Get desktop application:
View/edit binary Protocol Buffers messages
Used in: FeatureNode
string type = 1
string api = 2
optional string description = 3
Used in: Addresses, Analysis, BasicBlockLayout, CallLayout, FunctionFeatureCount, FunctionLayout, LibraryFunction, Match, Pair_Address_Match, ProcessFeatureCount, ProcessLayout, StaticAnalysis, ThreadLayout
Used in: Address
ADDRESSTYPE_UNSPECIFIED = 0
ADDRESSTYPE_ABSOLUTE = 1
ADDRESSTYPE_RELATIVE = 2
ADDRESSTYPE_FILE = 3
ADDRESSTYPE_DN_TOKEN = 4
ADDRESSTYPE_DN_TOKEN_OFFSET = 5
ADDRESSTYPE_NO_ADDRESS = 6
ADDRESSTYPE_PROCESS = 7
ADDRESSTYPE_THREAD = 8
ADDRESSTYPE_CALL = 9
Used in: Match
Used in: Metadata
string format = 1
string arch = 2
string os = 3
string extractor = 4
repeated string rules = 5
optional Address base_address = 6
optional Layout layout = 7
optional FeatureCounts feature_counts = 8
repeated LibraryFunction library_functions = 9
Used in: FeatureNode
string type = 1
string arch = 2
optional string description = 3
Used in: RuleMetadata
repeated string parts = 1
string tactic = 2
string technique = 3
string subtechnique = 4
string id = 5
Used in: FeatureNode
string type = 1
optional string description = 2
Used in: FunctionLayout
Used in: FeatureNode
string type = 1
string bytes = 2
optional string description = 3
Used in: ThreadLayout
optional Address address = 1
string name = 2
Used in: FeatureNode
string type = 1
string characteristic = 2
optional string description = 3
Used in: FeatureNode
string type = 1
string class_ = 2
optional string description = 3
Used in: StatementNode
string type = 1
optional string description = 2
Used in: Metadata
string format = 1
string arch = 2
string os = 3
string extractor = 4
repeated string rules = 5
Used in: DynamicAnalysis
Used in: DynamicAnalysis
Used in: FeatureNode
string type = 1
string export = 2
optional string description = 3
Used in: Analysis
Used in: Match, RangeStatement
string type = 1
oneof feature
Used in: Metadata
FLAVOR_UNSPECIFIED = 0
FLAVOR_STATIC = 1
FLAVOR_DYNAMIC = 2
Used in: FeatureNode
string type = 1
string format = 2
optional string description = 3
Used in: FeatureCounts, StaticFeatureCounts
optional Address address = 1
uint64 count = 2
Used in: Layout, StaticLayout
Used in: FeatureNode
string type = 1
string function_name = 2
optional string description = 3
Used in: FeatureNode
string type = 1
string import_ = 2
optional string description = 3
Used in: Address, OffsetFeature, OperandNumberFeature, OperandOffsetFeature, Ppid_Pid, Ppid_Pid_Tid, Ppid_Pid_Tid_Id, Token_Offset
Used in: Analysis
Used in: Analysis, StaticAnalysis
optional Address address = 1
string name = 2
Used in: RuleMetadata
repeated string parts = 1
string objective = 2
string behavior = 3
string method = 4
string id = 5
Used in: RuleMetadata
string analysis_conclusion = 1
string analysis_conclusion_ov = 2
string malware_family = 3
string malware_category = 4
string malware_category_ov = 5
Used in: Pair_Address_Match
bool success = 1
oneof node
repeated Match children = 5
repeated Address locations = 6
map<string, Addresses> captures = 7
Used in: FeatureNode
string type = 1
string match = 2
optional string description = 3
Used in: ResultDocument
string timestamp = 1
string version = 2
repeated string argv = 3
optional Sample sample = 4
optional Analysis analysis = 5
oneof analysis2
Used in: FeatureNode
string type = 1
string mnemonic = 2
optional string description = 3
Used in: FeatureNode
string type = 1
string namespace = 2
optional string description = 3
Used in: NumberFeature
oneof value
uint64 u = 1
sint64 i = 2
double f = 3
Used in: FeatureNode
string type = 1
optional Number number = 2
optional string description = 5
Used in: FeatureNode
string type = 1
string os = 2
optional string description = 3
Used in: FeatureNode
string type = 1
optional Integer offset = 2
optional string description = 3
Used in: FeatureNode
string type = 1
uint32 index = 2
optional Integer operand_number = 3
optional string description = 4
Used in: FeatureNode
string type = 1
uint32 index = 2
optional Integer operand_offset = 3
optional string description = 4
Used in: RuleMatches
Used in: Address
Used in: Address
Used in: Address
Used in: DynamicFeatureCounts
optional Address address = 1
uint64 count = 2
Used in: DynamicLayout
Used in: FeatureNode
string type = 1
string property_ = 2
optional string access = 3
optional string description = 4
Used in: StatementNode
string type = 1
uint64 min = 2
uint64 max = 3
optional string description = 5
Used in: FeatureNode
string type = 1
string regex = 2
optional string description = 3
Used in: ResultDocument
Used in: RuleMatches
string name = 1
string namespace = 2
repeated string authors = 3
repeated MBCSpec mbc = 6
repeated string references = 7
repeated string examples = 8
string description = 9
bool lib = 10
bool is_subscope_rule = 12
optional Scopes scopes = 13
Used in: Metadata
string md5 = 1
string sha1 = 2
string sha256 = 3
string path = 4
Used in: RuleMetadata, Scopes, SubscopeStatement
SCOPE_UNSPECIFIED = 0
SCOPE_FILE = 1
SCOPE_FUNCTION = 2
SCOPE_BASIC_BLOCK = 3
SCOPE_INSTRUCTION = 4
SCOPE_PROCESS = 5
SCOPE_THREAD = 6
SCOPE_CALL = 7
SCOPE_SPAN_OF_CALLS = 8
Used in: RuleMetadata
optional Scope static = 1
optional Scope dynamic = 2
Used in: FeatureNode
string type = 1
string section = 2
optional string description = 3
Used in: StatementNode
string type = 1
uint32 count = 2
optional string description = 3
Used in: Match
string type = 1
oneof statement
Used in: Metadata
string format = 1
string arch = 2
string os = 3
string extractor = 4
repeated string rules = 5
optional Address base_address = 6
repeated LibraryFunction library_functions = 9
Used in: StaticAnalysis
Used in: StaticAnalysis
Used in: FeatureNode
string type = 1
string string = 2
optional string description = 3
Used in: StatementNode
string type = 1
optional string description = 3
Used in: FeatureNode
string type = 1
string substring = 2
optional string description = 3
Used in: ProcessLayout
Used in: Address
optional Integer token = 1
uint64 offset = 2