Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

several general issues #2

Open
omrirefaeli opened this issue Oct 23, 2019 · 1 comment
Open

several general issues #2

omrirefaeli opened this issue Oct 23, 2019 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@omrirefaeli
Copy link

  1. Loki IOC folder is not in the right place by default.
    I should have copied it from /opt/calamity/signature-base to /opt/calamity/Loki/signature-base
  2. calamity log always says ClamAV has some finding while the actual log of ClamAV is empty
  3. idk if it is in your hands, but while loki operating, it has bunch of errors saying the field pe.imphash() doesnt exist in many yara rules
@Hestat
Copy link
Owner

Hestat commented Oct 27, 2019

Will take a peak into these later this week.

  1. does seem to be an error will try to resolve in the script.

  2. currently script will write headers for clamav and loki by default, if there is nothing below them then nothing was found. May look into adding checks for content to make output less confusing.

  3. I believe this comes down to how the user installs yara, may be doable in the docker container, but no sure in the general script as dependent on user's base os

@Hestat Hestat added the enhancement New feature or request label Oct 27, 2019
@Hestat Hestat self-assigned this Oct 27, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants