Directories
¶
| Path | Synopsis |
|---|---|
|
Package atomicio writes a file atomically (temp + rename) and keeps a single rollback backup.
|
Package atomicio writes a file atomically (temp + rename) and keeps a single rollback backup. |
|
Package extract is yarad's format-aware front-end.
|
Package extract is yarad's format-aware front-end. |
|
Package yarad is the out-of-process YARA scanner backend for rspamd.
|
Package yarad is the out-of-process YARA scanner backend for rspamd. |
|
Package mbazaar adds an abuse.ch MalwareBazaar attachment-hash lookup to yarad: the SHA256 of each scanned buffer (a MIME attachment, as the rspamd plugin POSTs it) is checked against a locally-cached set of SHA256 hashes of known malware samples.
|
Package mbazaar adds an abuse.ch MalwareBazaar attachment-hash lookup to yarad: the SHA256 of each scanned buffer (a MIME attachment, as the rspamd plugin POSTs it) is checked against a locally-cached set of SHA256 hashes of known malware samples. |
|
Package threatfox adds an abuse.ch ThreatFox IOC lookup to yarad: URLs and domains pulled from a message (and from the decompressed VBA/RTF the extract package surfaces) are checked against a locally-cached feed of recent malicious indicators.
|
Package threatfox adds an abuse.ch ThreatFox IOC lookup to yarad: URLs and domains pulled from a message (and from the decompressed VBA/RTF the extract package surfaces) are checked against a locally-cached feed of recent malicious indicators. |
|
Package urlcand provides shared URL candidate extraction for reputation-feed checkers (urlhaus, threatfox).
|
Package urlcand provides shared URL candidate extraction for reputation-feed checkers (urlhaus, threatfox). |
|
Package urlhaus adds an abuse.ch URLhaus lookup to yarad: URLs pulled from a message (and from the decompressed VBA/RTF the extract package surfaces) are checked against a locally-cached feed of known malware-distribution URLs.
|
Package urlhaus adds an abuse.ch URLhaus lookup to yarad: URLs pulled from a message (and from the decompressed VBA/RTF the extract package surfaces) are checked against a locally-cached feed of known malware-distribution URLs. |
Click to show internal directories.
Click to hide internal directories.