Skip to content

Releases: mandiant/capa

v7.0.1

02 Feb 10:23
2ddb6b0
Compare
Choose a tag to compare

This release fixes a circular import error when using capa as a library.

Bug Fixes

Raw diffs

v7.0.0

01 Feb 14:26
a3a8e36
Compare
Choose a tag to compare

This is the v7.0.0 release of capa which was mainly worked on during the Google Summer of Code (GSoC) 2023. A huge
shoutout to our GSoC contributors @colton-gabertan and @yelhamer for their amazing work. See our blog posts for more details:

Also, a big thanks to the other contributors: @aaronatp, @Aayush-Goel-04, @bkojusner, @doomedraven, @ruppde, @larchchen, @JCoonradt, and @xusheng6.

New Features

Breaking Changes

New Rules (41)

Bug Fixes

capa explorer IDA Pro plugin

  • various integration updates and minor bug fixes

Development

Developer Notes

With this new release, many classes and concepts have been split up into static (mostly identical to the
prior implementations) and dynamic ones. For example, the legacy FeatureExtractor class has been renamed to
StaticFeatureExtractor and the DynamicFeatureExtractor has been added.

Starting from version 7.0, we have moved the component responsible for feature extractor from main to a new
capabilities' module. Now, users wishing to utilize capa’s feature extraction abilities should use that module instead
of importing the relevant logic from the main file.

For sandbox-based feature extractors, we are using Pydantic models. Contributions of more models for other sandboxes
are very welcome!

With this release we've reorganized the logic found in main() to localize logic and ease readability and ease changes
and integrations. The new "main routines" are expected to be used only within main functions, either capa main or
related scripts. These functions should not be invoked from library code.

Beyond copying code around, we've refined the handling of the input file/format/backend. The logic for picking the
format and backend is more consistent. We've documented that the input file is not necessarily the sample itself
(cape/freeze/etc.) inputs are not actually the sample.

Raw diffs

v7.0.0-beta

24 Jan 13:59
85e1495
Compare
Choose a tag to compare
v7.0.0-beta Pre-release
Pre-release

This is the beta release of capa v7.0 which was mainly worked on during the Google Summer of Code (GSoC) 2023. A huge
shoutout to @colton-gabertan and @yelhamer for their amazing work.

Also a big thanks to the other contributors: @aaronatp, @Aayush-Goel-04, @bkojusner, @doomedraven, @ruppde, and @xusheng6.

New Features

Breaking Changes

  • remove the SCOPE_* constants in favor of the Scope enum #1764 @williballenthin
  • protobuf: deprecate RuleMetadata.scope in favor of RuleMetadata.scopes @williballenthin
  • protobuf: deprecate Metadata.analysis in favor of Metadata.analysis2 that is dynamic analysis aware @williballenthin
  • update freeze format to v3, adding support for dynamic analysis @williballenthin
  • extractor: ignore DLL name for api features #1815 @mr-tz

New Rules (41)

Bug Fixes

Development

Developer Notes

With this new release, many classes and concepts have been split up into static (mostly identical to the
prior implementations) and dynamic ones. For example, the legacy FeatureExtractor class has been renamed to
StaticFeatureExtractor and the DynamicFeatureExtractor has been added.

Starting from version 7.0, we have moved the component responsible for feature extractor from main to a new
capabilities' module. Now, users wishing to utilize capa’s feature extraction abilities should use that module instead
of importing the relevant logic from the main file.

For sandbox-based feature extractors, we are using Pydantic models. Contributions of more models for other sandboxes
are very welcome!

Raw diffs

v6.1.0

25 Aug 09:12
9d21add
Compare
Choose a tag to compare

capa v6.1.0 is a bug fix release, most notably fixing unhandled exceptions in the capa explorer IDA Pro plugin. @Aayush-Goel-04 put a lot of effort into improving code quality and adding a script for rule authors. The script shows which features are present in a sample but not referenced by any existing rule. You could use this script to find opportunities for new rules.

Speaking of new rules, we have eight additions, coming from Ronnie, Jakub, Moritz, Ervin, and still@teamt5.org!

New Features

New Rules (8)

Modified rules (9)

Renamed rules (1)

Bug Fixes

capa explorer IDA Pro plugin

EDIT: a standalone binary created using Python 3.11 is now available.

Raw diffs

v6.0.0

18 Jul 16:29
781c33d
Compare
Choose a tag to compare

v6.0.0

capa v6.0 brings many bug fixes and quality improvements, including 64 rule updates and 26 new rules. We're now publishing to PyPI via Trusted Publishing and have migrated to using a pyproject.toml file. @Aayush-Goel-04 contributed a lot of new code across many files, so please welcome them to the project, along with @anders-v @crowface28 @dkelly2e @RonnieSalomonsen and @ejfocampo as first-time rule contributors!

For those that use capa as a library, we've introduced some limited breaking changes that better represent data types (versus less-structured data like dictionaries and strings). With the recent deprecation, we've also dropped support for Python 3.7.

