RustyNoob-619 / YARALinks
Everything related to YARA
☆14Updated last month
Alternatives and similar repositories for YARA
Users that are interested in YARA are comparing it to the libraries listed below
Sorting:
- NoDelete is a tool that assists in malware analysis by locking a folder where malware drops files before deleting them.☆48Updated 9 months ago
- Threat feeds designed to extract adversarial TTPs and IOCs, using: ✨AI✨☆36Updated this week
- Some of my rough notes for Docker threat detection☆47Updated 2 years ago
- A little tool to filter the stranger strings from a binary so you can analyze the good ones☆46Updated 3 weeks ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated 2 years ago
- information about ransomware groups (Ransomware Analysis Notes)☆39Updated last year
- ☆37Updated last year
- Malware Analysis tools☆26Updated last year
- C2 Active Scanner☆60Updated last year
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆28Updated 2 years ago
- Lena's scripts/code/resources for malware analysis☆26Updated last year
- ☆27Updated 10 months ago
- ☆19Updated last year
- ☆18Updated last year
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆23Updated 9 months ago
- Yet Another Memory Analyzer for malware detection☆24Updated 2 years ago
- ☆30Updated 2 years ago
- PowerShell Script Analyzer☆70Updated last year
- Make an Linux Kernel rootkit visible again.☆57Updated 7 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated 10 months ago
- ☆82Updated 10 months ago
- Configuration Extractors for Malware☆113Updated 5 months ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆39Updated 7 months ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆150Updated last year
- A comprehensive knowledge base for security professionals to keep track of and build defenses against API attack techniques.☆43Updated last year
- Proximity is a MCP security scanner powered with NOVA☆45Updated last week
- A library and a set of tools for exploiting and communicating with Google's Quick Share devices.☆47Updated 6 months ago
- Baseline a Windows System against LOLBAS☆68Updated last year
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆132Updated 8 months ago