bulk_extractor
bulk_extractor copied to clipboard
Add support for YARA
Would this be useful?
- https://virustotal.github.io/yara/
Just wanted to give this a big old thumbs up!
Okay. Do you want yara run on every feature?
Personally I would yes.
Although this will likely cause a nice collection of false positives, I've found it better to figure out how to effectively filter these out after rather than potentially miss something significant.