Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.
☆31Nov 1, 2025Updated 10 months ago
Alternatives and similar repositories for YARA
Users that are interested in YARA are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Listing of YARA rules I wrote for Live and Retro hunts. Includes Jupyter infostealer, suspicious powershell, dll hijacking, vbs downloade…☆17Jun 26, 2026Updated 2 months ago
- Collection of YARA signatures from individual research☆45Nov 20, 2023Updated 2 years ago
- Open YARA scan- and search engine☆26Feb 23, 2025Updated last year
- Information Stealers Wall of Sheep (IS-WOS)☆11Nov 13, 2020Updated 5 years ago
- Powershell Based tool for gathering information related to O365 intrusions and potential Breaches☆18Dec 29, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A repository of Sysmon For Linux configuration modules☆17Oct 14, 2021Updated 4 years ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆113Aug 19, 2026Updated 2 weeks ago
- Sniffpass will alert on cleartext passwords discovered in HTTP POST requests☆16Oct 30, 2023Updated 2 years ago
- Repository of YARA rules made by Trellix ATR Team☆626Mar 18, 2025Updated last year
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- This is a collection of threat detection rules / rules engines that I have come across.☆300May 5, 2024Updated 2 years ago
- Yara rules for malware families seen as part of targeted threats project☆145Nov 17, 2016Updated 9 years ago
- yara detection rules for hunting with the threathunting-keywords project☆166May 11, 2025Updated last year
- A tiny CRC32/64 library for C/C++☆12Aug 16, 2019Updated 7 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆62Mar 12, 2022Updated 4 years ago
- PowerShell Memory Pulling script☆19Mar 24, 2015Updated 11 years ago
- KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.☆25Nov 7, 2024Updated last year
- ☆13Feb 5, 2025Updated last year
- This repository regroups the Yara Rules for the Unprotect Project☆26Nov 19, 2020Updated 5 years ago
- Alternative password shadowing scheme☆12Aug 1, 2026Updated last month
- Script to chain search parameters for MalwareBazaar☆14Jan 26, 2025Updated last year
- ☆11Feb 9, 2023Updated 3 years ago
- Aralez is a triage tool for Windows and Linux that automates the collection of system information, network/process data, and files.☆25Aug 14, 2026Updated 2 weeks ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- IDA Processor for Compiled YARA Rules☆28Jan 22, 2019Updated 7 years ago
- ☆14Apr 1, 2017Updated 9 years ago
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆26Oct 3, 2023Updated 2 years ago
- Perform file-based malware scan on your on-prem servers with AWS☆14Oct 31, 2023Updated 2 years ago
- Repository for out-of-tree scheduler plugins based on scheduler framework.☆13Apr 2, 2023Updated 3 years ago
- Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets☆34Jan 14, 2026Updated 7 months ago
- 🌌 Real-time threat detection for smart contracts☆10May 16, 2023Updated 3 years ago
- Import Mitre Att&ck into Neo4j database☆41Mar 5, 2026Updated 5 months ago
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆37Sep 2, 2017Updated 9 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Yara Scanner For IMAP Feeds and saved Streams☆28Nov 5, 2019Updated 6 years ago
- Messing around with clamav sigs☆27Apr 15, 2026Updated 4 months ago
- ☆25Jan 4, 2023Updated 3 years ago
- Web interface to explore Suricata EVE outputs☆100Jul 19, 2026Updated last month
- MCP server with 55 security intelligence tools — CVE/KEV, MITRE ATLAS+D3FEND, Sigma detection rules, email security posture (SPF/DMARC), …☆33Updated this week
- Event Query Router☆12Aug 9, 2019Updated 7 years ago
- Hyde Themes☆27Feb 22, 2025Updated last year