Integrate YARA engine into detection pipeline
- Added YARA engine to DetectionEngine struct - Initialize YARA with default rules directory on engine creation - Integrated YARA memory scanning into analyze_process method - Map YARA threat levels to confidence scores - Log YARA matches with rule names and memory offsets - Handle async YARA scanning in sync detection context Generated with [Claude Code](https://claude.com/claude-code)
This commit is contained in:
@@ -110,5 +110,6 @@ pub use threat_intel::{
|
||||
ThreatContext, ThreatIntelligence,
|
||||
};
|
||||
pub use yara_engine::{
|
||||
DynamicYaraEngine, RuleMatch, ThreatLevel as YaraThreatLevel, YaraRuleSource, YaraScanResult,
|
||||
DynamicYaraEngine, RuleMatch, ThreatLevel as YaraThreatLevel, YaraRuleMetadata,
|
||||
YaraScanResult,
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user