{"id":20101032,"url":"https://github.com/fkie-cad/yapscan","last_synced_at":"2025-11-12T21:44:48.308Z","repository":{"id":41169982,"uuid":"312225789","full_name":"fkie-cad/yapscan","owner":"fkie-cad","description":"Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.","archived":false,"fork":false,"pushed_at":"2023-07-24T03:08:55.000Z","size":672,"stargazers_count":62,"open_issues_count":10,"forks_count":14,"subscribers_count":5,"default_branch":"master","last_synced_at":"2025-11-12T21:44:47.933Z","etag":null,"topics":["golang","memory","security","yara","yara-scanner"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fkie-cad.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-11-12T09:20:39.000Z","updated_at":"2025-09-25T13:21:22.000Z","dependencies_parsed_at":"2024-06-20T15:19:33.315Z","dependency_job_id":"1e69600b-f2f0-4785-a031-97f411d8eefc","html_url":"https://github.com/fkie-cad/yapscan","commit_stats":null,"previous_names":[],"tags_count":26,"template":false,"template_full_name":null,"purl":"pkg:github/fkie-cad/yapscan","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkie-cad%2Fyapscan","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkie-cad%2Fyapscan/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkie-cad%2Fyapscan/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkie-cad%2Fyapscan/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fkie-cad","download_url":"https://codeload.github.com/fkie-cad/yapscan/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkie-cad%2Fyapscan/sbom","scorecard":{"id":402224,"data":{"date":"2025-08-11","repo":{"name":"github.com/fkie-cad/yapscan","commit":"5e7d582630b01b6a3e076baa17636657a5939af3"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.9,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/8 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/ci.yml:156","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:28","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:29","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/fkie-cad/yapscan/codeql-analysis.yml/master?enable=pin","Warn: containerImage not pinned by hash: cicd/Dockerfile.xwin:2","Warn: pipCommand not pinned by hash: cicd/generateReportFormatDocs.sh:22","Info:   0 out of  19 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned","Info:   0 out of   1 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU Affero General Public License v3.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.19.3 not signed: https://api.github.com/repos/fkie-cad/yapscan/releases/107660725","Warn: release artifact v0.19.2 not signed: https://api.github.com/repos/fkie-cad/yapscan/releases/94397855","Warn: release artifact v0.19.1 not signed: https://api.github.com/repos/fkie-cad/yapscan/releases/87047724","Warn: release artifact v0.18.0 not signed: https://api.github.com/repos/fkie-cad/yapscan/releases/85567064","Warn: release artifact v0.17.0 not signed: https://api.github.com/repos/fkie-cad/yapscan/releases/74297496","Warn: release artifact v0.19.3 does not have provenance: https://api.github.com/repos/fkie-cad/yapscan/releases/107660725","Warn: release artifact v0.19.2 does not have provenance: https://api.github.com/repos/fkie-cad/yapscan/releases/94397855","Warn: release artifact v0.19.1 does not have provenance: https://api.github.com/repos/fkie-cad/yapscan/releases/87047724","Warn: release artifact v0.18.0 does not have provenance: https://api.github.com/repos/fkie-cad/yapscan/releases/85567064","Warn: release artifact v0.17.0 does not have provenance: https://api.github.com/repos/fkie-cad/yapscan/releases/74297496"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 0 commits out of 22 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"11 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T20:20:16.160Z","repository_id":41169982,"created_at":"2025-08-18T20:20:16.160Z","updated_at":"2025-08-18T20:20:16.160Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":284115869,"owners_count":26949957,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-11-12T02:00:06.336Z","response_time":59,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["golang","memory","security","yara","yara-scanner"],"created_at":"2024-11-13T17:22:57.767Z","updated_at":"2025-11-12T21:44:48.284Z","avatar_url":"https://github.com/fkie-cad.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# yapscan ![build status](https://github.com/fkie-cad/yapscan/actions/workflows/ci.yml/badge.svg?branch=master) [![codecov](https://codecov.io/gh/fkie-cad/yapscan/branch/master/graph/badge.svg?token=Y2ANV37QH6)](https://codecov.io/gh/fkie-cad/yapscan) [![Go Report Card](https://goreportcard.com/badge/github.com/fkie-cad/yapscan)](https://goreportcard.com/report/github.com/fkie-cad/yapscan)\n\nYapscan is a **YA**ra based **P**rocess **SCAN**ner, aimed at giving more control about what to scan and giving detailed reports on matches.\n\n**The report format is now versioned and a stable version 1.1.0 is released with compatibility guarantees, see the [report format documentation](report/v1.1.0/README.md).**\n\n## Features\n\nYou can use yapscan to selectively scan the memory of running processes as well as files in local hard drives and/or mounted shares.\nThe most notable differences to stock yara are (see section [Usage](#usage)),\n\n- Supports loading yara-rules from an encrypted zip file to prevent anti-virus software from detecting rules as malicious.\n- Multiple yara rules can also be loaded recursively from a directory. \n- Can suspend processes to be scanned (use with care, may crash your system).