Repository navigation
Expand file tree
/
Copy pathCargo.toml
More file actions
57 lines (52 loc) · 2.17 KB
/
Copy pathCargo.toml
File metadata and controls
57 lines (52 loc) · 2.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
[package]
name = "offsetscan"
version = "0.4.0"
edition = "2021"
authors = ["DreadHost Research"]
description = "Standalone native corpus-scale engine for PE parsing, entropy, string extraction, imphash, and IOC panels (JSON schema-compatible with OffsetInspect's Get-OffsetPEInfo/Get-OffsetEntropy/Get-OffsetString/Get-OffsetIOC), plus TLSH similarity clustering for grouping related samples across a corpus."
license = "MIT"
repository = "https://github.com/warpedatom/OffsetScan"
readme = "README.md"
keywords = ["malware", "forensics", "pe", "entropy", "security"]
categories = ["command-line-utilities", "parser-implementations"]
[[bin]]
name = "offsetscan"
path = "src/main.rs"
[dependencies]
# PE parsing (headers, sections, imports, imphash-equivalent, overlay detection)
goblin = "0.8"
# CLI arg parsing
clap = { version = "4", features = ["derive"] }
# JSON output matching OffsetInspect.Result / ThreatScanResult schema
serde = { version = "1", features = ["derive"] }
serde_json = "1"
# Hashing for MD5/SHA-1/SHA-256 (matches Get-OffsetIOC's single-pass hash set)
md-5 = "0.10"
sha1 = "0.10"
sha2 = "0.10"
# Parallel corpus scanning (thousands of files) - the actual perf payoff over PowerShell
rayon = "1"
# Directory/wildcard expansion, matching Invoke-OffsetThreatScanBatch's file-discovery semantics
walkdir = "2"
glob = "0.3"
# CSV output for the ioc panel (flat, analyst-friendly, one row per file)
csv = "1"
# Timestamps in ISO 8601 to match ThreatScanResult's UTC scan timestamp field
chrono = { version = "0.4", features = ["serde"] }
# TLSH locality-sensitive hashing for the `cluster` subcommand. Pure Rust (no C toolchain
# or libclang, unlike the optional yara-scan feature), so `cargo install offsetscan` needs
# no system prerequisites. The `diff` feature provides pairwise distance for clustering.
tlsh2 = { version = "1.1", features = ["diff"] }
[dependencies.yara]
version = "0.32"
optional = true
# Build a bundled libyara from source so the feature needs no system YARA install
# (still requires a C toolchain + libclang for bindgen at build time).
features = ["vendored"]
[features]
default = []
yara-scan = ["dep:yara"]
[profile.release]
lto = true
codegen-units = 1
panic = "abort"