May 8, 2015
View d03c18b

Fix YARA arena management, improve error reporting, clean up some code.

Steven Morgan authored on 2015/05/08 04:50:37
April 1, 2015
View c9f0bba

YARA: support condition data access functions int8, int16, int32, uint8, uint16, and uint32.

Steven Morgan authored on 2015/04/01 06:02:51
March 31, 2015
View b7999b8

YARA: capture offsets in matcher and use for processing YARA condition 'at' clauses.

Steven Morgan authored on 2015/03/31 06:12:01
March 19, 2015
View d255498

Add YARA condition evaluation function. Add support for YARA 'of' clauses.

Steven Morgan authored on 2015/03/19 07:26:59
March 7, 2015
View f51f42e

Capture YARA compiled condition string and anchor in struct cli_ac_lsig.

Steven Morgan authored on 2015/03/07 07:10:47
March 3, 2015
View ebf3953

add YARA condition processor (preliminary/work in progress)

Steven Morgan authored on 2015/03/03 09:37:50
February 26, 2015
View 39d0a15

Use YARA arena for rule memory.

Steven Morgan authored on 2015/02/26 04:52:33
View 7f74910

parser and memory management improvements.

Steven Morgan authored on 2015/02/26 01:14:27
February 25, 2015
View cc1c1c7

Fix memory leaks.

Steven Morgan authored on 2015/02/25 07:04:53
View 324fabb

Fix some ClamAV with YARA issues and turn on some more YARA parser features.

Steven Morgan authored on 2015/02/25 06:11:06
View bf80cd4

fix copy/paste

Steven Morgan authored on 2015/02/25 00:24:51
February 24, 2015
View ede803c

Define strlcat to cli_strlcat.

Steven Morgan authored on 2015/02/24 08:05:53
View a5bde84

Fix for errors on YARA rules when hex constants have odd lengths.

Steven Morgan authored on 2015/02/24 07:17:08
February 21, 2015
View 3ca6d4c

YARA work in progress: enable parser functions, add YARA arenas and hash tables.

Steven Morgan authored on 2015/02/21 07:31:10
December 15, 2014
View b3a7a51

Handle yara entrypoint keyword in prototype.

Steven Morgan authored on 2014/12/15 12:23:04