mkYARA – Writing YARA rules for the lazy analyst
ID: ddb3e5c3-4837-57c0-b4b8-f9e698f43157
STIX ID: report--ddb3e5c3-4837-57c0-b4b8-f9e698f43157
Feed Name: Fox-IT blog
mkYARA is a tool that automates creation of YARA rules from executable code by disassembling code with the Capstone library and wildcarding non-static elements; it currently supports x86 and x86-64 and is available as a pip package with an IDA Pro plugin for in-place rule generation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
