Neo23x0 / yaraLinks
The pattern matching swiss knife
☆10Updated 4 years ago
Alternatives and similar repositories for yara
Users that are interested in yara are comparing it to the libraries listed below
Sorting:
- Some YARA rules i will add from time to time☆12Updated 6 years ago
- Knowledge base of analytics designed to cover threats based on MITRE's ATT&CK.☆23Updated 6 years ago
- Recipes for GCHQ's CyberChef Web App☆35Updated 6 years ago
- Transform EQL detection rules to VQL artifacts☆11Updated 3 years ago
- Collection of scripts used to analyse malware or emails☆19Updated 4 years ago
- ☆11Updated 4 years ago
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 4 years ago
- Information about the open-source-dfir slack community☆29Updated 2 years ago
- Repository with Sample threat hunting notebooks on Security Event Log Data Sources☆65Updated 2 years ago
- Incident response teams usually working on the offline data, collecting the evidence, then analyze the data☆45Updated 3 years ago
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- Library of threat hunts to get any user started!☆44Updated 4 years ago
- Git for me to put all my forensics stuff☆22Updated 6 months ago
- A MITRE ATT&CK Lookup Tool☆45Updated last year
- Log aggregation, analysis, alerting and correlation for Windows, Syslog and text based logs.☆23Updated 8 years ago
- Mass Triage Tools☆20Updated 5 months ago
- Searches for Insider Threat Hunting☆32Updated 6 years ago
- ☆21Updated 3 years ago
- Incident Response Network Tools☆24Updated 3 years ago
- Reference sheet for Threat Hunting Professional Course☆25Updated 6 years ago
- Repo of python/bash scripts for identifying IoC's in threat feed and other online tools☆27Updated 4 years ago
- A DFVFS Backed Forensic Viewer☆40Updated 5 years ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆20Updated 4 years ago
- Integration between MISP platform and McAfee MVISION EDR☆14Updated 3 years ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Updated 5 months ago
- Open source training materials for law-enforcement and organisations interested in DFIR.☆59Updated last month
- Hunt malware with Volatility☆47Updated last week
- Use DNS to hunt for threats including DGAs☆15Updated 9 years ago
- A collection of typical false positive indicators☆55Updated 4 years ago