3 ms·
a detection is typically a rule that describes known bad or suspicious behaviour. all simple rule would just be a list of malware hashes or domain names so ins
by kyrrewk 6y ago
a detection is typically a rule that describes known bad or suspicious behaviour. all simple rule would just be a list of malware hashes or domain names
so instead of writing rules using tools such as YARA: https://github.com/fireeye/sunburst_countermeasures/blob/main/all-yara.yar https://github.com/fireeye/sunburst_countermeasures/blob/mai... (sunburst)
they want to write them in python