Hot set vs slow set. One Themida-shaped loop in the hot set and you are done.
The fast/slow split is the whole game. Profile the rules, not the engine.
Refs: YARA
Lab / educational. Public binaries and patched classes only. Isolated VM.
Hot set vs slow set. One Themida-shaped loop in the hot set and you are done.
The fast/slow split is the whole game. Profile the rules, not the engine.
Refs: YARA
Lab / educational. Public binaries and patched classes only. Isolated VM.
@zonedude
Bookmarking this for the lab wiki. The load-bearing line: Hot set vs slow set. Need/take/remain. Every C parser I still write uses them. Has
I tried the naive path first and wasted a morning. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. Caps on size and entry count are the feature. The parser is decoration. Took me 3 hours the first time.
@babatunde_k
I want the listing, not the decompiler story. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. If you inte
That insult was not a technical point. I am reporting it. This belongs in the first-hour ritual. The load-bearing line: Hot set vs slow set. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 9 hours the first time.
@rr_or_gtfo
I tried the naive path first and wasted a morning. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow
This is getting personal and it does not need to. I will argue the opposite and then probably agree. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. Caps on size and entry count are the feature. The parser is decoration. Took me 10 hours the first time.
@build
Please keep the hashes and drop the mystery zips. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. Caps on
I am reporting the sample-drop hint. Hash and corpus tag only. Same wall I hit last quarter. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. If you intern, intern copies. Views into a temp will haunt you. If anyone DMs me a zip I will not open it. Hash in-thread.
I want the listing, not the decompiler story. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. If you intern, intern copies. Views into a temp will haunt you. Took me 12 hours the first time.
Please keep the hashes and drop the mystery zips. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. Caps on size and entry count are the feature. The parser is decoration. Hash of the public file, or are we arguing a shape? I still have the snapshot named codi-98-pre.
This is the kind of thread that should be a sticky and is not. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. Dry-run default on destructive flags. Lab tools delete files. I wrote a 12-line script and then threw it away. The listing was enough.
@threx
This is the kind of thread that should be a sticky and is not. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot
You keep moving the goalposts. First it was the decoder, now it is the dump. This matches a public n-day class from last patch Tuesday. The load-bearing line: Hot set vs slow set. Checksums are not hashes. Stop keying maps with CRC32. I reproduced it on lab build 1186.
Came back to this after a coffee. Still hold. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. Need/take/remain. Every C parser I still write uses them. Took me 8 hours the first time.
@white
Came back to this after a coffee. Still hold. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set.
Decompiler output is a hypothesis. Treat it like one. Bookmarking this for the lab wiki. The load-bearing line: Hot set vs slow set. Need/take/remain. Every C parser I still write uses them. Hash of the public file, or are we arguing a shape? If anyone DMs me a zip I will not open it. Hash in-thread.