enhancementhelp wanted
Repository metrics
- Stars
- (3,644 stars)
- PR merge metrics
- (No merged PRs in 30d)
Description
To replace the current yaml signatures. This will allow us to create mroe powerful rules. For example to find GitHub API keys we would regex on ([a-f\d]{40}), but currently that would produce a lot of false positives (it's a SHA1 hash). With a YARA rule we could do:
rule GitHubApikey
{
strings:
$re1 = /[a-f\d]{40}/
$re2 = /Authorization: token/
$re3 = /https://api.github.com/
condition:
$re1 and ($re2 or $re3)
}