Skip to content

Commit

Permalink
refactor excavate finding description
Browse files Browse the repository at this point in the history
  • Loading branch information
liquidsec committed Nov 8, 2024
1 parent 3d7dee3 commit c73af0e
Showing 1 changed file with 3 additions and 4 deletions.
7 changes: 3 additions & 4 deletions bbot/modules/internal/excavate.py
Original file line number Diff line number Diff line change
Expand Up @@ -274,12 +274,11 @@ async def process(self, yara_results, event, yara_rule_settings, discovery_conte
description_string = (
f" with description: [{yara_rule_settings.description}]" if yara_rule_settings.description else ""
)
# Get URL from event if available
url = event.data.get("url", "") if hasattr(event, "data") else ""
url_string = f" on @{url}" if url else ""

url_string = event.data.get("url") or event.data.get("host", "Unknown Source")

event_data["description"] = (
f"Custom Yara Rule [{self.name}]{description_string} Matched via identifier [{identifier}]{url_string}"
f"Custom Yara Rule [{self.name}]{description_string} Matched via identifier [{identifier}] on [{url_string}]"
)
if yara_rule_settings.emit_match:
event_data["description"] += f" and extracted [{result}]"
Expand Down

0 comments on commit c73af0e

Please sign in to comment.