Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New capa (identify capabilities in executable files) module with ATT&CK support (S18) #1212

Open
wants to merge 9 commits into
base: master
Choose a base branch
from

Conversation

m-1-k-3
Copy link
Member

@m-1-k-3 m-1-k-3 commented Jul 1, 2024

  • What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)

feature

  • What is the current behavior? (You can also link to an open issue here)

As we have learned from the paper "ERS0: Enhancing Military Cybersecurity with AI-Driven SBOM for Firmware Vulnerability Detection and Asset Management" (see here) there might be some interest in using capa in EMBA. We are aware that capa is only supporting x86/64 architectures and so it is somehow limited in the firmware field. Nevertheless, if we have a supported architecture the results are quite useful:

image

The image shows also the links to the ATT&CK framework and to the MBCProject

  • Other information:

Do not merge until we have the docker base image updated!

@m-1-k-3 m-1-k-3 added enhancement New feature or request in progress Someone is working on this Core modules (Sxx) The core scanning modules (Sxx modules) EMBA labels Jul 1, 2024
@m-1-k-3
Copy link
Member Author

m-1-k-3 commented Jul 2, 2024

New container (v1.4.1e) should be available for testing now

@m-1-k-3 m-1-k-3 changed the title Capa module (S18) New capa module with ATT&CK support (S18) Jul 2, 2024
@m-1-k-3 m-1-k-3 marked this pull request as ready for review July 2, 2024 18:37
@m-1-k-3 m-1-k-3 changed the title New capa module with ATT&CK support (S18) New capa (identify capabilities in executable files) module with ATT&CK support (S18) Jul 2, 2024
@m-1-k-3 m-1-k-3 removed the in progress Someone is working on this label Jul 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Core modules (Sxx) The core scanning modules (Sxx modules) EMBA enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant