Closed mike-hunhoff closed 6 months ago
We should change the order used to yield multiple formats for .NET files so FORMAT_DOTNET is used for capa's output metadata.
FORMAT_DOTNET
https://github.com/mandiant/capa/blob/49231366f1cbb800f296c60a2cb99f97466e2e33/capa/features/extractors/dotnetfile.py#L51-L53
This order doesn't matter for matching but does matter when collecting the file's metadata because we default to the first in the list
https://github.com/mandiant/capa/blob/49231366f1cbb800f296c60a2cb99f97466e2e33/capa/loader.py#L385-L387
Alternatively, display all formats.
Hi @mr-tz , can i take this issue :)
of course
We should change the order used to yield multiple formats for .NET files so
FORMAT_DOTNET
is used for capa's output metadata.https://github.com/mandiant/capa/blob/49231366f1cbb800f296c60a2cb99f97466e2e33/capa/features/extractors/dotnetfile.py#L51-L53
This order doesn't matter for matching but does matter when collecting the file's metadata because we default to the first in the list
https://github.com/mandiant/capa/blob/49231366f1cbb800f296c60a2cb99f97466e2e33/capa/loader.py#L385-L387