Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

init add of Xamarin rules #824

Merged
merged 2 commits into from
Nov 22, 2023
Merged

init add of Xamarin rules #824

merged 2 commits into from
Nov 22, 2023

Conversation

mike-hunhoff
Copy link
Collaborator

Adding new rules based on #706 . This PR may be impacted by the discussions in #818 regarding mobile ATT&CK techniques. I wanted to open a PR for discussion before diving too far into creating new rules.

Questions:

  • Should Android example files be placed in separate tests folder?

@google-cla
Copy link

google-cla bot commented Sep 4, 2023

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Copy link
Collaborator

@williballenthin williballenthin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

so cool to see

nursery/get-system-information-in-dotnet-on-android.yml Outdated Show resolved Hide resolved
Copy link
Collaborator

@mr-tz mr-tz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the testfiles should be separate.

Similarly, do we want to keep the rules files separate? Some rules contain various formats/OS so that's a little messy.
There's pro and cons, so maybe we better open up a separate discussion?

@mr-tz
Copy link
Collaborator

mr-tz commented Oct 11, 2023

Collecting my thoughts here but happy to spin off separate issues/discussions.

  • I like the in .NET on Android naming
  • so far rules are inconsistent requiring format/os
    • this doesn't seem to be a problem though
  • important are:
    • rule readability and
    • organization
        1. duplicate all directories under android parent?
        1. only update namespaces to start with android/ root <-- my preferred option
  • testfiles should go into android directory

related discussion: mandiant/capa#701 (Rule organization for multiple file types PE and ELF)

@mike-hunhoff mike-hunhoff merged commit 20d2218 into master Nov 22, 2023
3 checks passed
@mike-hunhoff mike-hunhoff deleted the new/xamarin branch November 22, 2023 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants