Hyara
Hyara copied to clipboard
Issues with wildcarding
Both comment
and wildcard
option are checked but the wildcard
option is not working with the new version of Hyara
.
Unfortunately, wildcard option is not currently implemented. :(
Oh. Any ETA?
I can't update because I'm currently busy. It will be updated steadily.
If you have an idea or a feature you need, tell me. Pull requests are also welcome.
Sorry for late reply. As for feature I think this will be a great integration to Hyara. That script has multiple options for generating yara signatures. Specially the Position Independent Code (PIC) mode
is a solid one.
@r0ny123 Thanks. I will check this project :)
@r0ny123 Added a feature to modify the values to wildcards.
wildcard option is not yet :(
Nice, thanks @hyuunnn. But did you implement this https://github.com/MITRECND/malchive/blob/main/malchive/utilities/gensig.py as discussed earlier https://github.com/hyuunnn/Hyara/issues/15#issuecomment-980789671?
@r0ny123 Nope. I will study the source code.
https://github.com/c3rb3ru5d3d53c/binlex https://github.com/g-les/YARA-PE-Features https://github.com/g-les/floss2yar https://github.com/schrodyn/steezy https://github.com/fxb-cocacoding/yara-signator https://github.com/TcM1911/zig2yar https://github.com/fox-it/mkYARA https://github.com/immortalp0ny/yarg https://github.com/ald3ns/copy-as-yara https://github.com/mbrengel/yarix - https://www.usenix.org/system/files/sec21-brengel.pdf
https://github.com/DissectMalware/yaradbg-backend https://github.com/DissectMalware/yaradbg-frontend