capa.md
For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.
CAPA
CAPA is a tooling integration. Tooling Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
Dropzone integrates with CAPA to analyze executable files (e.g. PE/ELF/.NET) to determine what capabilities they have, such as initiating http communications or installing software, to help identify if it is malicious or not.
Enable CAPA
The CAPA Data Source integration does not require any API keys or credentials.
To enable the Data Source integration, do the following:
- Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
- In the bottom left hand corner, click Settings > Integrations
Integrations Dropdown
- Click "Provided"
Click Provided
- In the Search bar, search Capa, then click the kebab on the right
Select Capa
- Click "Enable data source" to enable Capa
Enable data source
If you have any errors engage your Dropzone AI support representative.