Victor M. Alvarez
Victor M. Alvarez
Related: https://github.com/VirusTotal/yara-x/issues/23
Do we really need `EXPRESSION_TYPE_INTEGER_FUNCTION`? I mean, as long as every `EXPRESSION_TYPE_INTEGER` has an associated field `width` indicating the number of bits in that integer we can check that operations...
I see the utility of this new module, but I'm worried about its maintenance and testability. One of the problem with process memory scanning in general is that it's poorly...
This request is interesting because it exposes the current limitations in the language. I agree @wxsBSD's comment, in order to implement this (and more powerful features in the feature) we...
For the time being I would put each RFC as in independent discussion.
What version of cuckoo are you using? The `cuckoo` module works with very old versions and haven't been updated in a long time. If you are using a recent version...
@mhmh261 can you provide more context about this? What's the intention for this change?
This is really nice!
@j-t-1 yes, the file `043066108b68b30fc2c475eae8edfafc080be7d451600eaa283d2c750bddbceb` is WIMA_SFX.EXE.
I think #402 is ok.