Commit Graph

35 Commits

Author SHA1 Message Date
Willi Ballenthin 88c9c786ca *: use meta.authors everywhere 2022-05-26 11:56:31 -06:00
idiom d9dfb69125 Update references to define it as a list of related information. 2022-05-11 10:47:15 -04:00
William Ballenthin 6728fb0d5a Revert "call $+5 update rule and doc"
This reverts commit c5368ed9a2.
2022-04-27 06:28:04 -06:00
William Ballenthin 056a6c2f28 Revert "Merge pull request #549 from mandiant/feature-doc-updates"
This reverts commit afd356e046, reversing
changes made to 9967d225a6.
2022-04-27 05:34:39 -06:00
Willi Ballenthin 79f7012aa9 format: remove /x32 and /x64, add operand features 2022-04-06 11:39:55 -06:00
Moritz Raabe c5368ed9a2 call $+5 update rule and doc 2022-03-01 08:46:58 +01:00
Moritz Raabe 1307be35d5 s/fireeye/mandiant 2021-09-27 21:47:49 +02:00
Willi Ballenthin 50a5b10621 format: add substring to section titles 2021-08-24 16:36:05 -06:00
Willi Ballenthin 542d1628f3 doc: format: string: tweak quoting 2021-08-24 11:44:06 -06:00
Willi Ballenthin 9fdaf7a10f format: document substring features 2021-08-24 11:42:32 -06:00
William Ballenthin 7bfafc6aed Merge branch 'master' of github.com:fireeye/capa-rules into feature-701 2021-08-18 14:31:01 -06:00
William Ballenthin 6bcd6d5e88 format: document the format feature 2021-08-16 17:34:42 -06:00
William Ballenthin 7ae2d3942d format: document OS and Arch features 2021-08-16 17:32:17 -06:00
Moritz Raabe 6c01d1e81e clarify verbatim string matching 2021-06-10 13:24:57 +02:00
William Ballenthin 002700dad9 format: document function-name feature 2021-05-27 08:39:19 -06:00
Arnim Rupp 3a565c6ffd fix URLs & formatting 2021-05-12 12:52:06 +02:00
Michael Hunhoff 7d5080b4d4 updating rule format README 2021-03-25 10:17:54 -06:00
Michael Hunhoff 20e1b8fd4c enforce string formatting with double quotes + escaped special characters 2021-03-24 14:14:38 -06:00
Moritz Raabe 873ed713e8 rule updates based on PMA labs
see #296
2021-03-22 09:45:56 +01:00
Moritz Raabe ed04be796a dos2unix 2021-03-19 08:13:26 +01:00
Moritz 7afd7de057 Apply suggestions from code review
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
2021-02-23 16:30:39 +01:00
Moritz c23bc2195d Update format.md 2021-02-23 10:21:08 +01:00
Moritz 355a1845c6 document example syntax
closes #205
2021-01-07 08:45:24 +01:00
Moritz Raabe 2611789b46 update documentation on descriptions 2020-09-25 18:45:10 +02:00
Moritz Raabe 1fcec06e7e comment out description blocks for statements
discussed in #312
2020-09-14 11:53:01 +02:00
0ssigeno 8dd3821274 fixed key, and added x32 and x64 flavours 2020-08-20 10:22:00 +02:00
Ana María Martínez Gómez cf0dedfc38 Remove characteristic(switch) from the documentation
The `characteristic(switch)` feature has been removed in:
https://github.com/fireeye/capa/pull/232
2020-08-13 16:51:47 +02:00
William Ballenthin 3a803f3401 add doc around arch flavors of offset/number 2020-08-03 16:49:44 -06:00
Ana María Martínez Gómez 170993b2ae doc: Document descriptions for statement nodes
Introduced in:
https://github.com/fireeye/capa/pull/209
2020-07-28 16:26:00 +02:00
Moritz f634c27772 update support for negative offsets 2020-07-27 20:14:42 +02:00
Moritz 4c9cb02949 fix links 2020-07-27 18:01:56 +02:00
Ana María Martínez Gómez c1c0bfb510 doc: fix/improve rule format documentation
- fix broken link
- fix wrong example
- add description example for regular expression.
- remove limitations from index (it is not in this file)
2020-07-16 19:21:43 +02:00
Moritz 1a6ac08cd1 Update format.md 2020-07-11 16:12:11 +02:00
William Ballenthin ba7843e7a8 update format doc 2020-07-03 01:21:41 -06:00
William Ballenthin cd88b27011 add doc/format.md 2020-07-02 17:55:53 -06:00