Commit ef6d971f by Antonio S

Added folder utils and rule to detect IPs

parent 9c0845a0
/*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as
long as you use it under this license.
*/
rule IP {
meta:
author = "Antonio S. <asanchez@plutec.net>"
strings:
$ip = /([0-9]{1,3}\.){3}[0-9]{1,3}/ wide ascii
condition:
$ip
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment