binaryalert
binaryalert copied to clipboard
require MZ to fix fp
to: @airbnb/binaryalert-maintainers
cc:
Background
rule produces false positives on e.g. debians /usr/share/doc/hashcat-data/examples/example.dict
Changes
require MZ bytes
Testing
running yara on mimikatz.exe