100 Days of YARA – Day 41: nmap

For reasons similar to masscan, it is worth investigating if Nmap is discovered on an unexpected host.

rule nmap
{
	meta:
		description = "Nmap network scanner"
		reference = "https://nmap.org"

	strings:
		$ = "Usage: nmap [Scan Type(s)] [Options] {target specification}"

	condition:
		all of them
}

YARA Rules Index

One thought on “100 Days of YARA – Day 41: nmap

  1. Pingback: Week 05 – 2022 – This Week In 4n6

Leave a comment