Skip to content

Conversation

m-1-k-3
Copy link
Member

@m-1-k-3 m-1-k-3 commented Jul 1, 2024

  • What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)

feature

  • What is the current behavior? (You can also link to an open issue here)

As we have learned from the paper "ERS0: Enhancing Military Cybersecurity with AI-Driven SBOM for Firmware Vulnerability Detection and Asset Management" (see here) there might be some interest in using capa in EMBA. We are aware that capa is only supporting x86/64 architectures and so it is somehow limited in the firmware field. Nevertheless, if we have a supported architecture the results are quite useful:

image

The image shows also the links to the ATT&CK framework and to the MBCProject

  • Other information:

Do not merge until we have the docker base image updated!

@m-1-k-3 m-1-k-3 added enhancement New feature or request in progress Someone is working on this Core modules (Sxx) The core scanning modules (Sxx modules) EMBA labels Jul 1, 2024
@m-1-k-3
Copy link
Member Author

m-1-k-3 commented Jul 2, 2024

New container (v1.4.1e) should be available for testing now

@m-1-k-3 m-1-k-3 changed the title Capa module (S18) New capa module with ATT&CK support (S18) Jul 2, 2024
@m-1-k-3 m-1-k-3 marked this pull request as ready for review July 2, 2024 18:37
@m-1-k-3 m-1-k-3 changed the title New capa module with ATT&CK support (S18) New capa (identify capabilities in executable files) module with ATT&CK support (S18) Jul 2, 2024
@m-1-k-3 m-1-k-3 removed the in progress Someone is working on this label Jul 2, 2024
@m-1-k-3 m-1-k-3 merged commit b327511 into e-m-b-a:master Jul 8, 2024
@m-1-k-3 m-1-k-3 deleted the white_rabbit branch February 13, 2025 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Core modules (Sxx) The core scanning modules (Sxx modules) EMBA enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant