Giter VIP home page Giter VIP logo

Comments (5)

Maijin avatar Maijin commented on June 12, 2024

Adding a warning in the tool but also a warning in the README would be awesome!

from capa.

mr-tz avatar mr-tz commented on June 12, 2024

Notes on current limitations can be found at https://github.com/fireeye/capa/blob/master/doc/limitations.md

from capa.

mr-tz avatar mr-tz commented on June 12, 2024

From the SANS DFIR chat:

Dr. Pepper
Is it possible to write a decryptor/unpacker for capa? For example if a binary uses aplib, could we write something for capa to automatically decompress and run the rest of the rules on that data?

We have ideas for some method of auto-unpack to deal with common packers (UPX, ASPack, etc) and an integration is definitely worth exploring further.

from capa.

Maijin avatar Maijin commented on June 12, 2024

Kewl, nice for the limitations.md!

from capa.

williballenthin avatar williballenthin commented on June 12, 2024

we've documented the limitations and emit warnings when encountering packed files. we are no longer considering building an unpacker into capa - its a large amount of effort that will still fail pretty often.

unpacking is left to the user; however, capa should still recommend unpacking techniques when it can.

from capa.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.