XORsearch: Searching With Regexes, (Mon, Apr 7th)
ID: de07cb2d-5d8d-5e78-838d-86a4fe0627c8
STIX ID: report--de07cb2d-5d8d-5e78-838d-86a4fe0627c8
Feed Name: SANS ISC Diary
This post explains a practical method to use regex with XORsearch by first extracting all ASCII strings (-S) and then applying a regex via re-search.py (e.g., for IPv4), demonstrated on a Cobalt Strike beacon to reveal an IP address, URL path, XOR encoding, and key 0x0D; it also shows using -n for surrounding context and notes an upcoming YARA-based approach pending a Python version of XORsearch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
