<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transcribing Yara Signatures for PA Custom Threat Signatures in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18330#M13362</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;You would have to submit this description to support for conformation against our archives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gary S. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Jan 2011 02:50:08 GMT</pubDate>
    <dc:creator>gsamuels</dc:creator>
    <dc:date>2011-01-12T02:50:08Z</dc:date>
    <item>
      <title>Transcribing Yara Signatures for PA Custom Threat Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18329#M13361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Has anyone translated, transcribed or converted an existing Yara malware signature to a Palo Alto custom threat signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://code.google.com/p/yara-project/"&gt;http://code.google.com/p/yara-project/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 22:02:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18329#M13361</guid>
      <dc:creator>apc050</dc:creator>
      <dc:date>2011-01-11T22:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Transcribing Yara Signatures for PA Custom Threat Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18330#M13362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;You would have to submit this description to support for conformation against our archives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gary S. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 02:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18330#M13362</guid>
      <dc:creator>gsamuels</dc:creator>
      <dc:date>2011-01-12T02:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Transcribing Yara Signatures for PA Custom Threat Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18331#M13363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just curious what the outcome of this was? Has this been done? I am also interested in this too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 19:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18331#M13363</guid>
      <dc:creator>rbergen</dc:creator>
      <dc:date>2013-10-22T19:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Transcribing Yara Signatures for PA Custom Threat Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18332#M13364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is interesting and yet challenging as PaloAlto Custom Vulnerability signatures use Contexts so you would need to know where you should be looking for the strings defined in the Yara definitions.&amp;nbsp; The conditional statements within Yara offer a lot of flexibility and that would be hard to do within PA.&amp;nbsp; Simple definitions I believe are doable, providing you know where to look in the flow (context).&amp;nbsp; We are currently creating custom signatures but I have not tried any yara signatures because I don't know in what context I need to look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 19:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/transcribing-yara-signatures-for-pa-custom-threat-signatures/m-p/18332#M13364</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-10-23T19:09:48Z</dc:date>
    </item>
  </channel>
</rss>

