Share
## https://sploitus.com/exploit?id=CA5ECB54-1A68-5CF2-B209-3326ADF51E49
# keepass_CVE-2023-24055_yara_rule
Contains a simple yara rule to hunt for possible compromised KeePass config files

## How-to

Use a yara rule scanner, like yara, loki or thor-lite to scan systems with this rule. The default location for the local KeePass config file is `%APPDATA%\Roaming\KeePass\KeePass.config.xml`.