.04 for building linux
executables
|
2023-04-03 17:39:43 +02:00 |
|
Willi Ballenthin
|
efcc2e0dd4
|
elf: remove old print statement
|
2023-04-03 16:13:28 +02:00 |
|
Willi Ballenthin
|
5e0d6176a1
|
elf: parse associated strtab for symtab
|
2023-04-03 16:09:14 +02:00 |
|
Willi Ballenthin
|
e240372a90
|
result document: document subscope/match handling
|
2023-04-03 15:37:46 +02:00 |
|
Willi Ballenthin
|
a64a88981f
|
tests: add another test demonstrating rd format output
|
2023-04-03 15:35:20 +02:00 |
|
Willi Ballenthin
|
bc8df09be5
|
result document: more deserialization
|
2023-04-03 15:27:48 +02:00 |
|
Willi Ballenthin
|
b09e3e69f2
|
wip: result document: deserialize into capa object instances
|
2023-04-03 15:04:15 +02:00 |
|
Willi Ballenthin
|
43128404be
|
elf: remove old debugging code
|
2023-04-03 15:04:00 +02:00 |
|
Willi Ballenthin
|
28e85aa548
|
main: mypy
|
2023-04-03 13:48:30 +02:00 |
|
Willi Ballenthin
|
30c14210ed
|
main: better separate logic for deserializing result/freeze/other
|
2023-04-03 13:44:19 +02:00 |
|
Willi Ballenthin
|
d2fc740278
|
result document: mypy
|
2023-04-03 13:44:09 +02:00 |
|
Willi Ballenthin
|
3f5d9c79f9
|
elf: add type hints and Symbol dataclass
|
2023-04-03 13:30:02 +02:00 |
|
Willi Ballenthin
|
59332c2e94
|
tests: fixtures: add paths for new ELF test file
|
2023-04-03 13:16:03 +02:00 |
|
Willi Ballenthin
|
d230780443
|
pep8
|
2023-04-03 13:00:02 +02:00 |
|
Willi Ballenthin
|
7387c073fb
|
Merge pull request #1412 from manasghandat/fix-shadowed-variable
Fix shadowed variable
|
2023-04-03 12:58:15 +02:00 |
|
Willi Ballenthin
|
535ba622ae
|
Merge pull request #1422 from yelhamer/feature-symtab-os-guess
ELF OS detection: add support for guessing that's based on .symtab entries
|
2023-04-03 08:41:47 +02:00 |
|
Capa Bot
|
c6b634f3ae
|
Sync capa-testfiles submodule
|
2023-04-03 06:41:30 +00:00 |
|
Willi Ballenthin
|
386baec3c5
|
elf: hints and formatting
|
2023-04-03 08:40:41 +02:00 |
|
Yacine Elhamer
|
b2ead45ad4
|
tests: Add test for sample 2bf18d
|
2023-04-02 21:57:22 +01:00 |
|
Yacine Elhamer
|
74284e9dad
|
bugfix: potential reference to uninitialized variables
|
2023-04-02 21:56:28 +01:00 |
|
Yacine Elhamer
|
270077bc73
|
SymTab class: update get_symbols() type and add return-value comment
|
2023-04-02 20:59:09 +01:00 |
|
Yacine Elhamer
|
367a0c483c
|
rename the SYMTAB class to SymTab
|
2023-04-02 20:49:58 +01:00 |
|
Yacine Elhamer
|
8a272e92c7
|
format: removed tabs
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-04-02 20:38:44 +01:00 |
|
Yacine Elhamer
|
2d1105dba9
|
format: update elf.py to use isort and black format
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-04-02 20:36:34 +01:00 |
|
Yacine Elhamer
|
c798996f6e
|
detect_elf_os(): Integrate symbol-based guessing ability
|
2023-04-02 18:11:11 +01:00 |
|
