Willi Ballenthin
db40d9bc7a
wip: add initial CAPE model
2023-08-15 11:41:11 +00:00
Willi Ballenthin
827b4b29b4
test_rules: fix rule scoping logic
2023-08-15 09:21:49 +00:00
Willi Ballenthin
2a31b16567
merge
2023-08-15 08:56:41 +00:00
Willi Ballenthin
c001c883f7
Merge pull request #1714 from mandiant/fix/issue-1697-1
...
rule scoping tweaks
2023-08-15 10:16:01 +02:00
Willi Ballenthin
4978aa74e7
tests: temporarily xfail script test
...
closes #1717
2023-08-15 08:13:14 +00:00
Willi Ballenthin
8479bc2f1f
Merge pull request #1720 from mandiant/fix/issue-1705
...
elf: detect Android OS via note and dependencies
2023-08-14 13:11:23 +02:00
Capa Bot
7c1522d84d
Sync capa-testfiles submodule
2023-08-14 11:11:05 +00:00
Willi Ballenthin
e6cb3d3b3b
os: detect Android via dependencies, too
2023-08-14 10:27:19 +00:00
Willi Ballenthin
8202e9e921
main: don't use analysis flavor to filter rules
...
im worried this will interact poorly with our rule cache,
unless we add more handling there, which needs more testing.
so, since the filtering likely has only a small impact on performance,
revert the rule filtering changes for simplicity.
2023-08-11 10:36:59 +00:00
Willi Ballenthin
6de23a9748
tests: main: demonstrate CAPE analysis (and bug #1702 )
2023-08-11 08:56:06 +00:00
Willi Ballenthin
1cf33e4343
tests: create workspaces only during tests, not import
...
closes #1707
2023-08-11 08:38:06 +00:00
Willi Ballenthin
34db63171f
sync submodule testfiles
2023-08-11 08:36:29 +00:00
Willi Ballenthin
c1fbb27d73
Merge branch 'master' into dynamic-feature-extraction
2023-08-10 13:21:49 +00:00
Capa Bot
e5efc158b7
Sync capa-testfiles submodule
2023-08-10 07:26:08 +00:00
Aayush Goel
232c9ce35c
Add test for script & output rendered
2023-08-07 22:43:25 +05:30
Willi Ballenthin
74d9b06835
Merge pull request #1679 from Aayush-Goel-04/Aayush-Goel-04/Issue#1582
...
bump pydantic to 2.1.1
2023-08-07 12:02:53 +02:00
Yacine Elhamer
aacd9f51b3
delete empty files
2023-08-07 09:48:11 +01:00
Yacine
95148d445a
test_rules.py: update rules' formatting
...
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com >
2023-08-07 09:47:57 +01:00
Yacine
65ac422e36
test_rules.py: update rules' fomratting
...
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com >
2023-08-07 09:47:37 +01:00
Willi Ballenthin
5ffb6ca0cd
Merge branch 'dynamic-feature-extraction' into call-scope
2023-08-07 10:40:53 +02:00
Willi Ballenthin
85f151303a
merge
2023-08-07 08:40:03 +00:00
Willi Ballenthin
216cd01b3c
sync test data submodule
2023-08-07 08:37:23 +00:00
Capa Bot
2c8f99143a
Sync capa-testfiles submodule
2023-08-05 16:40:13 +00:00
Capa Bot
ee68031d19
Sync capa-testfiles submodule
2023-08-05 16:37:46 +00:00
Yacine Elhamer
8dc4adbb5e
fix test_rules.py yaml identation bug
2023-08-04 16:20:37 +01:00
Yacine Elhamer
8b36cd1e35
add call-scope tests
2023-08-04 16:20:37 +01:00
Aayush Goel
2bed3468f6
bump pydantic to 2.1.1
2023-08-03 17:21:46 +05:30
Yacine Elhamer
ca2760fb46
Initial commit
2023-08-02 22:46:54 +01:00
Willi Ballenthin
727ece499a
Merge pull request #1662 from Aayush-Goel-04/Aayush-Goel-04/Issue#1607
...
ELF: Implement file import and export name extractor
2023-08-02 13:15:32 +02:00
Aayush Goel
62f50265bc
Resolved Import address
2023-08-02 16:41:24 +05:30
Capa Bot
d18224eac6
Sync capa-testfiles submodule
2023-08-02 11:03:16 +00:00
Aayush Goel
26935ee6e6
Update test_elffile_features.py
2023-08-02 13:51:51 +05:30
Aayush Goel
f8c499fb43
Added test for elf import/export handling
2023-08-02 11:52:27 +05:30
Capa Bot
d12185d851
Sync capa-testfiles submodule
2023-08-01 11:21:02 +00:00
Yacine Elhamer
462024ad03
update tests to explicitely specify scopes
2023-08-01 07:41:47 +01:00
Yacine Elhamer
3d812edc4d
use weakrefs for Scopes instantiation; fix test_rules()
2023-07-27 15:52:39 +01:00
Yacine Elhamer
16e32f8441
add tests
2023-07-27 10:31:45 +01:00
Xusheng
8f826cb92d
Fix binja backend stack string detection. Re-enable binja stack string unit test
2023-07-24 19:15:35 +08:00
Yacine Elhamer
ab585ef951
add the skipif mark back
2023-07-21 14:00:58 +01:00
Yacine Elhamer
b1e468dae4
add tests for the get_sample_hashes() method
2023-07-21 11:04:21 +01:00
Yacine Elhamer
6d1a885864
update static freeze test
2023-07-21 08:48:18 +01:00
Yacine Elhamer
d99b16ed5e
add copyright and remove old test
2023-07-20 21:41:16 +01:00
Yacine Elhamer
0a4fe58ac6
fix tests
2023-07-20 20:25:11 +01:00
Yacine Elhamer
8ac9caf45c
fix bugs
2023-07-20 20:20:33 +01:00
Yacine Elhamer
1029b369f2
Merge remote-tracking branch 'parentrepo/dynamic-feature-extraction' into find-dynamic-capabilities
2023-07-20 20:02:49 +01:00
Willi Ballenthin
a2f31ab8ae
update testfiles submodule
2023-07-20 11:52:15 +00:00
Willi Ballenthin
666c9c21a1
update testfiles submodule
2023-07-20 11:49:20 +00:00
Yacine Elhamer
16eab6b5e5
remove unused commit
2023-07-20 11:24:07 +01:00
Yacine Elhamer
d520bfc753
fix bugs and add copyrights
2023-07-20 11:19:54 +01:00
Yacine Elhamer
301b10d261
fix style issues
2023-07-20 10:52:43 +01:00