Yara-Rules / YaraRET
Carving tool based in Radare2 & Yara
☆15Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for YaraRET
- Threat hunting with EQL and Bro. This repo contains modifications to EQL and EQLLib to use BRO logs.☆8Updated 5 years ago
- Hashes of infamous malware☆26Updated last year
- Repository for scripts and tips for "Yara Scan Service"☆20Updated last year
- ☆15Updated 2 years ago
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated 3 weeks ago
- Penguin OS Forensic (or Flight) Recorder☆37Updated 4 months ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- Scripts and lists to help generate YARA friendly string mutations☆19Updated last year
- ☆22Updated 3 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- ☆15Updated 2 years ago
- C# User Simulation☆33Updated 2 years ago
- Yara rules☆20Updated last year
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 3 years ago
- Converts Sigma detection rules to a Splunk alert configuration.☆13Updated 3 years ago
- Can you pay the ransom in your country?☆14Updated 11 months ago
- Speaking materials from conferences I've given☆9Updated 2 years ago
- Repository of tools, YARA rules, and code-snippets from Stairwell's research team.☆22Updated 9 months ago
- Indicators of Normality☆12Updated 2 years ago
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆14Updated 4 years ago
- YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.☆27Updated 2 years ago
- A happy place for detection engineers, purple teamers and threat hunters focusing on macOS.☆20Updated 2 years ago
- Autopsy Module to analyze Registry Hives☆13Updated 2 years ago
- Standardized Malware Analysis Tool☆51Updated 3 years ago
- Collection of scripts used to analyse malware or emails☆19Updated 4 years ago
- ☆21Updated last month
- A Modular MWDB Utility to Collect Fresh Malware Samples☆34Updated 3 years ago
- unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Andro…☆32Updated 3 months ago
- THOR MITRE ATT&CK Framework Coverage☆24Updated 4 years ago
- F-Secure Lightweight Acqusition for Incident Response (FLAIR)☆16Updated 3 years ago