airbnb / airbnb/binaryalert

Run Arbitrary Parsing Scripts on Binary Files

Open
#135 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
1.5k
Forks
179
PR merge metrics
No merged PRs in 30d

Description

## Background

Malware is often packed or encrypted using custom algorithms on specific sections within a dropper binary. It would be nice to arbitrarily specify extracting/unpacking/decrypting/decoding scripts against binaries scanned by Binary Alert.

~~ Case 1 ~~
It is common for python scripts to be compiled using pyinstaller or py2app to create a single binary executable for both MacOS and Windows platforms. Instead of writing signatures on the compiled code (which can often reduce signal strength), it would be nice to run code to decompile the binary and then run Yara signatures on the resulting files.

For example of scripts to be applied before the Yara scanning occurs, see the 2 unpacker/decompiler scripts here https://github.com/countercept/python-exe-unpacker.

## Desired Change

Support for the addition of arbitrary code to be run against binaries before Yara scanning occurs. Ideally, this should be recursive as some malicious payloads can be packed more than one time.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by tracing BinaryAlert’s binary-scanning flow to the point before Yara scanning, then review the two example unpacker/decompiler scripts in the referenced python-exe-unpacker repository. Done means the project has a defined and supported way to run arbitrary parsing scripts, including the requested recursive processing, before Yara scanning.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.