New Features

Breaking Changes

New Rules (26)

Bug Fixes

  • extractor: add a Binary Ninja test that asserts its version #1487 @xusheng6
  • extractor: update Binary Ninja stack string detection after the new constant outlining feature #1473 @xusheng6
  • extractor: update vivisect Arch extraction #1334 @mr-tz
  • extractor: avoid Binary Ninja exception when analyzing certain files #1441 @xusheng6
  • symtab: fix struct.unpack() format for 64-bit ELF files @yelhamer
  • symtab: safeguard against ZeroDivisionError for files containing a symtab with a null entry size @yelhamer
  • improve ELF strtab and needed parsing @mr-tz
  • better handle exceptional cases when parsing ELF files #1458 @Aayush-Goel-04
  • improved testing coverage for Binary Ninja backend #1446 @Aayush-Goel-04
  • add logging and print redirect to tqdm for capa main #749 @Aayush-Goel-04
  • extractor: fix binja installation path detection does not work with Python 3.11
  • tests: refine the IDA test runner script #1513 @williballenthin
  • output: don't leave behind traces of progress bar @williballenthin
  • import-to-ida: fix bug introduced with JSON report changes in v5 #1584 @williballenthin
  • main: don't show spinner when emitting debug messages #1636 @williballenthin

capa explorer IDA Pro plugin

Development

Raw diffs

v5.1.0

06 Apr 11:11
7c4a46b
Compare
Choose a tag to compare

capa version 5.1.0 adds a Protocol Buffers (protobuf) format for result documents. Additionally, the Vector35 team contributed a new feature extractor using Binary Ninja. Other new features are a new CLI flag to override the detected operating system, functionality to read and render existing result documents, and a output color format that's easier to read.

Over 25 capa rules have been added and improved.

Thanks for all the support, especially to @xusheng6, @captainGeech42, @ggold7046, @manasghandat, @ooprathamm, @linpeiyu164, @yelhamer, @HongThatCong, @naikordian, @stevemk14ebr, @emtuls, @raymondlleong, @bkojusner, @joren485, and everyone else who submitted bugs and provided feedback!

New Features

New Rules (26)

Bug Fixes

  • extractor: removed '.dynsym' as the library name for ELF imports #1318 @stevemk14ebr
  • extractor: fix vivisect loop detection corner case #1310 @mr-tz
  • match: extend OS characteristic to match OS_ANY to all supported OSes #1324 @mike-hunhoff
  • extractor: fix IDA and vivisect string and bytes features overlap and tests #1327 #1336 @xusheng6

capa explorer IDA Pro plugin

Raw diffs

v5.0.0

08 Feb 20:37
c2346f4
Compare
Choose a tag to compare

This capa version comes with major improvements and additions to better handle .NET binaries. To showcase this we've updated and added over 30 .NET rules.

Additionally, capa now caches its rule set for better performance. The capa explorer also caches its analysis results, so that multiple IDA Pro or plugin invocations don't need to repeat the same analysis.

We have removed the SMDA backend and changed the program return codes to be positive numbers.

Other improvements to highlight include better ELF OS detection, various rendering bug fixes, and enhancements to the feature extraction. We've also added support for Python 3.11.

Thanks for all the support, especially to @jsoref, @bkojusner, @edeca, @richardweiss80, @joren485, @ryantxu1, @mwilliams31, @anushkavirgaonkar, @MalwareMechanic, @Still34, @dzbeck, @johnk3r, and everyone else who submitted bugs and provided feedback!

New Features

Breaking Changes

New Rules (77)

Bug Fixes

capa explorer IDA Pro plugin

Raw diffs

v4.0.1

15 Aug 11:28
3c41415
Compare
Choose a tag to compare

Some rules contained invalid metadata fields that caused an error when rendering rule hits. We've updated all rules and enhanced the rule linter to catch such issues.

New Rules (1)

Bug Fixes

  • linter: use pydantic to validate rule metadata #1141 @mike-hunhoff
  • build binaries using PyInstaller no longer overwrites functions in version.py #1136 @mr-tz

Raw diffs

v4.0.0

10 Aug 13:36
81cb4b3
Compare
Choose a tag to compare

Version 4 adds support for analyzing .NET executables. capa will autodetect .NET modules, or you can explicitly invoke the new feature extractor via --format dotnet. We've also extended the rule syntax for .NET features including namespace and class.

Additionally, new instruction scope and operand features enable users to create more explicit rules. These features are not backwards compatible. We removed the previously used /x32 and /x64 flavors of number and operand features.

We updated 49 existing rules and added 22 new rules leveraging these new features and characteristics to detect capabilities seen in .NET malware.

More breaking changes include updates to the JSON results document, freeze file format schema (now format version v2), and the internal handling of addresses.

Thanks for all the support, especially to @htnhan, @jtothej, @sara-rn, @anushkavirgaonkar, and @_re_fox!

Deprecation warning: v4.0 will be the last capa version to support the SMDA backend.

New Features

Breaking Changes

  • instruction scope and operand feature are new and are not backwards compatible with older versions of capa
  • Python 3.7 is now the minimum supported Python version #866 @williballenthin
  • remove /x32 and /x64 flavors of number and operand features #932 @williballenthin
  • the tool now accepts multiple paths to rules, and JSON doc updated accordingly @williballenthin
  • extractors must use handles to identify functions/basic blocks/instructions #981 @williballenthin
  • the freeze file format schema was updated, including format version bump to v2 #986 @williballenthin

Deprecation notice: as described in #937, we plan to remove the SMDA backend for v5. If you rely on this backend, please reach out so we can discuss extending the support for SMDA or transitioning your workflow to use vivisect.

New Rules (30)

Bug Fixes

capa explorer IDA Pro plugin

Raw diffs

v3.2.1

06 Jul 20:49
Compare
Choose a tag to compare

This release bumps the SMDA dependency version to enable installation on Python 3.10.

Bug Fixes

Raw diffs