Open ruppde opened 9 months ago
to: @airbnb/binaryalert-maintainers cc: size: small resolves #
rule produces false positives on e.g. debians /usr/share/doc/hashcat-data/examples/example.dict
require MZ bytes
running yara on mimikatz.exe
to: @airbnb/binaryalert-maintainers cc:
size: small
resolves #
Background
rule produces false positives on e.g. debians /usr/share/doc/hashcat-data/examples/example.dict
Changes
require MZ bytes
Testing
running yara on mimikatz.exe