Mike Hunhoff
Mike Hunhoff
@malwarefrank I've been working on a Python library that parses method body sections and CIL instructions using RVAs recovered by dnfile. Is there any interest in adding this level of...
Apologies for the delayed response. I've released the work I've been doing on CIL disassembly here: https://github.com/mandiant/dncil. The library supports parsing method body headers, instructions, and exception handlers. There is...
This sounds great. Please reach out if you have any questions or issues w/ dncil.
> Should we rebase this on top of master so that it doesn't depend on BinExport2? > > I'm inclined to say "yes" although we lose the intermediate history. This...
> ### lots of time spent in instancecheck > 5.5% of runtime is spent in `__instancecheck__`, including about 2.5% of _total runtime_ on the line here: data:image/s3,"s3://crabby-images/ad1ec/ad1ec7134c9b5ebd7d35c54f00575d06b35a44b4" alt="image" > > https://github.com/mandiant/capa/blob/824e8521845719d63d7ab06fb837f2bdbd951bf0/capa/features/common.py#L393...
@s-ff take a look at the research and discussion in this issue to get you thinking about our GSoC project. No action beyond reviewing (and posting any thoughts you have)...
> Hi :) I do give it a try, but im not sure will this work. I will test it soon. Here is my [fork](https://github.com/MYusufY/capa) if you want to test...