Module patterns

Module patterns 

Source
Expand description

Common YARA pattern libraries Provides pre-defined patterns for various detection scenarios

Constants§

C2_PATTERNS
Command and control (C2) patterns
ENCRYPTION_APIS
Common encryption API patterns
FILE_HEADERS
File header patterns for common file types
OBFUSCATION_PATTERNS
Code obfuscation patterns
PERSISTENCE_REGISTRY_KEYS
Common registry persistence keys
PROCESS_INJECTION
Common process injection patterns
RANSOMWARE_EXTENSIONS
Common ransomware file extensions
SANDBOX_EVASION
Common sandbox evasion techniques

Functions§

generate_base64_pattern
Generate base64 pattern
generate_hex_pattern
Generate hex pattern with wildcards
generate_sha256_pattern
Generate SHA256 pattern