mandiant / mandiant/capa-rules

discussion: organizing Android/mobile focused capa rules

Open
#850 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

Collecting my thoughts here but happy to spin off separate issues/discussions.

- I like the `in .NET on Android` naming
- so far rules are inconsistent requiring format/os
- this doesn't seem to be a problem though
- important are:
- rule readability and
- organization
- 1. duplicate all directories under `android` parent?
- 2. only update namespaces to start with `android/` root <-- my preferred option
- testfiles should go into `android` directory

related discussion: https://github.com/mandiant/capa/discussions/701 (Rule organization for multiple file types PE and ELF)

_Originally posted by @mr-tz in https://github.com/mandiant/capa-rules/issues/824#issuecomment-1757162927_

Contributor guide

Open the contributing guide

Research direction

Start with the rule directories and testfiles referenced in the discussion, then read the related discussion on rule organization for multiple file types. Compare duplicating directories under an android parent with updating namespaces to use an android/ root. Done requires an agreed organization for Android/mobile rules and placement of their testfiles.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
mobile-dev
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.