\n- Allows for filtering of memory segments to be scanned based on size, type (image, mapped, private), state (commit, free, reserve), and permissions.\n- Allows for easy scanning of all running processes, local drives and/or mounted shares.\n- Comes with extensive reporting features to allow later analysis of efficacy of rules.\n- Matched memory segments can even be automatically dumped and stored as part of the \n\nOther quality-of-life features include\n\n- (Experimental) Report server: Run `yapscan receive :8000` on a secure machine and run `yapscan scan` with the `--report-server` flag on infected machines. No missing reports due to ransomware anymore.\n- Statically built, dependency free exe for Windows\n- Listing running processes\n- Listing and dumping memory segments of a specific process\n- Compiling yara rules and compressing them into an encrypted zip.\n- Provides an \"executable DLL\" for locked down environments such as VDIs (see section [Executable DLL](#executable-dll))\n- Anonymization of reports with either a predefined, or a randomly generated salt\n\nYapscan comes with support for both Windows and Linux, however Windows is the primary and most thoroughly tested target OS.\n\n## Usage\n\n*I'll write a proper man page soon. For now, use* `yapscan --help` and `yapscan \u003ccommand\u003e --help` for usage information.\n\n```\nCOMMANDS:\n   list-processes, ps, lsproc  lists all running processes\n   list-process-memory, lsmem  lists all memory segments of a process\n   dump                        dumps memory of a process\n   scan                        scans processes or paths with yara rules\n   receive                     starts a server receiving reports from other yapscan clients (see --report-server flag of scan command)\n   anonymize                   anonymize reports\n   zip-rules                   creates an encrypted zip containing compiled yara rules\n   join                        joins dumps with padding\n   crash-process, crash        crash a process\n   help, h                     Shows a list of commands or help for one command\n```\n\n```\n\u003e yapscan scan --help\nNAME:\n   yapscan scan - scans processes or paths with yara rules\n\nUSAGE:\n   yapscan scan [command options] [pid/path...]\n\nOPTIONS:\n   --rules value, -r value, -C value                                                                          path to yara rules file or directory, if it's a file it can be a yara rules file or a zip containing a rules file encrypted with password \"infected\"\n   --rules-recurse, --recurse-rules, --rr                                                                     if --rules specifies a directory, compile rules recursively (default: false)\n   --all-processes, --all-p                                                                                   scan all running processes (default: false)\n   --all-drives, --all-d                                                                                      scan all files in all local drives, implies --recurse (default: false)\n   --all-shares, --all-s                                                                                      scan all files in all mounted net-shares, implies --recurse (default: false)\n   --file-extensions value, -e value [ --file-extensions value, -e value ]                                    list of file extensions to scan, use special extension \"-\" as no extension, use --file-extensions \"\" to allow any (default: \"-\", \"so\", \"exe\", \"dll\", \"sys\")\n   --threads value, -t value                                                                                  number of threads (goroutines) used for scanning files (default: 6)\n   --full-report                                                                                              create a full report (default: false)\n   --scan-mapped-files                                                                                        when encountering memory-mapped files also scan the backing file on disk (default: false)\n   --report-dir value                                                                                         the directory to which the report archive will be written (default: current working directory)\n   --report-server value                                                                                      the address of the server, the reports will be sent to\n   --server-ca value                                                                                          CA.pem to use when validating the server\n   --client-cert value                                                                                        certificate.pem to use for client authentication\n   --client-key value                                                                                         key.pem to use for client authentication\n   --store-dumps                                                                                              store dumps of memory regions that match rules, implies --full-report, the report will be encrypted with --password (default: false)\n   --password value, -p value                                                                                 setting this will encrypt the report with the given password; ignored without --full-report\n   --pgpkey value, -k value                                                                                   setting this will encrypt the report with the public key in the given file; ignored without --full-report\n   --anonymize                                                                                                anonymize any output, hashing any usernames, hostnames and IPs with a salt (default: false)\n   --salt value                                                                                               the salt (base64 string) to use for anonymization, ignored unless --anonmyize is provided (default: random salt)\n   --verbose, -v                                                                                              show more information about rule matches (default: false)\n   --filter-permissions value, --f-perm value                                                                 only consider segments with the given permissions or more, examples: \"rw\" includes segments with rw, rc and rwx\n   --filter-permissions-exact value, --f-perm-e value [ --filter-permissions-exact value, --f-perm-e value ]  comma separated list of permissions to be considered, supported permissions: r, rw, rc, rwx, rcx\n   --filter-type value, --f-type value [ --filter-type value, --f-type value ]                                comma separated list of considered types, supported types: image, mapped, private\n   --filter-state value, --f-state value [ --filter-state value, --f-state value ]                            comma separated list of considered states, supported states: free, commit, reserve (default: \"commit\")\n   --filter-size-max value, --f-size-max value                                                                maximum size of memory segments to be considered, can be absolute (e.g. \"1.5GB\"), percentage of total RAM (e.g. \"10%T\") or percentage of free RAM (e.g. \"10%F\") (default: \"10%F\")\n   --filter-size-min value, --f-size-min value                                                                minimum size of memory segments to be considered\n   --filter-rss-ratio-min value, --f-rss-min value                                                            minimum RSS/Size ratio of memory segments to eb considered\n   --suspend, -s                                                                                              suspend the process before reading its memory (default: false)\n   --force, -f                                                                                                don't ask before suspending a process (default: false)\n   --help, -h                                                                                                 show help (default: false)\n```\n\nHere are some additional example usages\n\n```bash\n# Create rules zip (optional)\nyapscan zip-rules --output rules.zip rules.yara\n\n# Scan a process with PID 423 with default filters\nyapscan scan -r rules.zip 423\n# Scan all processes with default filters\nyapscan scan -r rules.zip --all-processes\n# Scan all processes and all local drives with default filters\nyapscan scan -r rules.zip --all-processes --all-drives\n# Scan everything with default filters\nyapscan scan -r rules.zip --all-processes --all-drives --all-shares\n\n# Only scan memory segments with execute permission or more\nyapscan scan -r rules.zip --filter-permissions x --all-processes\n# Only scan memory segments with exactly read and execute (not write)\nyapscan scan -r rules.zip --filter-permissions-exact rx --all-processes\n\n# Enable logging, reporting and auto dumping of matched segments\nyapscan --log-level debug --log-path yapscan.log scan -r rules.zip --full-report --store-dumps --all-processes\n```\n\n## Running as Service\n\nYapscan can be run as a windows service in order to gain SYSTEM privileges.\nThis allows you to crash even other windows services, using the crash command.\nRunning as service is currently an **experimental feature**.\n\nFor memory scanning this should not be necessary.\nIn my experiments it has been sufficient to run yapscan as administrator in order to read the memory of any process.\nIf you find a process that yapscan cannot scan with administrator privileges but that can be scanned as a service, please let me know in the [issues](https://github.com/fkie-cad/yapscan/issues/new).\n\nIn order to use yapscan as a service just prepend the `as-service` command to the command (and flags) you wish to execute.\nExample:\n\n```shell\n# Normal mode\n.\\yapscan.exe crash 42\n# Service mode\n.\\yapscan.exe as-service crash 42\n```\n\nThe output of the windows service is transmitted to the terminal via two TCP connections.\nIf this breaks a warning will be emitted.\nIn such a case the service may still be running, you just won't see any output.\nAlso CTRL-C will break the proxy command, preventing you from seeing any output, but will not affect the running service.\nIf you want to kill the service, you'll have to use the windows service manager for now.\n\n## Executable DLL\n\n**The DLL built by this project is not a usual DLL, meant for importing functions from.**\nInstead it acts similarly to the exe with two exported, high-level entry points:\n\n```C\n// start acts same as you would expect a main function to act.\n// It assumes a terminal with stdout/stderr and stdin has already\n// been allocated.\nextern int start(int argc, char** argv);\n\n// run is meant for use with rundll32.\n// It opens a new console window via AllocConsole(), then parses the\n// lpCmdLine to extract the arguments and calls starts yapscan\n// with the extracted arguments. \nextern void run(HWND hWnd, HINSTANCE hInst, LPTSTR lpCmdLine, int nCmdShow);\n```\n\nSome environments like VDIs (Virtual Desktop Infrastructure) may prevent the execution of arbitrary exe-files but still allows for use of arbitrary DLLs.