INNER CODE UNIT · Python

process_image_pattern

magicsword-io/LOLRMM · bin/detection_paths.py:12

def process_image_pattern(path: str, filename: str):
    """Return an endswith pattern, or None when a generic name lacks context."""
    if filename.casefold() not in PATH_REQUIRED_EXECUTABLES:
        return f"\\\\{filename}"

    path = path.strip()
    if len(path) > 1 and path[0] == path[-1] and path[0] in "\"'":
        path = path[1:-1]
    path = path.replace("/", "\\")
    directory = ntpath.dirname(path)
    _, location = ntpath.splitdrive(directory)
    # A drive letter, root separator or wildcard is not installation context.
    # Unexpanded variables/placeholders would not match raw process telemetry.
    if not re.search(r"[a-zA-Z0-9]", location) or any(c in path for c in "%<>"):
        return None
    components = {
        part.casefold() for part in location.split("\\")
        if re.search(r"[a-zA-Z0-9]", part)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…