mandiant / mandiant/capa

Request for Data Examples from capa, capa web app, CAPE -> capa, and Ghidra -> capa

Open
#2,720 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
6.2k
Forks
726
Avg merge
11d 11h
Merged PRs (30d)
7

Description

Hi,

Sorry for the noob question, but our group is building an open-source, low-code Stix incident system, and we want to convert capa output from 4 scenarios directly into a Stix incident using an api. Can you help with data please?

### Background
Our low-code system supports both Jupyter notebooks, and the loading of 3rd party services in sandboxes, including use of virtualbox.

We came across your extraordinary open tools through working with the OCA (Open Cybersecurity Alliance) IoB (Indicators of Behavior) group, who want to use your tools to support publishing CACAO playbook responses to malware. Through them we were introduced to capa, and some web searching found your details on the capa web app, your integration with CAPEv2, and your integration with Ghidra.

I think it is very impressive how your capa system can report on ATT&CK TTP's and Malware MBC OBM's found in the binary, and even better you can convert analysis from dynamic and reverse engineering tools. Congratulations.

Our backend StixORM is currently being upgraded so it can load all 3 ATT&CK frameworks, the Malware MBC framework and the Mitre Atlas framework. We are currently modifying the Attack Navigator so it can take in the Malware MBC, so malware people can review any of these OBM's (i.e. a Malware Navigator).

We have even built a [workflow document, that shows (roughly) how users might use any of four tools to research malware and convert the results into a Stix Incident](https://docs.google.com/document/d/1caVj0XjnM3G4MFP_x8sf_axccoTm5tcQfzuo4p6k1_8/edit?usp=sharing):

1. capa in our Jupyter notebooks -> capa report
2. capa web app -> capa report
3. CAPEv2 -> capa report
4. Ghidra -> capa report

We would like to give this whole setup some love, so malware researchers globally can find it easy to analyse malware using your tools, and then import that capa report directly into a Stix Incident.

## Details

We don't currently have the resources to load and test malware ourselves, as we are not funded. Is it possible to get at least 2 verbose reports for each scenario please so we can setup the api using actual data? In short some (2 or more) verbose report examples for each of:

1. capa in our Jupyter notebooks -> capa report
2. capa web app -> capa report
3. CAPEv2 -> capa report
4. Ghidra -> capa report

I apologise I am not technically skilled enough to do it myself, but it would be great if you would help out. We really want to make our tool great for malware dudes, using your brilliant work.

Please help, thanks a lot

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The request names no repository files, tests, or entry points; start by reviewing the issue's four requested scenarios and the linked workflow document. Done would require determining whether the project can provide at least two verbose reports for each scenario, or clarifying what repository contribution is expected.

Written by the indexing model from the issue text.

Assessment

Tech stack
jupyter, python
Domain
documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.