Documentation
¶
Overview ¶
Package analyzershell is an isolated, static-only shell fact candidate.
Index ¶
Constants ¶
View Source
const ( Profile = "corvint-analyzer-candidate/experimental" Family = "shell" MaxRequestBytes = 1_500_000 MaxInputBytes = 1 << 20 MaxOutputBytes = 1 << 20 MaxInputs = 128 MaxFeatures = 64 MaxAggregateBase64Bytes = 1_398_104 MaxIdentifierBytes = 128 MaxPathBytes = 4096 MaxPathSegmentBytes = 128 MaxJSONDepth = 8 MaxJSONTokens = 4096 MaxFactFieldBytes = 4096 MaxFacts = 3000 MaxSourceBytes = 65_536 MaxBinaryBytes = 6_291_456 MaxBytesPerOp = 130_000 MaxAllocsPerOp = 900 )
Variables ¶
This section is empty.
Functions ¶
func AnalyzeCanonical ¶
AnalyzeCanonical never reads paths or executes shell; raw is the sole input.
Types ¶
type Fact ¶
type Fact struct {
Kind string `json:"kind"`
InputHandle string `json:"input_handle"`
RelatedHandle string `json:"related_handle"`
Subject string `json:"subject"`
Predicate string `json:"predicate"`
Value string `json:"value"`
InstanceID string `json:"instance_id"`
EvidenceSHA256 string `json:"evidence_sha256"`
}
Click to show internal directories.
Click to hide internal directories.