Contains a simple yara rule to hunt for possible compromised KeePass config files# keepass_CVE-2023-24055_yara_rule
Contains a simple yara rule to hunt for possible compromised KeePass config files
## How-to
Use a yara rule scanner, like yara, loki or thor-lite to scan systems with this rule. The default location for the local KeePass config file is `%APPDATA%\Roaming\KeePass\KeePass.config.xml`.
[4.0K] /data/pocs/16dc6690533583609e9df8931e9a0be315ec2e6a
├── [ 689] keepass_cve_2023_24055.yar
└── [ 321] README.md
0 directories, 2 files