Skip to Content
Hands-On Security in DevOps
book

Hands-On Security in DevOps

by Tony Hsiang-Chih Hsu
July 2018
Intermediate to advanced
356 pages
9h 18m
English
Packt Publishing
Content preview from Hands-On Security in DevOps

Malware behavior matching – YARA

YARA (https://virustotal.github.io/yara/) is a pattern-matching Swiss army knife for malware detection. YARA rules consist of the descriptions of malware characteristics based on textual or binary patterns. YARA can be used to perform malware detection, and the detection signatures can also be easily defined. The YARA scanner/rules can be seen as an antivirus scanner and signatures.

For example, say that one host identifies suspicious webshell activities, but the antivirus software does not detect any suspicious activities. The security administrator can use the YARA detector with predefined YARA rules to scan all the files on the host or to scan the collected logs. Here is one example of a YARA rule to detect ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Securing DevOps

Securing DevOps

Julien Vehent
Kubernetes Security

Kubernetes Security

Liz Rice, Michael Hausenblas
Three Essentials for Agentic AI Security

Three Essentials for Agentic AI Security

Paolo Dal Cin, Daniel Kendzior, Yusof Seedat, Renato Marinho
Security Automation with Ansible 2

Security Automation with Ansible 2

Akash Mahajan, MADHU AKULA

Publisher Resources

ISBN: 9781788995504Other