chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
387 stars 24 forks source link

Improve rules based on LightSpy + add Huntress to third_party #169

Closed tstromberg closed 2 months ago

tstromberg commented 2 months ago

I tested bincapz against the samples noted in https://www.huntress.com/blog/lightspy-malware-variant-targeting-macos and made some improvements.

This does pull in a handful of YARA rules that huntress provides, and includes a Makefile rule to update them in the future. MIT Licensed.