chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
387 stars 24 forks source link

add generic /dev path detection #147

Closed tstromberg closed 3 months ago

tstromberg commented 3 months ago

References to /dev should be highlighted - tagged as "notable"

The etc template is a good one to base it on:

https://github.com/chainguard-dev/bincapz/blob/fbdc4baa2a5448cb7508111900fe56209ff53608/rules/ref/path/etc.yara#L4