markmckinnon/Autopsy-Plugins

[request] Yara plugin

ctmayhew opened this issue · 3 comments

Would be great if you could make a YARA plugin. For example run x number of YARA rules against the E01 file.

Hi Chris.

John Lukach created a plugin for YARA a few years ago. Have you tried that out to see if it will meet your needs? You can find the plugin here https://github.com/jblukach/AutopsyModules along with the other plugins that he has written.

Mark

Ah thank you !

Hi Chris,

If that plugin does not work or you need something more let me know. Also if you have any more ideas for plugins you can fill out a very very short survey about your need/request here and it can be added to the list of plugins I am creating. https://www.surveymonkey.com/r/MKX732H.

Mark