Skip to content
Discussion options

You must be logged in to vote

SecurityOnion\agrules\strelka\yara\thor-webshells.yar is not a backdoor. It is a yara ruleset that looks for backdoors. You can review the file here:
https://github.com/Neo23x0/signature-base/blob/master/yara/thor-webshells.yar

I've updated the Download page in our documentation to include a warning about this:
https://docs.securityonion.net/en/2.3/download.html

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@jefferymcaron
Comment options

Answer selected by dougburks
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants