Different behavior of the same Yara rules on Linux/Windows servers
ivankott opened this issue · 1 comments
ivankott commented
Hi! Could you please help me to understand whether it possible that the same files have a different number of Yara rules matches (with yara-python) while running on different operation systems (e.g. Linux/Windows)? And what is the possible reason for this is happening if so?
Unfortunately, I cannot share the documents, but in my case, there are far more matches for lots of files (OLE/OOXML docs) when running on Linux rather than Windows server. However, I use the same files, codes and rules (e.g. from here or here).
Thanks a bunch in advance!
Xumeiquer commented
Hi @ivankott, you should ask in the Yara repositry. https://github.com/VirusTotal/yara