Releases: CIRCL/factual-rules-generator
Releases · CIRCL/factual-rules-generator
Factual rules generator version 1.0 released
Factual rules generator version 1.0 released
Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a running operating system.
The goal of the software is to be able to use a set of rules against collected or acquired digital forensic evidences and find installed software in a timely fashion.
The software can be used to baseline known software from Windows system and create a set of rules for finding similar installation on other systems.