\nIf you gain access to a command line terminal in such an environment you can call yapscan via the built DLL like so.\n\n```shell\nrundll32.exe yapscan.dll,run scan -r rules.zip --all-processes\n```  \n\n**NOTE**: This feature is still experimental!\nThere very likely are quirks with the argument parsing. \n\n## State of this project\n\n**BETA, FeatureFreeze**\n\nRight now yapscan is in a beta period.\nI am currently working on a stable 1.0 release.\nThis release will have a defined and documented stable API and cli interface that will remain backwards compatible for all 1.x versions.\nBefore releasing 1.0 I also want to have at least a reasonable amount of test-coverage.\n\nFeel free to use and test it and open issues for any bugs you may find.\nIf you would like to have some additional features you can also open an issue with a feature request, but until the 1.0 release I will not be working on or merging any new features.\n\n## Contributing\n\nFound a bug or want a feature, but you can't code or don't have the time?\nFeel free to open an issue! Please look for duplicates first.\n\nIf you want to contribute code, be it fixes or features, please open a pull request **on the develop branch** and mention any related issues.\n\nIn the rapid-development phase I have only used the master branch, but will switch very shortly to the [git-flow workflow](https://danielkummer.github.io/git-flow-cheatsheet/index.html).\nThis means the master branch will represent the latest stable release at any point in time and any work-in-progress is to be merged into the develop branch.\n\n## Scanning Technique\n\nThe actual scanning is left to the yara library.\nIn case of file scanning, the high level yara library function `yr_rules_scan_file` is used.\nThis function memory-maps the given file.\nScanning process memory, on the other hand, is done on a lower level.\nYapscan copies one memory segment at a time into a buffer in its own memory and then uses `yr_rules_scan_mem` in order to scan this buffer.\n\n## Building Yapscan\n\nTo build **natively on Linux**, for Linux you need install Go and the yara library.\nOnce you have installed the dependencies it's as easy as:\n\n```bash\n# Install Golang and libyara\ngit clone https://github.com/fkie-cad/yapscan\ncd yapscan/cmd/yapscan\ngo build\n```\n\nIf you want to build on Linux for Windows, all you need installed is docker.\n\n```bash\n# Install docker\ngit clone https://github.com/fkie-cad/yapscan\ncd yapscan/cicd/\n./crossBuildForWindows.sh\n```\n\nThe resulting binaries will be placed in `cicd/build/`.\n\nBuilding **natively on Windows**, using MSYS2 follow these instructions\n\n1. Install Go\n2. Install MSYS2 and follow the first steps on [the MSYS2 Website] of updating via pacman.\n3. Install build dependencies `pacman --needed -S base-devel git autoconf automake libtool mingw-w64-{x86_64,i686}-{gcc,make,pkgconf}`\n4. Open PowerShell in the `cicd/` directory and execute `.\\buildOnWindows.ps1 -MsysPath \u003cmsys_path\u003e -BuildDeps`\n   where `\u003cmsys_path\u003e` is the install directory for MSYS2, default is `C:\\msys64`.\n   **NOTE:** You'll have to press `Enter` on the MSYS window, once the dependencies are finished.\n5. Enjoy the built files in `cicd/build/`\n\nIf you want to run tests on Windows, you have to run `.\\cicd\\buildOnWindows.ps1 -BuildDeps` only once.\nThen you open PowerShell and execute `.\\cicd\\enableMingw.ps1 -MsysPath \u003cmsys_path\u003e` to set the appropriate environment variables.\nNow it's as easy as `go test -tags yara_static ./...`.\nThe `-tags yara_static` is necessary if you use the build scripts, as they do not install any windows DLLs but only the static libraries.\n\n**NOTE:** You might get inexplicable failures with `-race` on Windows.\nAccording to the [golang release notes for 1.14](https://golang.org/doc/go1.14#compiler), the new pointer arithmetic checks are somewhat overzealous on Windows.\nIn Golang v1.15 it seems this may not have been fixed, but the checks are enabled automatically.\nYou can deactivate them like this `go test -tags yara_static -race -gcflags=all=-d=checkptr=0 ./...`.\n\nYou don't have to rely on the powershell/bash scripts, but they are intended to make things as easy as possible at the cost of control over the compilation.\nIf you want more control, take a look at the scripts use and modify them or execute the commands individually.\nThe scripts perform the following tasks.\n\n1. Start \"MSYS2 MinGW 64-bit\"\n    1. Download OpenSSL from github\n    2. Static-Build OpenSSL and install the development files\n    3. Download libyara from github\n    4. Static-Build libyara and install it\n2. Set some environment variables in powershell, to allow the use of the mingw toolchain\n3. Call the `go build` command with the appropriate build tag for static builds\n\n## Thanks and Mentions\n\n- Thanks to [@hillu] (author of [go-yara]), for pointing me in the right direction for building natively on windows.\n  See #7 and the links therein if you want some more details.\n- Thanks to Joris for implementing optimized scanning on linux, avoiding OOM problems. See #25 for details.\n\n[the MSYS2 Website]: https://www.msys2.org/\n[@hillu]: https://github.com/hillu/\n[go-yara]: https://github.com/hillu/go-yara/","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffkie-cad%2Fyapscan","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffkie-cad%2Fyapscan","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffkie-cad%2Fyapscan/lists"}