pyllyukko / harden.yml

Ansible playbook for Linux hardening
MIT License
77 stars 9 forks source link

YARA #84

Open pyllyukko opened 10 months ago

pyllyukko commented 10 months ago
pyllyukko commented 1 month ago

It would be nice to have some YARA rule to detect malware like this:

gen_webshells.yar (from Arnims YARA rules) has a detection (WEBSHELL_ASP_Generic), but that file can't be used with ClamAV :(