SentineLabs / macos-ttps-yaraLinks
A ruleset to find potentially malicious code in macOS malware samples
☆41Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below
Sorting:
- Rules shared by the community from 100 Days of YARA 2025☆37Updated 10 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆61Updated 4 months ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆95Updated 2 years ago
- machofile is a module to parse Mach-O binary files☆89Updated 4 months ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆20Updated 4 years ago
- An LLM and OCR based Indicator of Compromise Extraction Tool☆38Updated last year
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆118Updated last year
- ☆166Updated 2 months ago
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆30Updated 5 months ago
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆29Updated 3 years ago
- FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.☆62Updated 6 months ago
- A comprehensive GenAI protection system designed to protect against malicious prompts, injection attacks, and harmful content. System inc…☆95Updated last month
- Examine Chrome extensions for security issues☆88Updated 3 weeks ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- ☆52Updated 2 months ago
- Linux #rootkit and #malware revealer☆28Updated last year
- Convert Sigma rules to SIEM queries, directly in your browser.☆96Updated this week
- ☆18Updated this week
- ☆19Updated 3 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- Memory Forensic System on Cloud☆92Updated last year
- C2 Active Scanner☆60Updated last year
- ☆100Updated last month
- God Mode Detection Rules☆134Updated last year
- Detection Engineering with YARA☆87Updated last year
- A YARA & Malware Analysis Toolkit written in Rust.☆78Updated 2 months ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆161Updated last week
- Forensic Artifact Collection Tool for macOS☆116Updated 4 months ago
- pocket guide for core detection engineering concepts☆31Updated 2 years ago