Skip to content

Create attachment_pdf_base64_javascript_eval.yml#4355

Draft
keaton-sublime wants to merge 2 commits intomainfrom
keaton-sublime.fn.esc-10915.mql_4_yara_pdf_b64_javascript
Draft

Create attachment_pdf_base64_javascript_eval.yml#4355
keaton-sublime wants to merge 2 commits intomainfrom
keaton-sublime.fn.esc-10915.mql_4_yara_pdf_b64_javascript

Conversation

@keaton-sublime
Copy link
Copy Markdown
Member

@keaton-sublime keaton-sublime commented Apr 15, 2026

Description

This is the MQL rule for the two yara rules related to js functions in PDFs, specifically the following:

  • pdf_acro_js_functions -- this is looking for acrobat functions
  • pdf_b64_js_var_eval -- this is looking for base64 encoded javascript staples like "eval".

Associated hunts

github-actions Bot added a commit that referenced this pull request Apr 15, 2026
@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label Apr 23, 2026
github-actions Bot added a commit that referenced this pull request Apr 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant