Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

discussion: capa doesn't handle sandbox or API traces #48

Closed
williballenthin opened this issue Jun 30, 2020 · 9 comments
Closed

discussion: capa doesn't handle sandbox or API traces #48

williballenthin opened this issue Jun 30, 2020 · 9 comments

Comments

@williballenthin
Copy link
Collaborator

capa relies on analysis of code structures to identify patterns. this is similar to matching sequences of API calls or other events in a sandbox, but not exactly. right now, capa rules don't directly translate to identifying behaviors from sandbox or debugging output, but it seems like there's a lot of overlap. maybe we can find a way to re-use a lot of work we've done for the static analysis rules.

@musaabimran
Copy link

Hey, I am interested in this project. How can I get started with this?

@mr-tz
Copy link
Collaborator

mr-tz commented Mar 1, 2023

@musaabimran
Copy link

Yes, I am. So, should I send the proposal regarding my approach?

@mr-tz
Copy link
Collaborator

mr-tz commented Mar 2, 2023

Yes, and please see the other steps we point out, i.e., the patch preparation.

@1nf3rn0-H
Copy link
Contributor

Even I am interested, I'll send the proposal right away!

@1nf3rn0-H
Copy link
Contributor

Hey @mr-tz I am interested to work on this. I have prepared my GSoC proposal, can you review it once?

@mr-tz
Copy link
Collaborator

mr-tz commented Mar 16, 2023

Great, yes, please share it with us in the respective GSOC repo discussion or via email. Ideally, use Google Docs or a similar tool so we can add comments.

@1nf3rn0-H
Copy link
Contributor

Alright, I have sent it over email, do check and review!

@williballenthin
Copy link
Collaborator Author

closed in v7 by @yelhamer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants