pub struct Scanner { /* private fields */ }Implementations§
Source§impl Scanner
impl Scanner
Sourcepub fn new(sig_set: SigSet) -> Self
pub fn new(sig_set: SigSet) -> Self
Create a new Scanner from a SigSet with default size limits.
§Default Limits
- Max extracted file size: 500 MB
- Max total extracted size: 2 GB
§Examples
use open_detect::{Scanner, SigSet, Signature};
let sig_set = SigSet::from_signature(
Signature("rule test { condition: true }".to_string())
).unwrap();
let scanner = Scanner::new(sig_set);Sourcepub fn with_max_extracted_size(self, size: usize) -> Self
pub fn with_max_extracted_size(self, size: usize) -> Self
Set the maximum size for individual extracted files (default: 500 MB).
This limit applies when scanning archives. Files larger than this limit will be skipped during archive extraction.
§Examples
use open_detect::{Scanner, SigSet};
let scanner = Scanner::new(sig_set)
.with_max_extracted_size(100 * 1024 * 1024); // 100 MBSourcepub fn with_max_total_extracted_size(self, size: usize) -> Self
pub fn with_max_total_extracted_size(self, size: usize) -> Self
Set the maximum total size for all extracted files (default: 2 GB).
This limit applies when scanning archives. Once the total size of extracted files exceeds this limit, extraction stops.
§Examples
use open_detect::{Scanner, SigSet};
let scanner = Scanner::new(sig_set)
.with_max_total_extracted_size(1024 * 1024 * 1024); // 1 GBSourcepub fn scan_buf(&self, buf: &[u8]) -> Result<ScanResult>
pub fn scan_buf(&self, buf: &[u8]) -> Result<ScanResult>
Scan a buffer of data for malicious content.
Automatically detects and extracts archives (ZIP, TAR, etc.) before scanning. If the buffer contains an archive, all files within will be scanned recursively.
§Errors
Returns an error if:
- The YARA scanner fails to scan the data
- Archive extraction fails (corrupted archive, etc.)
§Examples
use open_detect::{Scanner, SigSet, Signature, ScanResult};
let scanner = Scanner::new(sig_set);
let data = b"data to scan";
match scanner.scan_buf(data).unwrap() {
ScanResult::Clean => println!("No threats detected"),
ScanResult::Malicious(detections) => {
println!("Detected {} threats", detections.len());
}
}Sourcepub fn scan_file(&self, path: &Path) -> Result<ScanResult>
pub fn scan_file(&self, path: &Path) -> Result<ScanResult>
Scan a file for malicious content.
Reads the entire file into memory and scans it. Automatically detects and extracts archives before scanning.
§Errors
Returns an error if:
- The file cannot be read
- The YARA scanner fails to scan the data
- Archive extraction fails
§Examples
use open_detect::{Scanner, SigSet};
use std::path::Path;
let scanner = Scanner::new(sig_set);
let result = scanner.scan_file(Path::new("suspicious.exe")).unwrap();Sourcepub fn scan_buf_ft(
&self,
buf: &[u8],
file_type: &MimeType,
) -> Result<ScanResult>
pub fn scan_buf_ft( &self, buf: &[u8], file_type: &MimeType, ) -> Result<ScanResult>
Scan a buffer with an explicitly specified file type.
This is useful when you know the file type and want to skip automatic detection.
§Errors
Returns an error if:
- The YARA scanner fails to scan the data
- Archive extraction fails
§Examples
use open_detect::{Scanner, SigSet};
use mime_type::{MimeType, Archive};
let scanner = Scanner::new(sig_set);
let data = b"PK\x03\x04..."; // ZIP file data
let result = scanner.scan_buf_ft(
data,
&MimeType::Archive(Archive::Zip)
).unwrap();Sourcepub fn scan_file_ft(
&self,
path: &Path,
file_type: &MimeType,
) -> Result<ScanResult>
pub fn scan_file_ft( &self, path: &Path, file_type: &MimeType, ) -> Result<ScanResult>
Scan a file with an explicitly specified file type.
This is useful when you know the file type and want to skip automatic detection.
§Errors
Returns an error if:
- The file cannot be read
- The YARA scanner fails to scan the data
- Archive extraction fails
§Examples
use open_detect::{Scanner, SigSet};
use mime_type::{MimeType, Archive};
use std::path::Path;
let scanner = Scanner::new(sig_set);
let result = scanner.scan_file_ft(
Path::new("archive.zip"),
&MimeType::Archive(Archive::Zip)
).unwrap();Trait Implementations§
Auto Trait Implementations§
impl Freeze for Scanner
impl !RefUnwindSafe for Scanner
impl Send for Scanner
impl Sync for Scanner
impl Unpin for Scanner
impl !UnwindSafe for Scanner
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.