Matching Semantics

How consumers should interpret paths, platforms, and content indicators.

Schema version 1 keeps matching simple.

  1. Multiple match.paths entries are alternatives.
  2. A path matcher applies only to its listed platforms.
  3. A matching path identifies a candidate artifact.
  4. content.contains and content.regex provide additional evidence for a path.
  5. Consumers may use path-only matching or path plus content verification.
  6. Environment variables are not expanded inside the database.

Platforms

Supported platforms are:

  • windows
  • linux
  • macos

Linux and macOS remain distinct even when they currently share the same path.

Content Matching

contains is literal substring evidence. regex is regular-expression evidence validated by the LOLPaths validator. Content matching does not require YARA.

On this page