YARA scans in WinDbg

Because InfoSec loves RegExes.

Matt Suiche
Comae Technologies
1 min readFeb 7, 2018

--

Andrey Bazhan, from Comae Technologies, just made a neat addition to SwishDbgExt which is the ability to use Yara rules to hunt process in memory via a new command called !ms_yarascan

You can refer to the commit for more information.

Search through a specific process

Search through all processes

--

--

Matt Suiche
Comae Technologies

Hacker, Microsoft MVP, Founder of @ComaeIo — Co-Founder of @CloudVolumes (now @VMWare)