Carl Corea

53 papers A* 1A 4B 1C 1Journal 13Unranked 31
YearRankTypeTitle / Venue / Authors
2026 conf
HICSS
Henrik Leopold, Carl Corea, Benoît Depaire
2025 conf
CAiSE (2)
Carl Corea, Anti Alman, Fabrizio Maria Maggi, Paul Hermann Wittlinger
2025 conf
HICSS
Hajo Alexander Reijers, Henrik Leopold, Han van der Aa, Carl Corea
2025 ed.
ECSQARU (Workshops and Tutorials)
Carl Corea, Jérôme Delobelle, John Grant, Jean-Guy Mailly, Julien Rossit, Kenneth Skiba
2025 conf
ECSQARU (Workshops and Tutorials)
Carl Corea, Jérôme Delobelle, John Grant, Jean-Guy Mailly, Julien Rossit, Kenneth Skiba
2025 C conf
ECSQARU
Carl Corea, Timotheus Kampik, Nico Potyka
2025 J jnl
CoRR
Carl Corea, Timotheus Kampik, Nico Potyka
2024 conf
ICEIS (2)
Philipp Hehnle, Maximilian Behrendt, Luc Weinbrecht, Carl Corea
2024 conf
BPM (Forum)
Carl Corea, Timotheus Kampik, Marco Montali
2024 conf
BPM (Demos / Resources Forum)
Carl Corea, Patrick Delfmann
2024 conf
SUM
Isabelle Kuhlmann, Carl Corea
2024 conf
HICSS
Henrik Leopold, Han van der Aa, Carl Corea, Hajo Alexander Reijers
2024 J jnl
CoRR
Adrian Rebmann, Timotheus Kampik, Carl Corea, Han van der Aa
2024 A conf
CAiSE
Carl Corea, Paolo Felli, Marco Montali, Fabio Patrizi
2024 J jnl
Inf. Syst.
Carl Corea, Isabelle Kuhlmann, Matthias Thimm, John Grant
2023 conf
NMR
Isabelle Kuhlmann, Carl Corea, John Grant
2023 conf
BPMDS/EMMSAD@CAiSE
Nicolai Schützenmeier, Carl Corea, Patrick Delfmann, Stefan Jablonski
2023 conf
Business Process Management Workshops
Carl Corea, Timotheus Kampik, Patrick Delfmann
2023 J jnl
CoRR
Stefan Hill, David Fitzek, Patrick Delfmann, Carl Corea
2023 conf
Business Process Management Workshops
Isabelle Kuhlmann, Carl Corea, John Grant
2023 conf
KoDis+CAKR@KR
Carl Corea
2022 conf
BPM (PhD/Demos)
Eric Amann, Carl Corea, Christoph Drodt, Patrick Delfmann
2022 conf
Wirtschaftsinformatik
Carl Corea, Rana Mansour, Patrick Delfmann
2022 conf
HICSS
Carl Corea, Estefanía Serral, Faruk Hasic, Patrick Delfmann
2022 A conf
BPM
Carl Corea, John Grant, Matthias Thimm
2022 J jnl
CoRR
Carl Corea, John Grant, Matthias Thimm
2022 ch.
Process Querying Methods
Patrick Delfmann, Dennis M. Riehle, Steffen Höhenberger, Carl Corea, Christoph Drodt
2021 conf
CAiSE Forum
Nico Bartmann, Stefan Hill, Carl Corea, Christoph Drodt, Patrick Delfmann
2021 J jnl
Inf. Syst. Manag.
Sabine Nagel, Carl Corea, Patrick Delfmann
2021 conf
BPM (Forum)
Carl-Christian Grohé, Carl Corea, Patrick Delfmann
2021 conf
BPM (PhD/Demos)
Carl Corea
2021 conf
BPM (Forum)
Carl Corea, Sabine Nagel, Jan Mendling, Patrick Delfmann
2021 A* conf
KR
Carl Corea, Matthias Thimm, Patrick Delfmann
2021 J jnl
CoRR
Carl Corea, Matthias Thimm, Patrick Delfmann
2021 A conf
ER
Carl Corea, Michael Fellmann, Patrick Delfmann
2021 J jnl
CoRR
Carl Corea, Michael Fellmann, Patrick Delfmann
2021 J jnl
EMISA Forum
Carl Corea, Michael Fellmann, Patrick Delfmann
2020 J jnl
Enterp. Model. Inf. Syst. Archit.
Carl Corea, Patrick Delfmann
2020 B conf
RCIS
Faruk Hasic, Carl Corea, Jonas Blatt, Patrick Delfmann, Estefanía Serral
2020 J jnl
Knowl. Inf. Syst.
Faruk Hasic, Carl Corea, Jonas Blatt, Patrick Delfmann, Estefanía Serral
2020 conf
HICSS
Carl Corea, Sabine Nagel, Patrick Delfmann
2020 J jnl
Artif. Intell.
Carl Corea, Matthias Thimm
2020 A conf
ECAI
Carl Corea, Matthias Thimm
2020 conf
HICSS
Carl Corea, Patrick Delfmann, Sabine Nagel
2019 conf
BPM (PhD/Demos)
Carl Corea, Jonas Blatt, Patrick Delfmann
2019 conf
HICSS
Sabine Nagel, Carl Corea, Patrick Delfmann
2019 conf
BPM Forum
Carl Corea, Patrick Delfmann
2019 conf
Wirtschaftsinformatik
Carl Corea, Matthias Deisen, Patrick Delfmann
2019 J jnl
CoRR
Carl Corea, Matthias Thimm
2018 conf
BPM (Dissertation/Demos/Industry)
Carl Corea, Patrick Delfmann
2018 conf
BPM (Dissertation/Demos/Industry)
Carl Corea, Patrick Delfmann
2017 conf
Wirtschaftsinformatik
Carl Corea, Patrick Delfmann
2016 conf
SAFA
Carl Corea, Matthias Thimm
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"