Open JSCU-CNI opened 3 months ago
Can you also elaborate the reasoning for moving this towards target-yara and removing the functionality from target-query? On the one hand I can understand that it's nice to be able to run target-yara, but I don't understand the reasoning for completely walling it off from target-query. Is it a design choice?
target.yara()
is still accessible programmatically and for cli invocations we now have target-yara
. It's a design choice. Initially both still worked, but with a very elaborate method on defining argparse arguments. Decided against that and now we're here.
~Is YARA-X integration welcome in this PR, or should we wait until this has been merged in main
?~ We will push this to a separate PR.
It seems like that was all feedback, apologies for the delay @Schamper. Is this good to go now?
This PR aims to improve the YARA plugin.
dissect.target.plugins.filesystem.yara
is now anInternalPlugin
target-yara
is now a command which calls thefilesystem.yara
plugintarget-query -f yara
will no longer work as it is replaced bytarget-yara
filesystem.yara
andtarget-yara