Open s-ff opened 3 months ago
I think this requires regenerating the files in tests/data/rd/
Should be good to go once https://github.com/mandiant/capa-testfiles/pull/239 is merged.
Stepping back here for a moment, let's consider if we want to implement this differently:
characteristic
s: few imports
, few detected library functions
has_file_limitation
or similarThat way we can handle the various limitations/warnings consistently. The core extraction logic still resides in capa but we don't have to extend the meta data.
Related: should we provide functionality to easier leverage this in other tools? Right now other tools need to reimplement the logic we have in capa.main
to handle special cases/detections.
@mr-tz this would require many fewer breaking changes, which i like
Closes #857.
This commit introduces two new metadata fields to result_document. Would this be considered a breaking change?
This would require regenrating the rdoc test files. see https://github.com/mandiant/capa-testfiles/pull/239.
Checklist