Are raw files necessary for Yara? Can the outputs of "strings" be fed to the yara processor?

2017-11-14 Thread plague22
I understand that some tweaking might be necessary to the yara processor, but I am wondering if something like this would be possbile. If in the past I had stored the "strings" output of a particular file, could I pump that into a modified yara processor and have everything work? Are there some

Re: Are raw files necessary for Yara? Can the outputs of "strings" be fed to the yara processor?

2017-11-15 Thread Wesley Shields
You could do that. You would lose any capabilities based upon most of the modules (PE, elf, etc). The math module would still work but I'm not sure how relevant it would be. More importantly I'm not sure what doing this would get you that running YARA on the original files wouldn't also get you,