SentineLabs / macos-ttps-yaraLinks
A ruleset to find potentially malicious code in macOS malware samples
☆40Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below
Sorting:
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆117Updated 11 months ago
- Rules shared by the community from 100 Days of YARA 2025☆35Updated 7 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆58Updated last month
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆95Updated 2 years ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- machofile is a module to parse Mach-O binary files☆88Updated last month
- My very personal and opinionatedly organized infosec/cybersec sources in one OPML file☆57Updated 2 years ago
- Examine Chrome extensions for security issues☆85Updated last month
- ☆96Updated last month
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆65Updated 3 years ago
- ☆164Updated this week
- An LLM and OCR based Indicator of Compromise Extraction Tool☆35Updated 9 months ago
- Linux #rootkit and #malware revealer☆27Updated last year
- acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.☆108Updated last week
- Repository of tools and resources for analyzing Docker containers☆68Updated last year
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆20Updated 4 years ago
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆27Updated 2 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated 9 months ago
- God Mode Detection Rules☆134Updated last year
- SECurityTr8Ker monitors the SEC's RSS feed for 8-K filings with cybersecurity incident disclosures.☆85Updated 2 months ago
- FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.☆58Updated 3 months ago
- Forensic Artifact Collection Tool for macOS☆114Updated last month
- Detection Engineering with YARA☆87Updated last year
- Lightweight Python-Based Malware Analysis Pipeline☆35Updated this week
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆150Updated 11 months ago
- A home for detection content developed by the delivr.to team☆70Updated last month
- FT3: Fraud Tools, Tactics, and Techniques Framework☆90Updated last month
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 2 months ago
- HASH (HTTP Agnostic Software Honeypot)☆138Updated last year