Difference between revisions of "Yara"
Jump to navigation
Jump to search
(Created page with "{| style="float:right;border:1px solid black" |+ Details | Executable | <code>Archives.exe</code> |- | Stage | style="text-align:center;" | 6 |- | Percent Complete | style="te...") |
|||
| (One intermediate revision by the same user not shown) | |||
| Line 2: | Line 2: | ||
|+ Details | |+ Details | ||
| Executable | | Executable | ||
| − | | <code> | + | | <code>Yara.exe</code> |
|- | |- | ||
| Stage | | Stage | ||
| Line 11: | Line 11: | ||
|- | |- | ||
| Message Queue | | Message Queue | ||
| − | | <code> | + | | style="text-align:center;" | <code>yara</code> |
|} | |} | ||
Latest revision as of 12:57, 25 January 2021
| Executable | Yara.exe
|
| Stage | 6 |
| Percent Complete | 48% |
| Message Queue | yara
|
Yara ETL uses the malware scanning tool called, well, YARA to scan files. When a rule hits, the file will be tagged with the name of the rule. If any tags were specified in the YARA rule, they will also be applied to the file.
File Types
Yara scan the following types of files:
- Type_Parsable_MIME
- Type_PE
- Type_32bit_Windows_Executable
- Type_64bit_Windows_Executable
- Type_ROM_Windows_Executable
- Type_Adobe_PDF
- Type_XP_Prefetch
- Type_Vista7_Prefetch
- Type_TrueType_Font
- Type_DOS_Executable
- Type_TrueType_Font_Collection
- Type_OpenType_Font
- Type_Windows_Registry
- Type_SAM_Registry
- Type_System_Registry
- Type_Boot_Registry
- Type_User_Registry
- Type_Software_Registry
- Type_Xbox_Executable
- Type_Xbox_360_Executable
- Type_Windows_Event_Log
- Type_ELF_Executable
- Type_Android_Executable_35
- Type_Android_Executable_36
- Type_Windows_Registry_Fragment
- Type_Windows_XML_Event_Log
- Type_Obfuscated_TrueType_Font
- Type_Apple_Mach_O_Executable
- Type_81_Prefetch
- Type_LUA
- Type_XBE_Executable
- Type_Compressed_Prefetch
- Type_10_Prefetch