capa icon indicating copy to clipboard operation
capa copied to clipboard

Drakvuf Feature Extractor File Features

Open yelhamer opened this issue 8 months ago • 0 comments

This issue is for tracking any possible file features we could extract from Drakvuf reports.

Currently, most artifacts (registry keys, files, etc.) are collected by other Drakvuf plugins from the windows api/native calls, which makes them available at the file scope by default.

However, there are some other plugins supported by Drakvuf that might be interesting to look into and try to extract file features from.

yelhamer avatar Jun 25 '24 05:06 yelhamer