CARVIEW |
Select Language
HTTP/2 200
date: Sun, 27 Jul 2025 13:35:42 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
x-repository-download: git clone https://github.com/rabbitstack/fibratus.git
etag: W/"9eca4dd96a8e43adeb9f16e26caa8295"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=9CFHf6TPFOUAXhSx8cpbHn2IFJgjrTKgklyVW3Xyu2uGS6Wz6h7IUTD6lnzBTTOUoXs7uwEcztENBOSGw7HLDaxV8xYxzjysMD%2FImY2fF%2FfnpwxNLxMJGiaWD9CPS5Ms%2BvZDKb7NjRH5EPRqk8v32g77%2FuEtlC1OKvzItZ7cQFsV4b2Kudr2s2%2B0wuY00886dbzBI2%2FIL4Br9cj9dsjhSGOzqdd010CqccRoDb%2F2pq4TWfISlNBSNvHzCI5PVQuxIWDatH7z7KL5J5RQbjnFcw%3D%3D--zWkqct%2BR3D5fAltd--%2F1xCUfaBbP6Ssijv2C7QZQ%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.359194248.1753623341; Path=/; Domain=github.com; Expires=Mon, 27 Jul 2026 13:35:41 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Mon, 27 Jul 2026 13:35:41 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: D978:15E61D:DE3D3D:121AAF4:68862B2D
feat(yara): Revamp Yara scanner · rabbitstack/fibratus@c66f028 · GitHub
Copy file name to clipboard
Copy file name to clipboardExpand all lines: internal/etw/source_test.go
Copy file name to clipboardExpand all lines: pkg/config/_fixtures/fibratus.yml
Copy file name to clipboardExpand all lines: pkg/config/schema_windows.go
Copy file name to clipboardExpand all lines: pkg/yara/_fixtures/rules/dll.yar
Copy file name to clipboard
Copy file name to clipboard
Skip to content
Navigation Menu
{{ message }}
-
-
Notifications
You must be signed in to change notification settings - Fork 201
Commit c66f028
committed
feat(yara): Revamp Yara scanner
The Yara scanner is revamped to perform file and
memory scanning triggered by multiple signals. Aside
from the basic process creation and image loading, the
scan is initiated when the PE file is dropped in the file
system, or when the ADS (Alternate Data Stream) is created.
Memory scan is triggered under suspicious memory allocation or section mapping. Lastly, when the
registry binary value is set, the scan is also performed
on the binary blob.1 parent 59662d9 commit c66f028Copy full SHA for c66f028
File tree
Expand file treeCollapse file tree
16 files changed
+1678
-548
lines changedFilter options
- internal/etw
- _fixtures
- pkg
- config
- _fixtures
- kevent
- yara
- _fixtures/rules
- config
- types
Expand file treeCollapse file tree
16 files changed
+1678
-548
lines changedpkg/yara/_fixtures/yara-test.dll renamed to internal/etw/_fixtures/yara-test.dll
Copy file name to clipboardFile renamed without changes.
internal/etw/source_test.go
Copy file name to clipboardExpand all lines: internal/etw/source_test.go+15-5Lines changed: 15 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
256 | 256 |
| |
257 | 257 |
| |
258 | 258 |
| |
259 |
| - | |
260 | 259 |
| |
261 | 260 |
| |
262 | 261 |
| |
| |||
275 | 274 |
| |
276 | 275 |
| |
277 | 276 |
| |
| 277 | + | |
| 278 | + | |
278 | 279 |
| |
279 | 280 |
| |
280 | 281 |
| |
281 |
| - | |
282 |
| - | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
283 | 286 |
| |
284 | 287 |
| |
285 | 288 |
| |
| |||
292 | 295 |
| |
293 | 296 |
| |
294 | 297 |
| |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
295 | 303 |
| |
296 | 304 |
| |
| 305 | + | |
| 306 | + | |
297 | 307 |
| |
298 | 308 |
| |
299 | 309 |
| |
| |||
486 | 496 |
| |
487 | 497 |
| |
488 | 498 |
| |
489 |
| - | |
| 499 | + | |
490 | 500 |
| |
491 | 501 |
| |
492 | 502 |
| |
| |||
529 | 539 |
| |
530 | 540 |
| |
531 | 541 |
| |
532 |
| - | |
| 542 | + | |
533 | 543 |
| |
534 | 544 |
| |
535 | 545 |
| |
|
pkg/config/_fixtures/fibratus.yml
Copy file name to clipboardExpand all lines: pkg/config/_fixtures/fibratus.yml+4-4Lines changed: 4 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
223 | 223 |
| |
224 | 224 |
| |
225 | 225 |
| |
226 |
| - | |
227 |
| - | |
228 |
| - | |
229 |
| - | |
| 226 | + | |
230 | 227 |
| |
231 | 228 |
| |
232 | 229 |
| |
| 230 | + | |
| 231 | + | |
| 232 | + | |
233 | 233 |
| |
234 | 234 |
| |
235 | 235 |
| |
|
pkg/config/schema_windows.go
Copy file name to clipboardExpand all lines: pkg/config/schema_windows.go+4-9Lines changed: 4 additions & 9 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
484 | 484 |
| |
485 | 485 |
| |
486 | 486 |
| |
487 |
| - | |
488 |
| - | |
489 |
| - | |
490 |
| - | |
491 |
| - | |
492 |
| - | |
493 |
| - | |
494 |
| - | |
495 |
| - | |
| 487 | + | |
496 | 488 |
| |
497 | 489 |
| |
| 490 | + | |
| 491 | + | |
| 492 | + | |
498 | 493 |
| |
499 | 494 |
| |
500 | 495 |
| |
|
+9-2Lines changed: 9 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
211 | 211 |
| |
212 | 212 |
| |
213 | 213 |
| |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
214 | 221 |
| |
215 | 222 |
| |
216 | 223 |
| |
217 | 224 |
| |
218 |
| - | |
| 225 | + | |
219 | 226 |
| |
220 | 227 |
| |
221 | 228 |
| |
222 | 229 |
| |
223 | 230 |
| |
224 |
| - | |
| 231 | + | |
225 | 232 |
| |
226 | 233 |
| |
227 | 234 |
| |
|
pkg/yara/_fixtures/rules/dll.yar
Copy file name to clipboardExpand all lines: pkg/yara/_fixtures/rules/dll.yar-10Lines changed: 0 additions & 10 deletions
This file was deleted.
