wireshark_yara_scan
Scan exported files from packet captures using YARA rules to detect malware, webshells, and shellcode across HTTP, SMB, or TFTP protocols.
Instructions
[Security] YARA scan exported files. Detects malware, webshells, shellcode. protocol: http|smb|tftp.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| dest_dir | No | ||
| protocol | No | http | |
| pcap_file | Yes |