Skip to content

Commit

Permalink
doc: update usage information
Browse files Browse the repository at this point in the history
  • Loading branch information
mr-tz committed Jul 12, 2020
1 parent 3ce01fa commit bebc9b0
Show file tree
Hide file tree
Showing 3 changed files with 2 additions and 2 deletions.
Binary file removed doc/capa_explorer.png
Binary file not shown.
Binary file added doc/img/capa_explorer.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
4 changes: 2 additions & 2 deletions doc/usage.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ See `capa -h` for all supported arguments and usage examples.
- [IDA Pro rule generator](#rule-generator)

### only run selected rules
Use the `-t` option to run rules with the given metadata value (see the rule fields `rule.meta.*`).
Use the `-t` option to run rules with the given metadata value (see the rule fields `rule.meta.*`).
For example, `capa -t [email protected]` runs rules that reference Willi's email address (probably as the author), or
`capa -t communication` runs rules with the namespace `communication`.

Expand All @@ -29,7 +29,7 @@ The capa explorer allows you to interactively display and browse capabilities ca
As you select rules or logic, capa will highlight the addresses that support its analysis conclusions.
We like to use capa to help find the most interesting parts of a program, such as where the C2 mechanism might be.

![capa explorer](capa_explorer.png)
![capa explorer](img/capa_explorer.png)

#### rule generator
The rule generator helps you to easily write new rules based on the function you are currently analyzing in your IDA disassembly view.
Expand Down

0 comments on commit bebc9b0

Please sign in to comment.