Example Offensive Threat Hunting

Draiden Lv2Posted 11 May 2023 15:29

Apart from the very great tools we already have, I think if we put an extra Icon tool for Custom Yara rules offensive threat hunting. Would be gold. Hence, we are not waiting for custom scan time and as we all know all of the AV's out there are using signature bases which is the nature of AV's.

Now if we go for yara we go for memory base.
Images below are the example (only) where the Yara Icon will reside.

The only drawbacks on this is that, it needs tweaking during Yara Scan. Cause it will eat not much of memory but it will be quite lag depending on the options you're going to use. (ei: recursive, intense)
Yep this is just a Sangfor ES Teaser only..

Feel alike? Bump to help this suggestion accepted by developers.

An accepted suggestion earns you 100 to 1000 coins. For more active members in Suggestions board, a badge Product Consultant may be rewarded. What is Coin?

Enter your mobile phone number and company name for better service. Go

Draiden Lv2Posted 12 May 2023 22:20
Any thoughts R&D team?

Moderator on This Board


Started Topics



Trending Topics

Board Leaders