spyre-project / spyre

simple YARA-based IOC scanner
GNU Lesser General Public License v3.0
164 stars 27 forks source link

Add log file scanner #54

Open hillu opened 3 years ago

hillu commented 3 years ago

The idea is to find log files and journald files on Linux, EVTX logs on Windows in their well-known locations and scan them for simple IOCs or YARA rules.