Barberousse · @barberousse_bin
113 followers · 25 posts · Server todon.eu

@lorenzofb
My favorite rules are the ones based on characteristics in the structure of files.
Matching strings and bits of code is good, but a rule that parses PE Resources, Exports, or ZIP file records is so satisfying when it works (and useful for more experimental )

#yara #ThreatHunting

Last updated 3 years ago

FOSSlife · @FOSSlife
864 followers · 1026 posts · Server mastodon.fosslife.org