e-m-b-a / emba

EMBA - The firmware security analyzer
https://www.securefirmware.de
GNU General Public License v3.0
2.49k stars 223 forks source link

New capa (identify capabilities in executable files) module with ATT&CK support (S18) #1212

Open m-1-k-3 opened 5 days ago

m-1-k-3 commented 5 days ago

feature

As we have learned from the paper "ERS0: Enhancing Military Cybersecurity with AI-Driven SBOM for Firmware Vulnerability Detection and Asset Management" (see here) there might be some interest in using capa in EMBA. We are aware that capa is only supporting x86/64 architectures and so it is somehow limited in the firmware field. Nevertheless, if we have a supported architecture the results are quite useful:

image

The image shows also the links to the ATT&CK framework and to the MBCProject

~Do not merge until we have the docker base image updated!~

m-1-k-3 commented 4 days ago

New container (v1.4.1e) should be available for testing now