run_capa_analysis
Match capa rules against a pre-analyzed Rizin session to identify malicious capabilities. Use after open_and_analyze; supports disk caching for fast re-analysis.
Instructions
[Ultra-fast Rizin Extractor Mode] Use the pre-analyzed Rizin Session from open_and_analyze to match capa-rules and identify malicious capabilities. open_and_analyze must be called first. It fully analyzes all functions until completion, automatically supports disk caching, and directly returns cached results if already analyzed.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| force_reanalysis | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |