mandiant / mandiant/capa

explorer: add option to cancel file feature extraction

Open
#693 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug ida-explorer
Dominant language
Python
Stars
6.2k
Forks
726
Avg merge
11d 11h
Merged PRs (30d)
7

Description

Enable users to cancel capa explorer analysis during file feature extraction step. This really only matters for very large files with a lot of file features.

Presently capa explorer displays a Cancel button but clicking it does nothing because we are not tracking individual extraction steps like we do while extracting function/basic block features. We will need to add this capability in order for users to be able to cancel.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in the capa explorer analysis flow at the file feature extraction step, comparing it with the existing function and basic-block extraction cancellation path. Check how the displayed Cancel button is wired; done means cancellation interrupts extraction for large files and the explorer stops cleanly.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
reverse-engineering
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.