SentineLabs / macos-ttps-yara
A ruleset to find potentially malicious code in macOS malware samples
☆39Updated last year
Related projects ⓘ
Alternatives and complementary repositories for macos-ttps-yara
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆93Updated 2 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆48Updated 10 months ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆63Updated 9 months ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆89Updated last year
- Simple Workspace Attack Tool (SWAT) is a tool for simulating malicious behavior against Google Workspace in reference to the MITRE ATT&CK…☆161Updated last month
- An LLM and OCR based Indicator of Compromise Extraction Tool☆31Updated 7 months ago
- Lightweight Python-Based Malware Analysis Pipeline☆29Updated last month
- Mapping XProtect's obfuscated malware family names to common industry names.☆82Updated 6 months ago
- ☆68Updated last month
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆20Updated 3 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated last year
- ☆83Updated 3 months ago
- Unit tests for blue teams to aid with building detections for some common macOS post exploitation methods.☆104Updated 2 years ago
- machofile is a module to parse Mach-O binary files☆48Updated 9 months ago
- ☆211Updated this week
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆49Updated 6 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆62Updated 2 years ago
- Repository of tools and resources for analyzing Docker containers☆59Updated last year
- C2 Active Scanner☆48Updated 5 months ago
- God Mode Detection Rules☆131Updated 3 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆66Updated last week
- Detection Engineering with YARA☆85Updated 10 months ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆26Updated last month
- pocket guide for core detection engineering concepts☆27Updated last year
- ☆18Updated 3 years ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆140Updated 2 months ago
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆59Updated 3 weeks ago
- Collection of Docker honeypot logs from 2021 - 2024☆35Updated last month
- ☆37Updated 2 months ago
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆28Updated 2 years ago