simsong / bulk_extractor

This is the development tree. Production downloads are at:
https://github.com/simsong/bulk_extractor/releases
Other
1.07k stars 185 forks source link

Add support for YARA #320

Open simsong opened 2 years ago

simsong commented 2 years ago

Would this be useful?

tomnewman86 commented 2 years ago

Just wanted to give this a big old thumbs up!

simsong commented 2 years ago

Okay. Do you want yara run on every feature?

tomnewman86 commented 2 years ago

Personally I would yes.

Although this will likely cause a nice collection of false positives, I've found it better to figure out how to effectively filter these out after rather than potentially miss something significant.