github mandiant/capa v3.1.0

latest releases: v7.2.0, v7.1.0, v7.0.1...
2 years ago

This release improves the performance of capa while also adding 23 new rules and many code quality enhancements. We profiled capa's CPU usage and optimized the way that it matches rules, such as by short circuiting when appropriate. According to our testing, the matching phase is approximately 66% faster than v3.0.3! We also added support for Python 3.10, aarch64 builds, and additional MAEC metadata in the rule headers.

This release adds 23 new rules, including nine by Jakub Jozwiak of Mandiant. @ryantxu1 and @dzbeck updated the ATT&CK and MBC mappings for many rules. Thank you!

And as always, welcome first time contributors!

New Features

Breaking Changes: None

New Rules (23)

Rule Changes

Bug Fixes

capa explorer IDA Pro plugin

Development

Raw diffs

Don't miss a new capa release

NewReleases is sending notifications on new releases.