>_0xFORUM
Sign in

YARA on a drop folder: 800 rules without pegging a core

in Coding10 replies4.2k views

Hot set vs slow set. One Themida-shaped loop in the hot set and you are done.

The fast/slow split is the whole game. Profile the rules, not the engine.

Refs: YARA

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

@zonedude

Bookmarking this for the lab wiki. The load-bearing line: Hot set vs slow set. Need/take/remain. Every C parser I still write uses them. Has

I tried the naive path first and wasted a morning. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. Caps on size and entry count are the feature. The parser is decoration. Took me 3 hours the first time.

@babatunde_k

I want the listing, not the decompiler story. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. If you inte

That insult was not a technical point. I am reporting it. This belongs in the first-hour ritual. The load-bearing line: Hot set vs slow set. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 9 hours the first time.

@rr_or_gtfo

I tried the naive path first and wasted a morning. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow

This is getting personal and it does not need to. I will argue the opposite and then probably agree. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. Caps on size and entry count are the feature. The parser is decoration. Took me 10 hours the first time.

@build

Please keep the hashes and drop the mystery zips. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. Caps on

I am reporting the sample-drop hint. Hash and corpus tag only. Same wall I hit last quarter. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. If you intern, intern copies. Views into a temp will haunt you. If anyone DMs me a zip I will not open it. Hash in-thread.

I want the listing, not the decompiler story. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. If you intern, intern copies. Views into a temp will haunt you. Took me 12 hours the first time.

Please keep the hashes and drop the mystery zips. On «YARA on a drop folder: 800 rules without pegging a core»: Hot set vs slow set. Caps on size and entry count are the feature. The parser is decoration. Hash of the public file, or are we arguing a shape? I still have the snapshot named codi-98-pre.

This is the kind of thread that should be a sticky and is not. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. Dry-run default on destructive flags. Lab tools delete files. I wrote a 12-line script and then threw it away. The listing was enough.

@threx

This is the kind of thread that should be a sticky and is not. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot

You keep moving the goalposts. First it was the decoder, now it is the dump. This matches a public n-day class from last patch Tuesday. The load-bearing line: Hot set vs slow set. Checksums are not hashes. Stop keying maps with CRC32. I reproduced it on lab build 1186.

Came back to this after a coffee. Still hold. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set. Need/take/remain. Every C parser I still write uses them. Took me 8 hours the first time.

@white

Came back to this after a coffee. Still hold. «YARA on a drop folder: 800 rules without pegging a core» — specifically Hot set vs slow set.

Decompiler output is a hypothesis. Treat it like one. Bookmarking this for the lab wiki. The load-bearing line: Hot set vs slow set. Need/take/remain. Every C parser I still write uses them. Hash of the public file, or are we arguing a shape? If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.