mandiant / mandiant/capa-rules
discussion: organizing Android/mobile focused capa rules
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
Collecting my thoughts here but happy to spin off separate issues/discussions.
- I like the `in .NET on Android` naming
- so far rules are inconsistent requiring format/os
- this doesn't seem to be a problem though
- important are:
- rule readability and
- organization
- 1. duplicate all directories under `android` parent?
- 2. only update namespaces to start with `android/` root <-- my preferred option
- testfiles should go into `android` directory
related discussion: https://github.com/mandiant/capa/discussions/701 (Rule organization for multiple file types PE and ELF)
_Originally posted by @mr-tz in https://github.com/mandiant/capa-rules/issues/824#issuecomment-1757162927_
Contributor guide
Research direction
Start with the rule directories and testfiles referenced in the discussion, then read the related discussion on rule organization for multiple file types. Compare duplicating directories under an android parent with updating namespaces to use an android/ root. Done requires an agreed organization for Android/mobile rules and placement of their testfiles.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android
- Domain
- mobile-dev
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100