You should apt-get install these before beginning. automake, libtool, libssl-dev
-
git submodule update --init --recursive
-
cd go
-
./build.sh
All done! wasn't that simple?
first make a slack config file that contains your slack endpoint url. It should contain only the slack endpoint url with nothing else.
Next, from the go dir, run: ./main -rule YaraRules/certificates.yar -config slack.conf
Then sit back and watch the pastes come flooding in!
Thanks to @kevtehhermit for some of the great yara rules for scraping pastebin. https://github.com/kevthehermit/PasteHunter