Перейти к основному содержимому

Quick start

Fire up Mandolin and throw a file at it: content extraction, antivirus and Yara, all in one go.

You need: Docker with Docker Compose. Allow about 2 GB of disk space and a minute for the antivirus signatures to load.

Copy and paste the following block in a terminal. It creates the configuration and starts Mandolin with its two companion services, Apache Tika and ClamAV.

Deploy Mandolin
mkdir -p mandolin && cd mandolin
cat > docker-compose.yml <<'EOF'
services:
tika:
image: apache/tika:3.0.0.0-full
restart: unless-stopped
healthcheck:
test: [ "CMD", "wget", "-O", "/dev/null", "http://localhost:9998/tika" ]
interval: 30s
timeout: 20s
retries: 3
clamav:
mem_reservation: 262144000
mem_limit: 1048576000
image: ajilaag/clamav-rest
healthcheck:
test: [ "CMD", "wget", "-O", "/dev/null", "http://localhost:9000/" ]
interval: 30s
timeout: 20s
retries: 3
mandolin:
image: ghcr.io/piroguetoolsuite/mandolin:main
restart: unless-stopped
ports:
- "127.0.0.1:8888:8000"
depends_on:
clamav:
condition: service_healthy
tika:
condition: service_healthy
healthcheck:
test: [ "CMD", "wget", "-O", "/dev/null", "http://localhost:8000/" ]
interval: 30s
timeout: 20s
retries: 3
environment:
- TIKA_URL=http://tika:9998/
- CLAMAV_URL=http://clamav:9000
- MAX_FILE_SIZE=250000000
EOF
docker compose up -d --wait
Check that it works​

Mandolin answers on http://127.0.0.1:8888. Create two small files and analyze them:

echo "Hello from the PiRogue Tool Suite" > hello.txt
printf 'rule pts { strings: $a = "PiRogue" condition: $a }\n' > rules.yar

# Extract the content and metadata
curl -s -X POST http://127.0.0.1:8888/analyzer/tika -F "file=@hello.txt"

# Scan with the antivirus
curl -s -X POST http://127.0.0.1:8888/analyzer/clamav -F "file=@hello.txt"

# Apply a Yara rule
curl -s -X POST http://127.0.0.1:8888/analyzer/yara -F "file=@hello.txt" -F "rules=<rules.yar"

Want to see the antivirus detect something? Scan the harmless EICAR test file, which every antivirus recognizes:

printf '%s' 'X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > eicar.txt
curl -s -X POST http://127.0.0.1:8888/analyzer/clamav -F "file=@eicar.txt"

The answer contains "infected": true and the name Eicar-Test-Signature.

What's next​

Read the REST API page to see all the operations, or use Mandolin with Colander.

To stop Mandolin, run docker compose stop. To remove it, run docker compose down.

Security

Mandolin has no authentication and processes untrusted files. The block above only publishes it on 127.0.0.1. Do not expose it to the Internet.