March 7, 2015
View f51f42e

Capture YARA compiled condition string and anchor in struct cli_ac_lsig.

Steven Morgan authored on 2015/03/07 07:10:47
March 3, 2015
View ebf3953

add YARA condition processor (preliminary/work in progress)

Steven Morgan authored on 2015/03/03 09:37:50
February 26, 2015
View 39d0a15

Use YARA arena for rule memory.

Steven Morgan authored on 2015/02/26 04:52:33
View 7f74910

parser and memory management improvements.

Steven Morgan authored on 2015/02/26 01:14:27
February 25, 2015
View cc1c1c7

Fix memory leaks.

Steven Morgan authored on 2015/02/25 07:04:53
View 324fabb

Fix some ClamAV with YARA issues and turn on some more YARA parser features.

Steven Morgan authored on 2015/02/25 06:11:06
View bf80cd4

fix copy/paste

Steven Morgan authored on 2015/02/25 00:24:51
February 24, 2015
View ede803c

Define strlcat to cli_strlcat.

Steven Morgan authored on 2015/02/24 08:05:53
View a5bde84

Fix for errors on YARA rules when hex constants have odd lengths.

Steven Morgan authored on 2015/02/24 07:17:08
February 21, 2015
View 3ca6d4c

YARA work in progress: enable parser functions, add YARA arenas and hash tables.

Steven Morgan authored on 2015/02/21 07:31:10
December 15, 2014
View b3a7a51

Handle yara entrypoint keyword in prototype.

Steven Morgan authored on 2014/12/15 12:23:04
December 13, 2014
View e9b611f

Fix bug in ldb length calculation for yara hex strings, refine 'all/any of them' condition handling, handle EMALFDB errors from yara strings, add some metrics.

Steven Morgan authored on 2014/12/13 00:23:36
December 12, 2014
View b9af043

Support yara 'all of them/any of them' conditions, enforce maximum subsig constraint, and fix signature length calculation error.

Steven Morgan authored on 2014/12/12 19:52:48
December 11, 2014
View 93ff0da

Define some flags for yara prototype.

Steven Morgan authored on 2014/12/11 21:20:25
December 10, 2014
View 88c4a39

work in progress: support more yara parser functionality.

Steven Morgan authored on 2014/12/10 23:49:22