APT_Project_Sauron_kblogi_module
Description
Detects strings from kblogi module - Project Sauron report by Kaspersky
Query · yara
strings: $x1 = "Inject using process name or pid. Default" $s2 = "Convert mode: Read log from file and convert to text" $s3 = "Maximum running time in seconds" condition: $x1 or 2 of them