It's all about the structure! Creating YARA rules by clicking
#1
Information 
Quote:
[Image: Logo_VT_Horizontal.png]

Since we made our (extended) vt module available for LiveHunt YARA rules we understand it is not easy for analysts to keep in mind all the new potential possibilities - too many of them! Our goal is to make YARA rule creation as easy as possible while providing security experts everything they need to make even more powerful rules.

Our recently published new YARA editor, which incorporates full syntax coloring and auto-complete while you develop your rule, is a first step.

However, we wanted to go further. We already discussed how you can use predefined templates (additionally you can check our Threat Hunting with VirusTotal - Episode 4 for further examples and ideas), but in this post we want to focus on a terrific new feature when creating rules using the “Structure” of any given object (file, URL, domain or IP).

“Structure” provides the full JSON containing all details VirusTotal knows for any given indicator. For instance, you can paste a file hash and you will get full details about its behaviour and metadata. What is better, you can simply click on any field you are interested in, and it will automatically included in a fresh new YARA rule in the editor - no need to remember how to get that particular field in the VT module anymore.

In case you are wondering, this also deals with all kinds of loops. If any of the selected fields needs to be iterated, the correct syntax will automatically be added to your rule.Let’s check the different object types. 

Files

For a file object you will find two different branches in the resulting JSON - behaviour and metadata.The behaviour key is based on the sample execution in the sandbox. For example, you can create rules based on files written by the malware, files dropped, mutexes created, processes created, sigma results or ATT&CK MITRE results, among others.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft releases KB5070773 out of band...
Microsoft has rele...harlan4096 — 10:23
AdGuard for iOS v4.5.14
AdGuard for iOS v4...harlan4096 — 08:49
AVLab.pl - Advanced In-The-Wild Malware ...
Hi Community We...harlan4096 — 08:48
K. STANDARD / PLUS / PREMIUM 21.23
K. STANDARD / PLUS /...harlan4096 — 07:12
Notepad++ 8.8.7
Notepad++ 8.8.7 ...harlan4096 — 07:09

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (47)Michaelaceve
avatar (37)QuadirLigh
avatar (38)Mblippek
avatar (44)viecontAceve
avatar (40)Michaelcrini

[-]
Online Staff
There are no staff members currently online.

>