# Bro script to detect XOR'd executables

**URL:** <https://community.zeek.org/t/bro-script-to-detect-xord-executables/2932>\
**Category:** Zeek\
**Created:** [December 10, 2013, 12:40am UTC](https://community.zeek.org/t/bro-script-to-detect-xord-executables/2932 "2013-12-10T00:40:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Beck](https://avatars.discourse-cdn.com/v4/letter/d/90db22/32.png) [@Daniel\_Beck](https://community.zeek.org/u/Daniel_Beck)\
**Post date:** [December 10, 2013, 12:40am UTC](https://community.zeek.org/t/bro-script-to-detect-xord-executables/2932/1 "2013-12-10T00:40:15Z")

</div>

Hello list,

I’ve been working on my first real bro script and I had a couple questions. It uses the File API to detect the transfer of XOR’d Windows executables, the code is at [https://github.com/justbeck/bro-xorpe](https://github.com/justbeck/bro-xorpe).

My questions are:

- Is the file object in the file\_new event guaranteed to have the beginning of the captured file? If not, is there a better location to hook the analysis into?

- What’s the performance impact of running a script like this on a large pipe? The script runs several (quasi) loops for each file\_new event and I only have my home network to test it on.

- Following on the last question, Is there a better way to do bitwise operations in Bro scripts besides creating a huge lookup table?

Thanks,

Daniel

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [December 10, 2013, 2:07am UTC](https://community.zeek.org/t/bro-script-to-detect-xord-executables/2932/2 "2013-12-10T02:07:08Z")

</div>

> - Is the file object in the file\_new event guaranteed to have the beginning of the captured file? If not, is there a better location to hook the analysis into?

No, you aren't guaranteed that it's the beginning of the file. You should be able to inspect the file record though to see if you have gotten the begging of the file although I'm blanking on how exactly you'd do that at the moment.

> - What's the performance impact of running a script like this on a large pipe? The script runs several (quasi) loops for each file\_new event and I only have my home network to test it on.

Not sure, but likely to have a lot of overhead. There is quite a bit of code there that runs for each file. The best way to find out is to run it on a larger network though.

> - Following on the last question, Is there a better way to do bitwise operations in Bro scripts besides creating a huge lookup table?

Unfortunately not at the moment. There have been a number of discussions where we've talked about adding bitwise operators to Bro but we've never come to any firm conclusion.

Anyway, overall it's a really neat script. Nice job!

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/bro-script-to-detect-xord-executables/2932/3 "2022-05-06T15:41:26Z")

</div>


