1 रिपॉजिटरी
Limits analysis to specific processes by PID when processing dynamic sandbox reports.
Distinct from GPU Process Analysis: Distinct from GPU Process Analysis: focuses on scoping sandbox report analysis by PID, not GPU resource profiling.
Explore 1 awesome GitHub repository matching testing & quality assurance · Process-Scoped Sandbox Analysis. Refine with filters or upvote what's useful.
capa is a binary capability scanner that identifies high-level behaviors and actions an executable can perform, such as network communication or file manipulation. It functions as a malware behavior analysis tool and a MITRE ATT&CK mapping framework, scanning PE, ELF, .NET, and shellcode files through both static analysis and dynamic sandbox report processing. The tool distinguishes itself through a YAML-based detection rule engine that defines detection logic in human-readable files, with conditions expressed as feature combinations and logical operators. It integrates with IDA Pro, Ghidra,
Limits analysis to specific processes by PID when processing dynamic sandbox reports.