Search

Tag: yara

Making YARA better: Authenticode, .NET, Telfhash

YARA is a popular open-source tool for malware identification and classification. But if you are reading a blog post about YARA improvements, I will assume you are already familiar with what YARA is and what it offers.  We have been using YARA...

Yara: In Search Of Regular Expressions

This blog post is based on my paper Pattern Matching in YARA: Improved Aho-Corasick Algorithm and a pull request that I opened on the upstream version of Yara. My main goal is to describe the changes from a more practical point of view and also...