diff --git a/capa/features/extractors/base_extractor.py b/capa/features/extractors/base_extractor.py index b81cbdfcd..b88da5f82 100644 --- a/capa/features/extractors/base_extractor.py +++ b/capa/features/extractors/base_extractor.py @@ -328,7 +328,7 @@ class CallHandle: reference to an api call extracted by the sandbox. Attributes: - address: call's id address + address: call's address, such as event index or id inner: sandbox-specific data """ @@ -445,8 +445,8 @@ def extract_call_features( ) -> Iterator[Tuple[Feature, Address]]: """ Yields all features of a call. These include: - - api's - - arguments + - api name + - bytes/strings/numbers extracted from arguments """ raise NotImplementedError() diff --git a/capa/features/extractors/cape/process.py b/capa/features/extractors/cape/process.py index 4c1babe90..2119cef1c 100644 --- a/capa/features/extractors/cape/process.py +++ b/capa/features/extractors/cape/process.py @@ -22,7 +22,7 @@ def get_threads(behavior: Dict, ph: ProcessHandle) -> Iterator[ThreadHandle]: """ - get a thread's child processes + get the threads associated with a given process """ process = capa.features.extractors.cape.helpers.find_process(behavior["processes"], ph)