Skip to content

Helper scripts to automate the extraction of YARA rules from XProtectRemediators

Notifications You must be signed in to change notification settings

ald3ns/XPR-dump

Folders and files

NameName
Last commit message
Last commit date

Latest commit

510bf67 · Mar 5, 2024

History

13 Commits
Mar 5, 2024
Mar 5, 2024
Mar 5, 2024
Feb 26, 2024
Mar 5, 2024
Mar 5, 2024
Mar 5, 2024

Repository files navigation

XPR-dump

This repo contains all the supporting material for this blog post: https://alden.io/posts/secrets-of-xprotect/.

Keep in mind that if you don't have a commercial Binary Ninja license, you won't be able to run the extractor headlessly. You can still run it from within the app via File > Run Script....

Repo Structure

Files

  • setup.sh: a helper script to copy the remediators and perform extraction
  • xpr-dump.py: a binaryninja script to dump the strings from an XPR

Folders

  • /rules: all the cleaned YARA rules
  • /output: the raw output from string decryption
  • /notes: a collection of notes about a subset of the YARA rules

About

Helper scripts to automate the extraction of YARA rules from XProtectRemediators

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published