[Bro] Bro + Yara File Scanning Module?

Jason Batchelor jxbatchelor at gmail.com
Fri Jul 25 07:03:40 PDT 2014


Hello all:

I wanted to poke the hive mind to see if anyone has considered, or is
actively pursuing integrating Yara into a Bro script?

An idea for a script I would like to write is to simply take any file from
a 'file_new' event. Then add something like Files::ANALYZER_YARA that would
do the heavy lifting and take a user defined path to a master Yara file,
scan the file, append the results to either files.log or notice.log, and
finally, extract any file that hit on a signature (for further analysis).

Interested if this is something that has been considered previously? If so,
what were the results? If not, I'm happy to spin off an effort of my own.
Either way I see it as a good project to get into Bro scripting at a deeper
level.

Thanks,
Jason
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20140725/4321f9f8/attachment.html 


More information about the Bro mailing list