Skip to content

Commit 7fb5a90

Browse files
committed
refactor(yara): Use the new registry data parameter name
1 parent e38d5a3 commit 7fb5a90

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

pkg/yara/scanner.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -334,7 +334,7 @@ func (s scanner) Scan(e *event.Event) (bool, error) {
334334
if typ := e.Params.TryGetUint32(params.RegValueType); typ != registry.BINARY {
335335
return false, nil
336336
}
337-
v, err := e.Params.Get(params.RegValue)
337+
v, err := e.Params.Get(params.RegData)
338338
if err != nil {
339339
// value not attached to the event
340340
return false, nil

pkg/yara/scanner_test.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -933,7 +933,7 @@ func TestScan(t *testing.T) {
933933
PID: 565,
934934
Params: event.Params{
935935
params.RegValueType: {Name: params.RegValueType, Type: params.Uint32, Value: uint32(registry.BINARY)},
936-
params.RegValue: {Name: params.RegValue, Type: params.Binary, Value: data},
936+
params.RegData: {Name: params.RegValue, Type: params.Binary, Value: data},
937937
params.RegPath: {Name: params.RegPath, Type: params.UnicodeString, Value: `HKEY_LOCAL_MACHINE\CurrentControlSet\Control\DeviceGuard\Mal`},
938938
},
939939
Metadata: make(map[event.MetadataKey]any),

0 commit comments

Comments
 (0)