/keepass_CVE-2023-24055_yara_rule

Contains a simple yara rule to hunt for possible compromised KeePass config files

Primary LanguageYARA

keepass_CVE-2023-24055_yara_rule

Contains a simple yara rule to hunt for possible compromised KeePass config files

How-to

Use a yara rule scanner, like yara, loki or thor-lite to scan systems with this rule. The default location for the local KeePass config file is %APPDATA%\Roaming\KeePass\KeePass.config.xml.