google / google/turbinia

Document "targeted" processing

Open
#1,111 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
794
Forks
172
PR merge metrics
No merged PRs in 30d

Description

Now that we have recipes, can extract arbitrary artifacts with the 'binary_extraction_path' parameter for the binary extraction Task as well as Yara rules processing, we should document the ways that we have to do targeted processing, ie., extract and process very specific artifacts or hunt for specific IOCs. It would be nice to have a page in the documentation dedicated to this and maybe an example recipe in the recipe's folder for how to do this.

Contributor guide

Open the contributing guide

Research direction

Start by reading the existing documentation and the recipes folder, then inspect the binary extraction Task's binary_extraction_path parameter and the Yara rules processing examples. Done means a dedicated documentation page explains targeted processing for artifact extraction and IOC hunting, with an accompanying example recipe in the recipes folder.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.