VirusTotal / yara-x
A rewrite of YARA in Rust.
☆718Updated this week
Alternatives and similar repositories for yara-x:
Users that are interested in yara-x are comparing it to the libraries listed below
- AVML - Acquire Volatile Memory for Linux☆917Updated this week
- High Octane Triage Analysis☆713Updated this week
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆568Updated this week
- Threat-hunting tool for Linux☆789Updated 2 weeks ago
- Elastic Security detection content for Endpoint☆1,134Updated this week
- ReversingLabs YARA Rules☆796Updated last week
- Malduck is your ducky companion in malware analysis journeys☆326Updated 8 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆590Updated this week
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆727Updated 2 weeks ago
- AssemblyLine 4: File triage and malware analysis☆286Updated this week
- Automated YARA Rule Standardization and Quality Assurance Tool☆196Updated this week
- The multi-platform memory acquisition tool.☆756Updated 3 months ago
- Windows kernel and user mode emulation.☆1,607Updated last week
- A Binary Genetic Traits Lexer Framework☆486Updated 2 weeks ago
- Go symbol recovery tool☆671Updated 2 weeks ago
- Collection of private Yara rules.☆343Updated this week
- Living Off The Land Drivers☆1,127Updated this week
- A GUI and CLI tool for removing bloat from executables☆383Updated 2 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆2,489Updated this week
- A centralized and enhanced memory analysis platform☆433Updated last month
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,103Updated this week
- Deep Linux runtime visibility meets Wireshark☆285Updated last month
- Distributed malware processing framework based on Python, Redis and S3.☆403Updated last month
- YARA signature and IOC database for my scanners and tools☆2,566Updated last week
- Collaborative Malware Analysis Platform at Scale☆740Updated 2 weeks ago
- Dynamic unpacker based on PE-sieve☆709Updated last month
- Cuckoo3 is a Python 3 open source automated malware analysis system.☆687Updated this week
- The Python interface for YARA☆681Updated 3 months ago
- Indicators of Compromises (IOC) of our various investigations☆1,741Updated 2 weeks ago
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,123Updated 2 weeks ago