{"id":3400,"date":"2017-07-28T21:57:52","date_gmt":"2017-07-28T13:57:52","guid":{"rendered":"https:\/\/ixyzero.com\/blog\/?p=3400"},"modified":"2017-07-28T21:57:52","modified_gmt":"2017-07-28T13:57:52","slug":"yara%e4%b9%8bwhatwhyhow","status":"publish","type":"post","link":"https:\/\/ixyzero.com\/blog\/archives\/3400.html","title":{"rendered":"YARA\u4e4bwhat&#038;why&#038;how"},"content":{"rendered":"<p>=Start=<\/p>\n<h4 id=\"YARA\u4e4bwhat&amp;why&amp;how-\u7f18\u7531\uff1a\">\u7f18\u7531\uff1a<\/h4>\n<p><a class=\"external-link\" href=\"https:\/\/github.com\/search?o=desc&amp;q=yara&amp;s=stars&amp;type=Repositories&amp;utf8=%E2%9C%93\" rel=\"nofollow\">https:\/\/github.com\/search?o=desc&amp;q=yara&amp;s=stars&amp;type=Repositories&amp;utf8=%E2%9C%93<\/a><\/p>\n<h4 id=\"YARA\u4e4bwhat&amp;why&amp;how-\u6b63\u6587\uff1a\">\u6b63\u6587\uff1a<\/h4>\n<h5 id=\"YARA\u4e4bwhat&amp;why&amp;how-\u53c2\u8003\u89e3\u7b54\uff1a\">\u53c2\u8003\u89e3\u7b54\uff1a<\/h5>\n<p><span style=\"color: #0000ff;\"><strong>YARA\u662f\u4ec0\u4e48\uff1f<\/strong><\/span><\/p>\n<p>\u6a21\u5f0f\u5339\u914d\u4e2d\u7684\u745e\u58eb\u519b\u5200\uff08The pattern matching swiss knife\uff09<\/p>\n<div class=\"row\">\n<div id=\"outputText\" class=\"row small_font\">\n<div class=\"translated_result\">\n<p class=\"tgt\">YARA\u662f\u4e00\u6b3e\u65e8\u5728(\u4f46\u4e0d\u9650\u4e8e)\u5e2e\u52a9\u6076\u610f\u8f6f\u4ef6\u7814\u7a76\u4eba\u5458\u8bc6\u522b\u548c\u5206\u7c7b\u6076\u610f\u8f6f\u4ef6\u6837\u672c\u7684\u5de5\u5177\u3002\u4f7f\u7528YARA\uff0c\u60a8\u53ef\u4ee5\u6839\u636e\u6587\u672c\u6216\u4e8c\u8fdb\u5236\u6a21\u5f0f\u521b\u5efa\u6076\u610f\u8f6f\u4ef6\u5bb6\u65cf(\u6216\u60a8\u60f3\u8981\u63cf\u8ff0\u7684\u4efb\u4f55\u4e1c\u897f)\u7684\u63cf\u8ff0\u3002\u6bcf\u4e00\u4e2a\u63cf\u8ff0\uff0c\u79f0\u4e3a\u89c4\u5219\uff0c\u7531\u4e00\u7ec4\u5b57\u7b26\u4e32\u548c\u4e00\u4e2a\u51b3\u5b9a\u5176\u903b\u8f91\u7684\u5e03\u5c14\u8868\u8fbe\u5f0f\u7ec4\u6210\u3002<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><span style=\"color: #0000ff;\"><strong>YARA\u7684\u4f18\u52bf\u5728\u54ea\uff1f<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"color: #ff0000;\"><strong>YARA\u9002\u7528\u4e8e\u591a\u5e73\u53f0<\/strong><\/span>\uff0c\u53ef\u8fd0\u884c\u5728Windows\u3001Linux\u548cMac OS X\u4e0a\uff0c\u5e76\u4e14\u53ef\u4ee5\u901a\u8fc7\u5b83\u7684\u547d\u4ee4\u884c\u63a5\u53e3\u6216\u5728\u4f60\u81ea\u5df1\u7f16\u5199\u7684Python\u811a\u672c\u4e2d\u5f15\u5165yara-python\u6269\u5c55\u6765\u4f7f\u7528\u5b83\u3002<\/li>\n<li><span style=\"color: #ff0000;\"><strong>\u6709\u793e\u533a\u5e2e\u4f60\u7ef4\u62a4\/\u66f4\u65b0\u5404\u79cd\u89c4\u5219<\/strong><\/span>\uff0c\u4e0d\u8bba\u662f\u6076\u610f\u8f6f\u4ef6\u8fd8\u662fwebshell\u3002<\/li>\n<\/ul>\n<p><span style=\"color: #0000ff;\"><strong>YARA\u6709\u54ea\u4e9b\u5e94\u7528\uff1f<\/strong><\/span><\/p>\n<ul>\n<li><a href=\"http:\/\/www.osquery.io\/\">osquery<\/a><\/li>\n<li><a href=\"https:\/\/www.payload-security.com\/\">Payload Security<\/a><\/li>\n<li><a href=\"http:\/\/phishme.com\/\">PhishMe<\/a><\/li>\n<li><a href=\"http:\/\/www.symantec.com\/\">Symantec<\/a><\/li>\n<li><a href=\"http:\/\/www.trendmicro.com\/\">Trend Micro<\/a><\/li>\n<li><a href=\"https:\/\/www.virustotal.com\/intelligence\/\">VirusTotal Intelligence<\/a><\/li>\n<li>\u2026\u2026<\/li>\n<\/ul>\n<h5 id=\"YARA\u4e4bwhat&amp;why&amp;how-\u53c2\u8003\u94fe\u63a5\uff1a\">\u53c2\u8003\u94fe\u63a5\uff1a<\/h5>\n<p><a