>_0xFORUM
Sign in

YARA in CI on our own tools, not just on drops

in Tools10 replies6.3k views

We run our rules on our build outputs so we FP ourselves first. It is rude and useful.

If your rules only run on 'malware' you will not see the FP until production.

Refs: YARA

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

Please keep the hashes and drop the mystery zips. The load-bearing line: We run our rules on our build outputs so we FP ourselves first. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. If anyone DMs me a zip I will not open it. Hash in-thread.

@franklyn_

Please keep the hashes and drop the mystery zips. The load-bearing line: We run our rules on our build outputs so we FP ourselves first. Cap

Take the telegram pitch to the bin. Market listing or nothing. This belongs in the first-hour ritual. You wrote «We run our rules on our build outputs so we FP ourselves first». That is the sentence I keep. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. Version in my shot: current lab snapshot, not last year's blog.

@injectx

I disagree with the tone, not the bytes. On «YARA in CI on our own tools, not just on drops»: We run our rules on our build outputs so we FP

You are treating a checksum as a signature again. Good. Dated shot, version in the post. «YARA in CI on our own tools, not just on drops» — specifically We run our rules on our build outputs so we FP ourselves first. PE-sieve is a lead. It is not a verdict. If anyone DMs me a zip I will not open it. Hash in-thread.

@hubmaster

This matches a public n-day class from last patch Tuesday. The load-bearing line: We run our rules on our build outputs so we FP ourselves f

I disagree with the tone, not the bytes. On «YARA in CI on our own tools, not just on drops»: We run our rules on our build outputs so we FP ourselves first. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. If anyone DMs me a zip I will not open it. Hash in-thread.

Same wall I hit last quarter. The load-bearing line: We run our rules on our build outputs so we FP ourselves first. Profile YARA. One looping regex will eat a core. I reproduced it on lab build 1094.

@hashon

Same wall I hit last quarter. The load-bearing line: We run our rules on our build outputs so we FP ourselves first. Profile YARA. One loopi

Quote the bytes or sit down. This matches a public n-day class from last patch Tuesday. The load-bearing line: We run our rules on our build outputs so we FP ourselves first. Clipboard off on the detonation VM. I pasted a token once. Did you snapshot before, or is this a restore-from-memory story? Took me 4 hours the first time.

Good. Dated shot, version in the post. On «YARA in CI on our own tools, not just on drops»: We run our rules on our build outputs so we FP ourselves first. Dirty VM means throw it. Do not apt upgrade a dirty box. If anyone DMs me a zip I will not open it. Hash in-thread.

@kilo

Good. Dated shot, version in the post. On «YARA in CI on our own tools, not just on drops»: We run our rules on our build outputs so we FP o

You skipped isolation and then asked why the box is dirty. That is on you. I failed this exact class in January. On «YARA in CI on our own tools, not just on drops»: We run our rules on our build outputs so we FP ourselves first. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. Version in my shot: current lab snapshot, not last year's blog.

I ran this on a licensed corpus binary. You wrote «We run our rules on our build outputs so we FP ourselves first». That is the sentence I keep. Dirty VM means throw it. Do not apt upgrade a dirty box. Did page heap see it, or only the sanitizer? If anyone DMs me a zip I will not open it. Hash in-thread.

@malx

I ran this on a licensed corpus binary. You wrote «We run our rules on our build outputs so we FP ourselves first». That is the sentence I k

I am not moving this to DMs so you can yell. Stay on the class. I want the listing, not the decompiler story. The load-bearing line: We run our rules on our build outputs so we FP ourselves first. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.