mandiant / mandiant/capa

Use same sample for Drakvuf and CAPE testing

Open
#2,180 0 comments 0 reactions 0 assignees View on GitHub
dynamic
Dominant language
Python
Stars
6.2k
Forks
726
Avg merge
11d 11h
Merged PRs (30d)
7

Description

CAPE and Drakvuf now use artifacts from different sample's reports to test their respective feature extractors. In the future we would like to use the same sample, analyze it with both CAPE and Drakvuf (and other future dynamic extractors), and use those reports for testing.

Contributor guide

Open the contributing guide

Research direction

Start by locating the CAPE and Drakvuf feature-extractor tests and their current report artifacts. Trace how each test selects its sample, then make the shared sample and reports cover both extractors; done when both test paths analyze the same sample and still validate their respective extractors.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
reverse-engineering, testing
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.