YARA-X's Dump Command, (Sun, Sep 15th)
2024-9-16 02:32:6 Author: isc.sans.edu(查看原文) 阅读量:11 收藏

Published: 2024-09-15. Last Updated: 2024-09-15 18:32:06 UTC
by Didier Stevens (Version: 1)

YARA-X is not just a rewrite of YARA in Rust, it comes with new features too.

One of these features is the dump command: yr.exe dump ...

YARA-X can parse several file formats natively, to support file-format specific YARA rules. These parsers can also be invoked explicitly (without YARA rules for testing). The default output is YAML:

And JSON output is supported too:

Didier Stevens
Senior handler
blog.DidierStevens.com


文章来源: https://isc.sans.edu/diary/rss/31264
如有侵权请联系:admin#unsafe.sh