Skip to content

Latest commit

 

History

History
73 lines (53 loc) · 2.75 KB

File metadata and controls

73 lines (53 loc) · 2.75 KB

FilesystemFinding

Properties

Name Type Description Notes
address String Function's virtual address, hex-encoded
categories List<CategoriesEnum> Distinct filesystem categories evidenced by this function
confidence ConfidenceEnum High when a direct name match was found, medium when the function only calls into filesystem APIs
directMatches List<FilesystemDirectMatch> Matches against the function's own name [optional]
evidenceCount Long Total number of direct matches and filesystem calls
filesystemCalls List<FilesystemCall> Matches against names this function calls [optional]
functionId Long ID of the function the finding was reported in
functionName String Name of the function the finding was reported in
functionSize Long Size of the function in bytes
modifies Boolean Whether this function evidences modifying the filesystem rather than only observing it
sources List<SourcesEnum> Distinct filesystem sources evidenced by this function
verification FilesystemVerification LLM verdict checking this finding against its decompilation. Present only when the run verified this finding. [optional]

Enum: List<CategoriesEnum>

Name Value
DIR_READ "dir-read"
DIR_WRITE "dir-write"
ENVIRONMENT "environment"
FILE_DELETE "file-delete"
FILE_OPEN "file-open"
FILE_PERMS "file-perms"
FILE_READ "file-read"
FILE_STAT "file-stat"
FILE_WRITE "file-write"
MODULE "module"
PATH_WRITE "path-write"
PROCESS "process"
REGISTRY_READ "registry-read"
REGISTRY_WRITE "registry-write"
SERVICE "service"
SYSTEM "system"
UNKNOWN_DEFAULT_OPEN_API "unknown_default_open_api"

Enum: ConfidenceEnum

Name Value
HIGH "high"
MEDIUM "medium"
UNKNOWN_DEFAULT_OPEN_API "unknown_default_open_api"

Enum: List<SourcesEnum>

Name Value
BOOST "boost"
CPP "cpp"
CPP_STDLIB "cpp-stdlib"
GENERIC "generic"
LIBC "libc"
QT "qt"
WINDOWS "windows"
UNKNOWN_DEFAULT_OPEN_API "unknown_default_open_api"