eth0izzle/shhgit

Implement YARA rules

Open

#17 opened on Oct 1, 2019

View on GitHub
 (9 comments) (2 reactions) (1 assignee)JavaScript (474 forks)batch import
enhancementhelp wanted

Repository metrics

Stars
 (3,644 stars)
PR merge metrics
 (No merged PRs in 30d)

Description

To replace the current yaml signatures. This will allow us to create mroe powerful rules. For example to find GitHub API keys we would regex on ([a-f\d]{40}), but currently that would produce a lot of false positives (it's a SHA1 hash). With a YARA rule we could do:

rule GitHubApikey
{
    strings:
        $re1 = /[a-f\d]{40}/
        $re2 = /Authorization: token/
        $re3 = /https://api.github.com/

    condition:
        $re1 and ($re2 or $re3)
}

Contributor guide