mandiant / mandiant/capa

dynamic: vmray: add support for "array" function call parameters

Open
#2,246 0 comments 0 reactions 0 assignees View on GitHub
dynamic enhancement vmray
Dominant language
Python
Stars
6.2k
Forks
726
Avg merge
11d 11h
Merged PRs (30d)
7

Description

The "array" type roughly maps to series of bytes and integers. We must first determine if capa can emit features from arrays without polluting the matches.

e.g.

```xml
[...]








[...]
```

Contributor guide

Open the contributing guide

Research direction

Start by locating the dynamic VMRay XML parsing entry point; the issue names no file or test. Use the provided array member example to determine whether array values should produce capa features without polluting matches. Done means array function-call parameters are handled with agreed feature behavior and covered by tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
reverse-engineering
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.