Releases: CIRCL/factual-rules
Releases · CIRCL/factual-rules
Factual rules version 1.0 released
Factual rules version 1.0 released
Factual rules are YARA rules to find legitimate software on raw disk acquisition. The goal of the software is to be able to use a set of rules against collected or acquired digital forensic evidences and find installed software in a timely fashion. All the rules are generated using factual-rules-generator.
The source code for generating automatically rules is released as open source as factual rules generator.