Neo23x0 / signature-base

YARA signature and IOC database for my scanners and tools
Other
2.49k stars 605 forks source link

feat: add new rule related to moveit exploitation #264

Closed nasbench closed 1 year ago

Neo23x0 commented 1 year ago

The problem with "LOG" rules in the public repo is that not only THOR Lite uses that repo but also LOKI and other people with their YARA scanning engines that wouldn't apply "LOG" rules in the right way. Just recently I had a problem with LOG_LibSSH_Auth_Bypass_CVE_2023_2283_Jun23_1 that caused many FPs because it matched on many different files, not just log lines in log files.

Neo23x0 commented 1 year ago

But it looks okay : Screenshot 2023-06-14 at 08 40 23