Closed s-ff closed 4 months ago
Hi @mike-hunhoff,
I have run the test_ida_features.py test script using the following steps:
pip install .
to install flare-capa
with my changes.capa_explorer.py
to IDA plugins folder.mimikatz.exe_
is loaded in IDA, I ran the script using : File > Script file... (or Alt+F7) Hi @mike-hunhoff,
Good point - ida_bytes.parse_bin_pat_str
does indeed change the first input passed to it. Thus, it doesn't make sense decalring a global variable IDA_BYTES_PATTERNS
. On the other hand ida_nalt.get_default_encoding_idx(ida_nalt.BPU_1B)
could be used a global variable for reuse.
Here is a snippet demonstrating this case:
Please let me know if you need anything else before you merge this.
This change closes #1606 by replacing the deprecated IDA API
find_binary
withbin_search
.Checklist