yara4ida
YARA for IDA
Unofficial YARA IDA Pro plugin, along with an unparalleled crypto/hash/compression rule set based on
Luigi Auriemma's signsrch signatures.
And as a general upgraded replacement for my deprecated IDA Signsrch plugin.
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!
安装
将yara4ida.dll,yara4ida64.dll和yara4ida_rules文件夹复制到您的 IDAplugins目录。
默认的 IDA 热键是“Ctrl-Y”,但可以通过 IDA“plugins.cfg”配置文件配置为另一个。
需要 IDA Pro 版本 7.7'ish。