Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/kevthehermit/YaraPcap

Process HTTP Pcaps With YARA
https://github.com/kevthehermit/YaraPcap

Last synced: about 11 hours ago
JSON representation

Process HTTP Pcaps With YARA

Awesome Lists containing this project

README

        

yaraPCAP
========

Yara Scanner For IMAP Feeds and saved Streams

###What it does:
- Reads a PCAP File and Extracts Http Streams.
- gzip deflates any compressed streams
- Scans every file with yara
- writes a report.txt
- optionally saves matching files to a Dir

###Usage
- Simple report
"python yaraPcap.py -r sampleReport.txt sample.yar sample.pcap"
- Save Matching Files
"python yaraPcap.py -s SampleDir sample.yar sample.pcap"

###Requirements
- Python
- Yara / PyYara
- TCPFlow 1.3 - https://github.com/simsong/tcpflow
- For windows edit the Script to point to your copy of the tcpflow binary. Line 29

###ToDo
- Save Report as XML
- Add More Detail to the Report