Skip to main content

File and analysis artifacts yara matcher for Karton framework

Project description

YaraMatcher karton service

Scans analyses and samples with yara rules and spawns tasks with appropiate tags.

Author: CERT.pl

Maintainers: nazywam

Consumes:

{
    "type": "sample",
    "stage": "recognized",
    "kind": "runnable"
}, {
    "type": "sample",
    "stage": "recognized",
    "kind": "dump"
}, {
    "type": "analysis",
    "kind": "cuckoo1"
}, {
    "type": "analysis",
    "kind": "drakrun"
}, {
    "type": "analysis",
    "kind": "joesandbox"
}

Produces:

{
    "type": "sample",
    "stage": "analyzed"
}

Usage

First of all, make sure you have setup the core system: https://github.com/CERT-Polska/karton

Then install karton-yaramatcher from PyPi:

$ pip install karton-yaramatcher

And run the karton service by pointing it to your YARA rules repository:

$ karton-yaramatcher --rules yara_rule_directory

Co-financed by the Connecting Europe Facility by of the European Union

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

karton_yaramatcher-1.3.0-py3-none-any.whl (6.9 kB view details)

Uploaded Python 3

File details

Details for the file karton_yaramatcher-1.3.0-py3-none-any.whl.

File metadata

File hashes

Hashes for karton_yaramatcher-1.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f674e0562c81f125edadf963cdf0bd16abc25bbf7b88ff9c5359d7a38d9fa85a
MD5 55341725c3ed9f2d611d098a6a0ac29c
BLAKE2b-256 2cd07a920fe7255ab7cc5f1fab566c078162941edd15ef3b6ef9d9555c69358b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page