100DaysofYARA / 2023

Rules Shared by the Community from 100 Days of YARA 2023
77 stars 26 forks source link

add file_plist.yar #22

Closed shellcromancer closed 1 year ago

shellcromancer commented 1 year ago

Day 12: Adds identification of plist files (XML, binary, or generally embedded) and then uses that to look for common malware keys. Day 13: Adds identification of compiled AppleScript executables.