SentineLabs / macos-ttps-yaraLinks
A ruleset to find potentially malicious code in macOS malware samples
☆40Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below
Sorting:
- Rules shared by the community from 100 Days of YARA 2025☆36Updated 9 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆59Updated 3 months ago
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆28Updated 4 months ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆117Updated last year
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆95Updated 2 years ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆96Updated this week
- machofile is a module to parse Mach-O binary files☆89Updated 2 months ago
- pocket guide for core detection engineering concepts☆30Updated 2 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- ☆50Updated last month
- ☆166Updated last month
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆20Updated 4 years ago
- A YARA & Malware Analysis Toolkit written in Rust.☆54Updated 3 weeks ago
- ☆98Updated 2 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated 10 months ago
- ☆41Updated 11 months ago
- An LLM and OCR based Indicator of Compromise Extraction Tool☆36Updated 10 months ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆150Updated last year
- ☆18Updated last month
- An index of publicly available and open-source threat detection rulesets.☆128Updated 6 months ago
- Detection Engineering with YARA☆87Updated last year
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆152Updated last week
- My very personal and opinionatedly organized infosec/cybersec sources in one OPML file☆58Updated 2 years ago
- C2 Active Scanner☆60Updated last year
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆65Updated 3 years ago
- FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.☆62Updated 5 months ago
- Linux #rootkit and #malware revealer☆28Updated last year
- A comprehensive GenAI protection system designed to protect against malicious prompts, injection attacks, and harmful content. System inc…☆92Updated 2 weeks ago
- Examine Chrome extensions for security issues☆85Updated 2 months ago