Skip to content

Latest commit

 

History

History
72 lines (52 loc) · 2.56 KB

File metadata and controls

72 lines (52 loc) · 2.56 KB

NetworkingFinding

Properties

Name Type Description Notes
address String Function's virtual address, hex-encoded
categories List<CategoriesEnum> Distinct networking categories evidenced by this function
confidence ConfidenceEnum High when a direct name match was found, medium when the function only calls into networking APIs
directMatches List<NetworkingDirectMatch> Matches against the function's own name [optional]
evidenceCount Long Total number of direct matches and network calls
functionId Long ID of the function the finding was reported in
functionName String Name of the function the finding was reported in
functionSize Long Size of the function in bytes
networkCalls List<NetworkingCall> Matches against names this function calls [optional]
remote Boolean Whether this function evidences remote communication rather than only supporting it
sources List<SourcesEnum> Distinct networking sources evidenced by this function
verification NetworkingVerification LLM verdict checking this finding against its decompilation. Present only when the run verified this finding. [optional]

Enum: List<CategoriesEnum>

Name Value
ACCEPT "accept"
ADDRESS "address"
CONNECT "connect"
DNS "dns"
HTTP "http"
NETINFO "netinfo"
RAW_PACKET "raw-packet"
RECV "recv"
SEND "send"
SOCKET "socket"
TLS "tls"
URL "url"
UNKNOWN_DEFAULT_OPEN_API "unknown_default_open_api"

Enum: ConfidenceEnum

Name Value
HIGH "high"
MEDIUM "medium"
UNKNOWN_DEFAULT_OPEN_API "unknown_default_open_api"

Enum: List<SourcesEnum>

Name Value
BOOST "boost"
CPP "cpp"
CURL "curl"
GENERIC "generic"
LIBC "libc"
PCAP "pcap"
POCO "poco"
QT "qt"
TLS "tls"
WINDOWS "windows"
UNKNOWN_DEFAULT_OPEN_API "unknown_default_open_api"