# Handcuff malware byte-signatures (payload scanning).
#
# One signature per line. Lines starting with '#' and blank lines are ignored.
#   - A plain line is matched as UTF-8 bytes.
#   - A line prefixed with 'hex:' is parsed as hex bytes, e.g.  hex:4d5a9000
#
# Add your own by pointing `signatures_path` at another file of the same
# format:  handcuff config set signatures_path /path/to/my_signatures.txt
# Your file is loaded IN ADDITION to these defaults.

# EICAR standard antivirus test string (the canonical harmless test payload).
EICAR-STANDARD-ANTIVIRUS-TEST-FILE
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

# Generic placeholder marker used by Handcuff's own tests/fixtures.
malicious_payload
