INNER CODE UNIT · Python

path

magicsword-io/LOLRMM · bin/detection_paths.py:19

        path = path[1:-1]
    path = path.replace("/", "\\")
    directory = ntpath.dirname(path)
    _, location = ntpath.splitdrive(directory)
    # A drive letter, root separator or wildcard is not installation context.
    # Unexpanded variables/placeholders would not match raw process telemetry.
    if not re.search(r"[a-zA-Z0-9]", location) or any(c in path for c in "%<>"):
        return None
    components = {
        part.casefold() for part in location.split("\\")
        if re.search(r"[a-zA-Z0-9]", part)
    }
    if components <= {"windows", "system32", "syswow64", "sysnative"}:
        return None

    # Anchor relative directory suffixes; preserve explicit wildcard roots.
    if not ntpath.isabs(path) and not path.startswith("*"):
        path = "\\" + path

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…