Comments (5)
Thanks for finding and reporting this @Javiery3889 ! I believe I have fixed the problem, but let me know if you find other edge-cases.
from ioc-finder.
Thanks for reporting this @Javiery3889 ! And thank you for looking into the problem; that is really helpful (and most people don't do that)! I'll take a look and will hopefully have a fix soon.
from ioc-finder.
I've pushed an update to fix this issue. Thanks again for reporting! With the new implementation, there is one caveat (which I've noted in the readme):
A registry key path with a space in the final section (the part after the final \
) will not be taken as part of the registry key. For example:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\ConsoleIME
will be parsed as HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\ConsoleIME
and
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\ConsoleIME foo...
will be parsed as HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\ConsoleIME
(notice that everything after the space in the last section is removed)
from ioc-finder.
Hi @fhightower just discovered another bug regarding registry keys with multiple whitespaces, the path gets truncated as well shown below on Python 3.6.7.
from ioc_finder import find_iocs
text = "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe"
iocs = find_iocs(text)
print(iocs['registry_key_paths'])
# output: 'HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image'
However, I am unsure about the workaround this time, any advice? Thanks.
from ioc-finder.
Good catch. I'll take a look at that.
from ioc-finder.
Related Issues (20)
- Consider removing "filler words" from text HOT 1
- Improve documentation around "original_text" vs. "text" variables
- Maybe an ioc type should be added. HOT 1
- Some file paths match to wrong paths. HOT 1
- Review docs
- url parser error HOT 2
- Move large test into separate tests
- parser ssdeeps error HOT 2
- Incorrect parsing of ipv4 cidrs to urls HOT 1
- Improve URL boundary regarding commas (Old name: Wrong URL Pattern being Parsed) HOT 4
- Update lint step to fail properly
- Add documentation about how we handle natural, human language conventions vs. RFC
- Speed parsing by running concurrent processes HOT 11
- Incorrect extract domains from AV signatures HOT 1
- Identify ip or version HOT 1
- v7.3.0 does not work properly in interactive docs HOT 2
- URL path and query params getting to lower case HOT 1
- Add logging
- Feature Request: Give option to return found start and end index of IoC HOT 2
- Drop formal support for python 3.7 and 3.8
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from ioc-finder.