pkg/yara/_fixtures/rules/notepad.yar
Copy file name to clipboard+6-15Lines changed: 6 additions & 15 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
2 | 2 |
| |
3 | 3 |
| |
4 |
| - | |
| 4 | + | |
5 | 5 |
| |
| 6 | + | |
| 7 | + | |
6 | 8 |
| |
7 |
| - | |
| 9 | + | |
8 | 10 |
| |
9 |
| - | |
| 11 | + | |
10 | 12 |
| |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - |
pkg/yara/_fixtures/rules/regedit.yar
Copy file name to clipboard+12Lines changed: 12 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + |
+98-35Lines changed: 98 additions & 35 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| 22 | + | |
| 23 | + | |
22 | 24 |
| |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
23 | 30 |
| |
24 | 31 |
| |
25 |
| - | |
26 | 32 |
| |
| 33 | + | |
27 | 34 |
| |
28 | 35 |
| |
29 | 36 |
| |
30 | 37 |
| |
31 |
| - | |
32 |
| - | |
33 |
| - | |
34 |
| - | |
35 |
| - | |
36 |
| - | |
37 |
| - | |
38 |
| - | |
39 |
| - | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
40 | 53 |
| |
41 | 54 |
| |
42 | 55 |
| |
| |||
59 | 72 |
| |
60 | 73 |
| |
61 | 74 |
| |
62 |
| - | |
| 75 | + | |
63 | 76 |
| |
64 | 77 |
| |
65 | 78 |
| |
66 | 79 |
| |
67 | 80 |
| |
68 |
| - | |
69 |
| - | |
70 |
| - | |
71 |
| - | |
72 |
| - | |
73 |
| - | |
| 81 | + | |
| 82 | + | |
74 | 83 |
| |
75 | 84 |
| |
76 | 85 |
| |
77 | 86 |
| |
78 |
| - | |
| 87 | + | |
79 | 88 |
| |
80 |
| - | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
81 | 97 |
| |
82 |
| - | |
| 98 | + | |
| 99 | + | |
83 | 100 |
| |
84 | 101 |
| |
85 | 102 |
| |
86 | 103 |
| |
87 | 104 |
| |
88 | 105 |
| |
89 |
| - | |
90 |
| - | |
91 |
| - | |
| 106 | + | |
92 | 107 |
| |
93 | 108 |
| |
94 | 109 |
| |
| 110 | + | |
| 111 | + | |
| 112 | + | |
95 | 113 |
| |
96 | 114 |
| |
97 | 115 |
| |
| |||
111 | 129 |
| |
112 | 130 |
| |
113 | 131 |
| |
114 |
| - | |
115 |
| - | |
116 |
| - | |
| 132 | + | |
117 | 133 |
| |
118 | 134 |
| |
119 |
| - | |
120 |
| - | |
121 |
| - | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
122 | 141 |
| |
123 | 142 |
| |
124 |
| - | |
125 |
| - | |
126 |
| - | |
127 |
| - | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
128 | 148 |
| |
129 | 149 |
| |
130 | 150 |
| |
131 | 151 |
| |
132 | 152 |
| |
133 | 153 |
| |
134 |
| - | |
| 154 | + | |
135 | 155 |
| |
136 | 156 |
| |
137 |
| - | |
| 157 | + | |
138 | 158 |
| |
139 | 159 |
| |
140 | 160 |
| |
141 | 161 |
| |
142 | 162 |
| |
143 | 163 |
| |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
144 | 207 |
| |
145 | 208 |
| |
146 | 209 |
| |
|
You can’t perform that action at this time.
0 commit comments