New API: internal_yara_scan

The internal_yara_scan runs the Yara engine with the previously loaded
rules against the given file.

For each rule matching against the scanned file, a struct containing
the file name and the rule identifier is returned.

The gathered list of yara_detection structs is serialised into XDR format
and written to a file.

Signed-off-by: Matteo Cafasso <noxdafox@gmail.com>
This commit is contained in:
Matteo Cafasso
2017-04-25 23:03:03 +03:00
committed by Richard W.M. Jones
parent 09bab5d38c
commit d00dc913aa
9 changed files with 110 additions and 1 deletions

View File

@@ -46,4 +46,5 @@ java_built_sources = \
com/redhat/et/libguestfs/Version.java \
com/redhat/et/libguestfs/XAttr.java \
com/redhat/et/libguestfs/XFSInfo.java \
com/redhat/et/libguestfs/YaraDetection.java \
com/redhat/et/libguestfs/GuestFS.java

View File

@@ -23,3 +23,4 @@ VG.java
Version.java
XAttr.java
XFSInfo.java
YaraDetection.java