Scan Artifact
4 min
Resumo
Executa o scan de regras YARA em um artefato.
Parâmetros
Parâmetro | Requerido | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|---|
artifact | Sim | string | | Artefato a ser escaneado. |
Exemplos
# Compilar uma regra YARA de fontes externas
- name: Pegar regra de um repositório
uri:
url: https://raw.githubusercontent.com/godaddy/yara-rules/master/example.yara
method: GET
return_content: yes
register: yara_rules
- name: Executar scan
yara_scan_artifact:
artifact: "abcdefgjiklmnoprhellostuvwx0123456789ABCDEFyz"
rules:
GithubRuleset: "{{ yara_rules.content }}"
register: result
- name: Escanear artefato a partir de uma regra em string
yara_scan_artifact:
artifact: "abcdefgjiklmnoprhellostuvwx0123456789ABCDEFyz"
rules:
hexExample: |
/* This will match any file containing "hello" anywhere. */
rule AsciiExample {
strings:$ascii_string = "hello"
condition:$ascii_string
}
register: resultValores retornados
Chave | Tipo | Retornado quando | Descrição |
|---|---|---|---|
scan_detection | string | Sempre | Saída da execução |