ida_yara Logo

ida_yara

0
Free
Visit Website

ida_yara is a Python script that can be used to scan data within an IDB using Yara. The code mimics IDA's find_text and find_binary. It creates the Yara signature based off of the search and its search flags. Usage: Same as IDA's find_text and find_binary. Example: ida_yara.yara_find_text(start_ea, y, x, ustr, sflag=0) ida_yara.yara_find_binary(start_ea, ubinstr, radix=16, sflag=0) Search Flags: SEARCH_UP = search up return single match SEARCH_DOWN = search down return single match SEARCH_UP|SEARCH_NEXT = return all up from ea with the order being closest to furthest SEARCH_DOWN|SEARCH_DOWN = return all down from ea SEARCH_DOWN = same as SEARCH_DOWN SEARCH_UNICODE = search for Unicode characters

FEATURES

ALTERNATIVES

A framework for reverse engineering Flutter apps with modified Flutter library for dynamic analysis and traffic monitoring.

A tool for reverse engineering Android apk files.

VMCloak is a tool for creating and preparing Virtual Machines for Cuckoo Sandbox.

Management portal for LoKi scanner with centralized database for scanning activities.

A web-based manager for Yara rules, allowing for storage, editing, and management of Yara rules.

An open-source binary debugger for Windows with a comprehensive plugin system for malware analysis and reverse engineering.

A PowerShell obfuscation detection framework designed to highlight the limitations of signature-based detection and provide a scalable means of detecting known and unknown obfuscation techniques.

A Python library for automating time-based blind SQL injection attacks

PINNED