{% extends "base.html" %} {% set active_page = "Database" %} {% block body %}
rule a_hex_string_rule
{
strings:
$a = { 0A1B }
condition:
$a
}
rule a_ascii_string_rule
{
strings:
$a = "backdoor" ascii wide nocase
$b = "roodkcab" ascii wide nocase
condition:
$a or $b
}
rule a_regex_rule
{
strings:
$a = /vxworks 5\.\d+(\.\d+)?/ nocase
condition:
$a
}
Do you need more advanced rules? Have a look at the official yara documentation!