Yacine Elhamer
|
ef0e4bd4fd
|
os-guessing: Add symtab-guessing capability
|
2023-04-02 18:07:46 +01:00 |
|
Yacine Elhamer
|
bfaee2c402
|
Add a class (SYMTAB) for the symbol table
|
2023-04-02 18:07:46 +01:00 |
|
Yacine Elhamer
|
1f6cd807a4
|
Shdr dataclass: add sh_entsize member
|
2023-04-02 18:07:22 +01:00 |
|
Willi Ballenthin
|
6f416dfefb
|
Merge pull request #1418 from stevemk14ebr/master
Remove dynsym library name for ELF imports
|
2023-04-01 13:54:07 +02:00 |
|
Capa Bot
|
06c71a7f2b
|
Sync capa rules submodule
|
2023-03-31 17:40:58 +00:00 |
|
Stephen Eckels
|
270350f8d1
|
Update CHANGELOG.md
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-03-31 13:26:41 -04:00 |
|
Stephen Eckels
|
c603b92bc5
|
Merge branch 'master' of https://github.com/stevemk14ebr/capa
|
2023-03-31 13:25:45 -04:00 |
|
Stephen Eckels
|
59be399dac
|
Revert line removal
|
2023-03-31 13:25:37 -04:00 |
|
Capa Bot
|
7f39cb1bc3
|
Sync capa rules submodule
|
2023-03-31 14:03:51 +00:00 |
|
manasghandat
|
d09e1c8ee2
|
fix linting error
|
2023-03-31 12:29:26 +05:30 |
|
manasghandat
|
c1735b6033
|
Merge branch 'mandiant:master' into fix-shadowed-variable
|
2023-03-31 12:27:43 +05:30 |
|
Stephen Eckels
|
1921961cff
|
Update todo comment to link issue
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-03-30 13:23:29 -04:00 |
|
Stephen Eckels
|
3cd766630f
|
Update changelog
|
2023-03-30 13:21:37 -04:00 |
|
manasghandat
|
fac548a76e
|
Update capa/render/proto/__init__.py
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-03-30 22:51:17 +05:30 |
|
manasghandat
|
24f4ebef23
|
Update capa/render/proto/__init__.py
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-03-30 22:51:07 +05:30 |
|
Willi Ballenthin
|
99ee317fd0
|
Merge pull request #1396 from ooprathamm/read-render
Towards improving read and rendering of results
|
2023-03-30 13:03:27 +02:00 |
|
Pratham Chauhan
|
456f6e0003
|
fix broken arch logic
|
2023-03-30 16:18:52 +05:30 |
|
Willi Ballenthin
|
1ccd2c4d0f
|
tests: fix proto tests on windows (#1417)
closes #1416
|
2023-03-30 11:45:03 +02:00 |
|
Willi Ballenthin
|
f42b5b1088
|
Merge pull request #1409 from mandiant/dependabot/pip/protobuf-4.22.1
build(deps): bump protobuf from 4.21.12 to 4.22.1
|
2023-03-30 11:17:14 +02:00 |
|
Pratham Chauhan
|
1b90a28acd
|
resolved merge conflicts
|
2023-03-30 11:05:32 +05:30 |
|
Pratham Chauhan
|
cd0e0ce4d1
|
remove unused import
|
2023-03-30 10:52:05 +05:30 |
|
Pratham Chauhan
|
7cb4ea9273
|
Fix lint issues
|
2023-03-30 10:35:31 +05:30 |
|
Stephen Eckels
|
66e374a343
|
Update changelog
|
2023-03-29 16:01:31 -04:00 |
|
Stephen Eckels
|
5e8262d3c0
|
Remove dynsym from elf entirely
|
2023-03-29 15:58:16 -04:00 |
|
Willi Ballenthin
|
6bb14d0874
|
Merge pull request #1415 from mandiant/f-strings
use f-strings as appropriate
|
2023-03-29 20:47:12 +02:00 |
|