VirusTotal / yara-x
A rewrite of YARA in Rust.
☆712Updated this week
Alternatives and similar repositories for yara-x:
Users that are interested in yara-x are comparing it to the libraries listed below
- AVML - Acquire Volatile Memory for Linux☆908Updated this week
- High Octane Triage Analysis☆709Updated this week
- A GUI and CLI tool for removing bloat from executables☆379Updated last month
- AssemblyLine 4: File triage and malware analysis☆282Updated this week
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆566Updated this week
- Malduck is your ducky companion in malware analysis journeys☆326Updated 8 months ago
- Elastic Security detection content for Endpoint☆1,119Updated this week
- A Binary Genetic Traits Lexer Framework☆487Updated last week
- Distributed malware processing framework based on Python, Redis and S3.☆403Updated 3 weeks ago
- Deep Linux runtime visibility meets Wireshark☆274Updated 2 weeks ago
- Automated YARA Rule Standardization and Quality Assurance Tool☆192Updated last week
- ReversingLabs YARA Rules☆791Updated last month
- Go symbol recovery tool☆662Updated this week
- Malware repository component for samples & static configuration with REST API interface.☆341Updated this week
- Threat-hunting tool for Linux☆685Updated this week
- Windows kernel and user mode emulation.☆1,578Updated this week
- Collection of private Yara rules.☆340Updated this week
- Sysmon for Linux☆1,822Updated this week
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆718Updated this week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆585Updated this week
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,095Updated this week
- A centralized and enhanced memory analysis platform☆431Updated 2 weeks ago
- ☆535Updated last year
- The Python interface for YARA☆676Updated 2 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆2,458Updated this week
- Open Source EDR for Windows☆1,182Updated last year
- Cuckoo3 is a Python 3 open source automated malware analysis system.☆676Updated last month
- MBC content in markdown☆407Updated last month
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,106Updated this week
- Signatures and IoCs from public Volexity blog posts.☆349Updated last week