Mac中爲IDA7.0安裝findcrypt3插件

我本次安裝過程很順利,步驟也較爲簡單。圖文並茂,請參考,不足之處望指出。python

前提條件是,你的電腦已經安裝了IDA7,也有Python,個人Mac使用默認的Python2.7版本。git


一、終端輸入命令"sudo pip install yara-python"安裝yara-pythongithub

$ sudo pip install yara-pythonPassword:Collecting yara-python  Downloading https://files.pythonhosted.org/packages/1d/93/688492dcedbd57a9c0b4074aa47d39ac5f5e7411a8ce69b23e57a801e638/yara-python-3.10.0.tar.gz (366kB)    100% |████████████████████████████████| 368kB 1.3MB/s Installing collected packages: yara-python  Running setup.py install for yara-pythonSuccessfully installed yara-python-3.10.0複製代碼

二、到github下載findcrypt-yara插件bash

下載地址:https://github.com/polymorf/findcrypt-yara
複製代碼

解壓下載的文件,找到 findcrypt3.rules 和 findcrypt3.py 這兩個文件,拷貝到IDA對應的/idabin/plugins/目錄下:spa



三、重啓IDA,在菜單中能夠看到剛安裝的插件,大功告成。插件



關注公衆號:逆向APP

相關文章
相關標籤/搜索