Skip to content

Expanded config option #33

@mgreen27-r7

Description

@mgreen27-r7

Hi team,

I was checking out this repo on using a custom config for a webshell usecase.
I think it would be helpful to allow a custom configuration option to enter a string to match rule name - for example "webshell" would match on any rules with the name webshell or enable specifying a param to match string.

After cutting down targeted rules, you can then run qa/performance checks etc.

I couldnt see if there was an option to do this directly in yara-forge, so at the moment I think im better off using a simple plyara script with your output rules - but it would be a cool feature to include directly in yara-forge config options.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions