From f774bfe4423ff17216160a5492c6c75835e9fb86 Mon Sep 17 00:00:00 2001 From: Bart P Date: Thu, 28 Dec 2023 13:16:15 +0100 Subject: [PATCH] Update README.md --- README.md | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 46a3cad..bb8bcf0 100644 --- a/README.md +++ b/README.md @@ -12,6 +12,9 @@ You can use them in your detection systems. For example, [CAPE sandbox](https:// All rules are TLP:White, so you can use and distribute them freely. Please retain the meta. +## Help! A generic rule is hitting my software! +If one of the rules in the [generic](https://github.com/bartblaze/Yara-rules/tree/master/rules/generic) rules section hits on your software: this is not a false positive. It is simply an objective fact that, for example, your software has been compiled or wrapped using AutoIT. It equally does **not** mean your software is malicious. + ## Actions There's two workflows running on this Github repository: @@ -27,11 +30,6 @@ v3.3.0 is minimally needed, as some rules may require a specific module. Note th ## Feedback? If you spot an issue or improvement with one of the rules, feel free to submit a PR! -## Help! A generic rule is hitting my software! -If one of the rules in the [generic](https://github.com/bartblaze/Yara-rules/tree/master/rules/generic) rules section hits on your software: this is not a false positive. It is simply an objective fact that, for example, your software has been compiled or wrapped using AutoIT. It equally does **not** mean your software is malicious. - - - # Extra ## What is Yara?