anyrun / YARALinks
Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.
☆26Updated last month
Alternatives and similar repositories for YARA
Users that are interested in YARA are comparing it to the libraries listed below
Sorting:
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 5 months ago
- Initial triage of Windows Event logs☆104Updated last year
- A YARA & Malware Analysis Toolkit written in Rust.☆78Updated 2 months ago
- C2 Active Scanner☆60Updated last year
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆106Updated last year
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Updated 2 years ago
- Remote access and Antivirus Logging Database☆44Updated last year
- yara detection rules for hunting with the threathunting-keywords project☆155Updated 7 months ago
- Can you pay the ransom in your country?☆14Updated last year
- A MITRE ATT&CK Lookup Tool☆46Updated last year
- Detection rule validation☆40Updated 2 years ago
- BlackBerry Threat Research & Intelligence☆99Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- Turn any blog into structured threat intelligence.☆42Updated last week
- The core backend server handling API requests and task management☆53Updated last week
- A home for detection content developed by the delivr.to team☆73Updated 4 months ago
- Yara Rules for Modern Malware☆78Updated last year
- Quick ESXi Log Parser☆28Updated last month
- An experimental Velociraptor implementation using cloud infrastructure☆26Updated last week
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 4 years ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated last year
- