VirusTotal / yara-x
A rewrite of YARA in Rust.
☆727Updated this week
Alternatives and similar repositories for yara-x:
Users that are interested in yara-x are comparing it to the libraries listed below
- AVML - Acquire Volatile Memory for Linux☆925Updated this week
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆568Updated this week
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆728Updated last week
- High Octane Triage Analysis☆716Updated this week
- Threat-hunting tool for Linux☆802Updated last month
- Go symbol recovery tool☆673Updated last month
- Distributed malware processing framework based on Python, Redis and S3.☆404Updated this week
- ReversingLabs YARA Rules☆804Updated this week
- Malduck is your ducky companion in malware analysis journeys☆326Updated 9 months ago
- The multi-platform memory acquisition tool.☆766Updated 3 months ago
- Elastic Security detection content for Endpoint☆1,142Updated this week
- Living Off The Land Drivers☆1,137Updated 3 weeks ago
- Malware repository component for samples & static configuration with REST API interface.☆341Updated this week
- A GUI and CLI tool for removing bloat from executables☆387Updated 2 months ago
- Deep Linux runtime visibility meets Wireshark☆287Updated last month
- A centralized and enhanced memory analysis platform☆434Updated last month
- AssemblyLine 4: File triage and malware analysis☆293Updated this week
- Automated YARA Rule Standardization and Quality Assurance Tool☆200Updated this week
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆967Updated 2 weeks ago
- A Binary Genetic Traits Lexer Framework☆486Updated last month
- Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the …☆333Updated this week
- Dynamic unpacker based on PE-sieve☆717Updated last week
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,111Updated last week
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆2,515Updated this week
- Windows kernel and user mode emulation.☆1,618Updated last month
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,131Updated last month
- Chepy is a python lib/cli equivalent of the awesome CyberChef tool.☆960Updated last month
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆593Updated 2 weeks ago
- Cuckoo3 is a Python 3 open source automated malware analysis system.☆693Updated 3 weeks ago
- Open Source EDR for Windows☆1,197Updated 2 years ago