# File detection signature - ISO

**URL:** <https://community.zeek.org/t/file-detection-signature-iso/5616>\
**Category:** Zeek\
**Created:** [February 27, 2019, 1:14am UTC](https://community.zeek.org/t/file-detection-signature-iso/5616 "2019-02-27T01:14:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darren\_S](https://avatars.discourse-cdn.com/v4/letter/d/59ef9b/32.png) [@Darren\_S](https://community.zeek.org/u/Darren_S)\
**Post date:** [February 27, 2019, 1:14am UTC](https://community.zeek.org/t/file-detection-signature-iso/5616/1 "2019-02-27T01:14:37Z")

</div>

ISO files (ISO 9660 media images) - magic bytes 43 44 30 30 31 (CD001)  
at offset(s). Is this omitted intentionally for any reason (confidence  
or similar), or is it sensible to add a signature for this? Just  
noting delivery of malicious ISO files as malware containers over  
recent years. I notice recent libmagic having a couple of entries for  
this. How would an update or addition typically happen?

[https://github.com/zeek/zeek/tree/master/scripts/base/frameworks/files/magic](https://github.com/zeek/zeek/tree/master/scripts/base/frameworks/files/magic)

---

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [February 27, 2019, 4:21pm UTC](https://community.zeek.org/t/file-detection-signature-iso/5616/2 "2019-02-27T16:21:39Z")

</div>

> ISO files (ISO 9660 media images) - magic bytes 43 44 30 30 31 (CD001)  
> at offset(s). Is this omitted intentionally for any reason (confidence  
> or similar),

Maybe omitted because of the way the matching works -- it buffers up  
to a certain number of bytes (default is 4096) at the beginning of the  
file and then checks for matches once upon the buffer becoming full.  
Seems the offset needed to check for the magic 'CD001' identifier is  
32k+ ? That may be a bit much to do generally.

> or is it sensible to add a signature for this?

You can try extending the signatures with your own for it, but may  
also need to increase the `default_file_bof_buffer_size` option and  
test that doesn't have undesired performance effects.

> How would an update or addition typically happen?
> 
> [https://github.com/zeek/zeek/tree/master/scripts/base/frameworks/files/magic](https://github.com/zeek/zeek/tree/master/scripts/base/frameworks/files/magic)

Typically, a simple pull request to add a signature would be  
considered, but here I'm not sure how likely it would be to include  
one for ISO 9660 by default since it also means an increase in the  
default buffer sizes used for all file type matching. That requires  
more cautious performance and resource utilization testing/review.

Though maybe an alternate route would be if there's changes to the  
file matching engine to make it sophisticated enough to better match  
this case with minimal resources -- that would be something to  
consider, but also more involved/effortful.

- Jon

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/file-detection-signature-iso/5616/3 "2022-05-06T15:46:21Z")

</div>


