CybOXProject / schemas

CybOX Schemas and Schema Development
42 stars 17 forks source link

Add Support for Characterizing Overlays as Part of Win Exec File Object #299

Open ikiril01 opened 10 years ago

ikiril01 commented 10 years ago

We should consider adding support for characterizing file overlays (data appended to the end of a PE file) as part of the Windows Executable File Object.

ikiril01 commented 9 years ago

Context: this is useful primarily for malware-related use cases, for more accurately characterizing the properties of a PE binary (i.e. in MAEC).

LOE: Low