It will be great to have the additional pre-processing modules subsystem that can transform original data, e.g extracting, unpacking, decrypting or other kinds of tasks before the scan, without need to use custom yara modules functions and full potential of yara search engine.
Example modules can be:
detect/unpack and upx, pyinstaller, asar, dmg, msi, zip ...
I'm sure with the right SDK for such functionality community will produce a lot of useful stuff.
It will be great to have the additional pre-processing modules subsystem that can transform original data, e.g extracting, unpacking, decrypting or other kinds of tasks before the scan, without need to use custom yara modules functions and full potential of yara search engine.
Example modules can be:
I'm sure with the right SDK for such functionality community will produce a lot of useful stuff.