class=\"external-link\" href=\"https:\/\/github.com\/VirusTotal\/yara\" rel=\"nofollow\">https:\/\/github.com\/VirusTotal\/yara<\/a><br \/>\n<a class=\"external-link\" href=\"http:\/\/yara.readthedocs.io\/en\/latest\/index.html\" rel=\"nofollow\">http:\/\/yara.readthedocs.io\/en\/latest\/index.html<\/a><\/p>\n<p><a class=\"external-link\" href=\"https:\/\/github.com\/Yara-Rules\/rules\" rel=\"nofollow\">https:\/\/github.com\/Yara-Rules\/rules<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/nbs-system\/php-malware-finder\" rel=\"nofollow\">https:\/\/github.com\/nbs-system\/php-malware-finder<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/Neo23x0\/yarGen\" rel=\"nofollow\">https:\/\/github.com\/Neo23x0\/yarGen<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/Neo23x0\/yarAnalyzer\" rel=\"nofollow\">https:\/\/github.com\/Neo23x0\/yarAnalyzer<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/mitre\/multiscanner\" rel=\"nofollow\">https:\/\/github.com\/mitre\/multiscanner<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/Xen0ph0n\/YaraGenerator\" rel=\"nofollow\">https:\/\/github.com\/Xen0ph0n\/YaraGenerator<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/godaddy\/procfilter\" rel=\"nofollow\">https:\/\/github.com\/godaddy\/procfilter<\/a><\/p>\n<p><a class=\"external-link\" href=\"https:\/\/github.com\/Yara-Rules\/rules\/tree\/master\/Webshells\" rel=\"nofollow\">https:\/\/github.com\/Yara-Rules\/rules\/tree\/master\/Webshells<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/phishme\/malware_analysis\/tree\/master\/yara_rules\" rel=\"nofollow\">https:\/\/github.com\/phishme\/malware_analysis\/tree\/master\/yara_rules<\/a><br \/>\n<a class=\"external-link\" href=\"https:\/\/github.com\/tenable\/yara-rules\" rel=\"nofollow\">https:\/\/github.com\/tenable\/yara-rules<\/a><\/p>\n<p><a class=\"external-link\" href=\"https:\/\/www.tenable.com\/blog\/hunting-for-web-shells\" rel=\"nofollow\">https:\/\/www.tenable.com\/blog\/hunting-for-web-shells<\/a><br \/>\n<a class=\"external-link\" href=\"http:\/\/www.tenable.com\/blog\/hunting-linux-malware-with-yara\" rel=\"nofollow\">http:\/\/www.tenable.com\/blog\/hunting-linux-malware-with-yara<\/a><br \/>\n<a class=\"external-link\" href=\"http:\/\/www.tenable.com\/blog\/threat-hunting-with-yara-and-nessus\" rel=\"nofollow\">http:\/\/www.tenable.com\/blog\/threat-hunting-with-yara-and-nessus<\/a><\/p>\n<p>=END=<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=Start= \u7f18\u7531\uff1a https:\/\/github.com\/search?o=desc&amp;q=yara [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,25,12],"tags":[847],"class_list":["post-3400","post","type-post","status-publish","format-standard","hentry","category-knowledgebase-2","category-security","category-tools","tag-yara"],"views":11359,"_links":{"self":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/3400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/comments?post=3400"}],"version-history":[{"count":2,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/3400\/revisions"}],"predecessor-version":[{"id":3454,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/3400\/revisions\/3454"}],"wp:attachment":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/media?parent=3400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/categories?post=3400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/tags?post=3400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}