Unverified Commit b496aadd by jovimon Committed by GitHub

Update TOOLKIT_Mandibule.yar

parent ff43fadc
......@@ -52,15 +52,6 @@ private rule is__hex_mid_mandibule32 {
3 of them
}
private rule is__elf {
meta:
author = "@mmorenog,@yararules"
strings:
$header = { 7F 45 4C 46 }
condition:
$header at 0
}
rule TOOLKIT_Mandibule {
meta:
description = "Generic detection for ELF Linux process injector mandibule generic"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment