mandiant / capa

The FLARE team's open-source tool to identify capabilities in executable files.
Apache License 2.0
3.98k stars 499 forks source link

Use same sample for Drakvuf and CAPE testing #2180

Open yelhamer opened 6 days ago

yelhamer commented 6 days ago

CAPE and Drakvuf now use artifacts from different sample's reports to test their respective feature extractors. In the future we would like to use the same sample, analyze it with both CAPE and Drakvuf (and other future dynamic extractors), and use those reports for testing.