Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
capa — Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK techniques for malware triage. | Kitploit
도구/GitHubGitHub/mandiant/capa
Indicator of Compromise (IOC) ManagementStatic AnalysisDynamic Analysis (Sandboxing)Memory ForensicsThreat Feeds & AggregatorsCode AnalysisReverse EngineeringMobile ForensicsMalware AnalysisBinary AnalysisThreat Intelligence
6.1k7148821일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
AI-Assisted Reversing
Incident Response
AI-Assisted Reversing #13위
Binary Analysis #7위
Code Analysis #7위
Dynamic Analysis (Sandboxing) #14위
Incident Response #15위
Indicator of Compromise (IOC) Management #17위
Malware Analysis #3위
Memory Forensics #11위
Mobile Forensics #20위
Reverse Engineering #20위
Static Analysis #2위
Threat Feeds & Aggregators #15위
Threat Intelligence #12위
GitHubmandiant/capa

capa

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK techniques for malware triage.

저장소 보기웹사이트

웹사이트 | 다운로드 | 웹 인터페이스

PyPI - Python 버전 최신 릴리스 규칙 수 CI 상태 다운로드 라이선스


capa는 실행 파일에서 기능을 탐지합니다. PE, ELF, .NET 모듈, 셸코드 파일 또는 샌드박스 보고서에 대해 실행하면 프로그램이 무엇을 할 수 있다고 생각하는지 알려줍니다. 예를 들어, 파일이 백도어이거나 서비스를 설치할 수 있거나 HTTP를 통신에 사용한다고 제안할 수 있습니다.

브라우저에서 capa 결과를 대화형으로 검사하려면 capa Explorer Web을 사용하십시오.

capa 규칙을 검사하거나 작성하려면 capa-rules 저장소로 이동하세요. 그렇지 않으면 계속 읽으십시오.

아래에 자세한 내용이 있는 당사의 capa 블로그 게시물 목록이 있습니다.

예제 capa 출력```

$ capa.exe suspicious.exe

+--------------------+------------------------------------------------------------------------+ | ATT&CK Tactic | ATT&CK Technique | |--------------------+------------------------------------------------------------------------| | DEFENSE EVASION | Obfuscated Files or Information [T1027] | | DISCOVERY | Query Registry [T1012] | | | System Information Discovery [T1082] | | EXECUTION | Command and Scripting Interpreter::Windows Command Shell [T1059.003] | | | Shared Modules [T1129] | | EXFILTRATION | Exfiltration Over C2 Channel [T1041] | | PERSISTENCE | Create or Modify System Process::Windows Service [T1543.003] | +--------------------+------------------------------------------------------------------------+

+-------------------------------------------+-------------------------------------------------+ | CAPABILITY | NAMESPACE | |-------------------------------------------+-------------------------------------------------| | read and send data from client to server | c2/file-transfer | | execute shell command and capture output | c2/shell | | receive data (2 matches) | communication | | send data (6 matches) | communication | | connect to HTTP server (3 matches) | communication/http/client | | send HTTP request (3 matches) | communication/http/client | | create pipe | communication/named-pipe/create | | get socket status (2 matches) | communication/socket | | receive data on socket (2 matches) | communication/socket/receive | | send data on socket (3 matches) | communication/socket/send | | connect TCP socket | communication/socket/tcp | | encode data using Base64 | data-manipulation/encoding/base64 | | encode data using XOR (6 matches) | data-manipulation/encoding/xor | | run as a service | executable/pe | | get common file path (3 matches) | host-interaction/file-system | | read file | host-interaction/file-system/read | | write file (2 matches) | host-interaction/file-system/write | | print debug messages (2 matches) | host-interaction/log/debug/write-event | | resolve DNS | host-interaction/network/dns/resolve | | get hostname | host-interaction/os/hostname | | create process | host-interaction/process/create | | create registry key | host-interaction/registry/create | | create service | host-interaction/service/create | | create thread | host-interaction/thread/create | | persist via Windows service | persistence/service | +-------------------------------------------+-------------------------------------------------+

# 다운로드 및 사용법

안정적인 독립형 capa 바이너리의 릴리스를 [여기](https://github.com/mandiant/capa/releases)에서 다운로드하세요. 설치 없이 독립형 바이너리를 실행할 수 있습니다. capa는 터미널에서 실행해야 하는 명령줄 도구입니다.

capa를 라이브러리로 사용하거나 다른 도구와 통합하려면 추가 설정 지침은 [doc/installation.md](https://github.com/mandiant/capa/blob/master/doc/installation.md)를 참조하세요.

**문서:** [사용법 및 팁](https://github.com/mandiant/capa/blob/master/doc/usage.md) · [설치](https://github.com/mandiant/capa/blob/master/doc/installation.md) · [제한사항](https://github.com/mandiant/capa/blob/master/doc/limitations.md) · [FAQ](https://github.com/mandiant/capa/blob/master/doc/faq.md)

# capa Explorer Web
[capa Explorer Web](https://mandiant.github.io/capa/explorer/)을 사용하면 웹 브라우저에서 대화형으로 capa 결과를 탐색할 수 있습니다. 온라인 버전 외에도 로컬 오프라인 사용을 위한 독립형 HTML 파일을 다운로드할 수 있습니다.

![capa Explorer Web 스크린샷](https://raw.githubusercontent.com/mandiant/capa/master/doc/img/capa_web_explorer.png)

웹 UI에 대한 자세한 내용은 [capa Explorer Web README](https://github.com/mandiant/capa/blob/master/web/explorer/README.md)에서 확인할 수 있습니다.

# 예제

위 샘플 출력에서 알 수 없는 바이너리(`suspicious.exe`)에 대해 capa를 실행하고, 도구는 프로그램이 HTTP 요청을 보내고, XOR 및 Base64를 통해 데이터를 디코딩하고, 서비스를 설치하고, 새 프로세스를 생성할 수 있다고 보고합니다. 종합해 보면, `suspicious.exe`가 지속형 백도어일 수 있다고 생각됩니다. 따라서 다음 분석 단계는 샌드박스에서 `suspicious.exe`를 실행하고 명령 및 제어 서버를 복구하는 것일 수 있습니다.

## 상세 결과

`-vv` 플래그(매우 자세한 출력)를 전달하면 capa가 이러한 기능의 증거를 찾은 위치를 정확히 보고합니다. 이는 적어도 두 가지 이유로 유용합니다:
도구 다운로드