Package modules :: Package processing :: Module behavior :: Class Anomaly
[hide private]
[frames] | no frames]

Class Anomaly

source code

                                 object --+    
                                          |    
lib.cuckoo.common.abstracts.BehaviorHandler --+
                                              |
                                             Anomaly

Anomaly detected during analysis. For example: a malware tried to remove Cuckoo's hooks.

Instance Methods [hide private]
 
__init__(self, *args, **kwargs)
x.__init__(...) initializes x; see help(type(x)) for signature
source code
 
handle_event(self, call)
Process API calls.
source code
 
run(self)
Fetch all anomalies.
source code

Inherited from lib.cuckoo.common.abstracts.BehaviorHandler: handles_path, parse

Inherited from object: __delattr__, __format__, __getattribute__, __hash__, __new__, __reduce__, __reduce_ex__, __repr__, __setattr__, __sizeof__, __str__, __subclasshook__

Class Variables [hide private]
  key = "anomaly"
  event_types = ["anomaly"]
Properties [hide private]

Inherited from object: __class__

Method Details [hide private]

__init__(self, *args, **kwargs)
(Constructor)

source code 

x.__init__(...) initializes x; see help(type(x)) for signature

Overrides: object.__init__
(inherited documentation)

handle_event(self, call)

source code 

Process API calls.

Parameters:
  • call - API call object
  • process - process object
Overrides: lib.cuckoo.common.abstracts.BehaviorHandler.handle_event

run(self)

source code 

Fetch all anomalies.

Overrides: lib.cuckoo.common.abstracts.BehaviorHandler.run