Kraken User Guide
Search…
Building on Linux
First, install some required dependencies before continuing:
1
$ sudo apt install gcc automake libtool make go-bindata
Copied!
You need to install Yara development libraries and headers. You should download and compile Yara from the official sources. It will require dh-autoreconf to be installed and you will need to configure some compilation flags. This is most likely the procedure you will need to follow:
1
$ sudo apt install dh-autoreconf
2
$ wget https://github.com/VirusTotal/yara/archive/v4.0.1.tar.gz
3
$ tar -zxvf yara-v4.0.1.tar.gz
4
$ cd yara-4.0.1
5
$ ./bootstrap.sh
6
$ ./configure --without-crypto
7
$ make && sudo make install
8
$ sudo ldconfig
Copied!
Compiling Kraken requires you to specify a path to a file or a folder that contains the Yara rules you wish to embed with the binary. You can try for example with:
1
$ BACKEND=example.com RULES=test/ make linux
Copied!
You might see some warning messages like the following:
1
/usr/bin/ld: /tmp/go-link-1111111/000018.o: in function `mygetgrouplist':
2
$GOPATH/src/os/user/getgrouplist_unix.go:16: warning: Using 'getgrouplist' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
3
/usr/bin/ld: /tmp/go-link-1111111/000017.o: in function `mygetgrgid_r':
4
$GOPATH/src/os/user/cgo_lookup_unix.go:38: warning: Using 'getgrgid_r' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
5
/usr/bin/ld: /tmp/go-link-1111111/000017.o: in function `mygetgrnam_r':
6
$GOPATH/src/os/user/cgo_lookup_unix.go:43: warning: Using 'getgrnam_r' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
7
/usr/bin/ld: /tmp/go-link-1111111/000017.o: in function `mygetpwnam_r':
8
$GOPATH/src/os/user/cgo_lookup_unix.go:33: warning: Using 'getpwnam_r' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
9
/usr/bin/ld: /tmp/go-link-1111111/000017.o: in function `mygetpwuid_r':
10
$GOPATH/src/os/user/cgo_lookup_unix.go:28: warning: Using 'getpwuid_r' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
11
/usr/bin/ld: /tmp/go-link-1111111/000015.o: in function `_cgo_18049202ccd9_C2func_getaddrinfo':
12
/tmp/go-build/cgo-gcc-prolog:49: warning: Using 'getaddrinfo' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
Copied!
If so, don't alarm, as they shouldn't prevent the executables from being successfully built.
Once the make linux command is completed, you should see Kraken binaries inside build/linux/.
Last modified 1yr ago
Copy link