proc_yara

Plugin

ArgDescriptionType
rulesYara rulesstring (required)
pidThe pid to scanint (required)
contextReturn this many bytes either side of a hitint
keyIf set use this key to cache the yara rules.string

Description

Scan processes using yara rules.

This plugin uses yara’s own engine to scan process memory for the signatures.

Process memory access depends on having the SeDebugPrivilege which depends on how Velociraptor was started. Even when running as System, some processes are not accessible.

comments powered by Disqus