ConfigExtractor
Maintainer: @cccs-rs
Python Library for performing configuration extraction across multiple extraction frameworks (ie. Maco, MWCP, etc.). This tool is actively used in the Assemblyline project as a service.
The code found in this repository contains a command line interface that acts as a wrapper for popular malware configuration data decoders from:
- Maco [MIT license]
- MWCP [MIT license]
- CAPE Sandbox [GPL license] via CAPE-parsers fork [MIT License]
- many thanks to @kevoreilly and the CAPESandbox community for releasing so many open source parsers.
MWCFG : https://github.com/c3rb3ru5d3d53c/mwcfg [BSD 3-Clause License]
Installation Guide
Running in a Container
docker container run \
-v /path/to/parsers:/mnt/parsers \
-v /path/to/samples:/mnt/samples \
cccs/assemblyline-service-configextractor \
"cx -p /mnt/parsers -s /mnt/samples"
Usage
Command-line
You can use configextractor or cx to make use of the CLI:
Usage: cx [OPTIONS] PARSERS_PATH SAMPLE_PATH
Options:
--block_list TEXT Comma-delimited list of parsers to ignore
--help Show this message and exit.
Python
from configextractor.main import ConfigExtractor
import logging
# Create a logger to track ongoings
logger = logging.getLogger()
logger.handlers = [logging.StreamHandler()]
logger.setLevel('DEBUG')
# Instantiate instance of class with path(s) to extractors
# Attaching a logger will allow some insight into what's going on if parser detection is the issue
cx = ConfigExtractor(["/path/to/extractors/"], logger=logger)
# List all parsers actively detected and loaded into instance
# cx.parsers.keys() lists all the relative module paths to the parsers
# The value of each key is an Extractor object containing details for running the extractor (ie. venv location, YARA rule, etc.)
print([cx.get_details(p)['name'] for p in cx.parsers.values()])
# Run all loaded parsers against sample
results = cx.run_parsers('/path/to/sample')
# Output raw results to stdout, each should be organized by the parsers that generated an output
print(results)
Adding a new Parser Framework
- Inherit from the base
Frameworkclass and implement class accordingly - Add new framework to the ConfigExtractor class'
FRAMEWORK_LIBRARY_MAPPING
Metadata
Release files for configextractor-py 1.1.18
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| configextractor_py-1.1.18.tar.gz | 25.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| configextractor_py-1.1.18-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 53.2 kB
Release files / configextractor_py-1.1.18.tar.gz
| Download URL | configextractor_py-1.1.18.tar.gz |
|---|---|
| Size | 25.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f95ec1d34c5cf7c80baad6f0101bccc864d01ab3c062c1265aebca399dab08d3
|
|
BLAKE2b-256 checksum How to use checksums |
767a586ca2cb20702b2ec8345324d94b315d11b3c75ba7ad924f12d589e78a44
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|
Release files / configextractor_py-1.1.18-py3-none-any.whl
| Download URL | configextractor_py-1.1.18-py3-none-any.whl |
|---|---|
| Size | 27.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e9f61e832a68eabed4136d89555030f52903f3c429860e30882f6aeeb36a44ca
|
|
BLAKE2b-256 checksum How to use checksums |
4e089b0685ccc8df85c1a84df021d7a072048d7857852f1a6766d9822ec63ec9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|