mandiant / mandiant/capa

Discrepancy in capa analysis results between `vivisect` and `IDA` backends

Open
#2,664 3 comments 0 reactions 0 assignees View on GitHub
bug question
Dominant language
Python
Stars
6.2k
Forks
726
Avg merge
11d 11h
Merged PRs (30d)
7

Description

### Description

When running `capa` with both the `vivisect` and `IDA` backends via the CLI on the same binary, Vivisect successfully identifies AES-related functionality while the IDA backend fails to detect the same capabilities.
Additionally, when using the `-d` flag, Vivisect extracts more features than IDA, which may contribute to the discrepancy in capability matches.
### Steps to Reproduce

1. Run `capa` on the same binary using both Vivisect and IDA backends:
```
capa -b vivisect path\to\binary -d
capa -b ida path\to\binary -d
```
2. Observe the difference in AES-related matches and feature extraction between the two backends.

**Expected behavior:**
Both backends should ideally extract similar features and identify the same capabilities, especially common ones like AES encryption.

**Actual behavior:**
vivisect backend detects the following AES-related capabilities:
```
encrypt data using AES (2 matches)
namespace data-manipulation/encryption/aes
scope function
matches 0x180001614
0x18000209C

reference AES constants (2 matches)
namespace data-manipulation/encryption/aes
scope function
matches 0x180001614
0x18000209C
```

### Versions

- capa version: 9.1.0

- IDA version: 9.0.20241216

- OS: Windows 10

- SHA256: `c0e4894f3a0d23d0d47b0c270ceeb78543f775abaf013b33de8b1d3cd46e0ed8`

Contributor guide

Open the contributing guide

Research direction

Reproduce the discrepancy with the two capa CLI commands in the issue against the referenced binary, comparing Vivisect and IDA output with -d. Trace how each backend extracts features and matches the AES capabilities; done means the backend behavior is reconciled or the remaining difference is clearly explained and covered by an appropriate regression check.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.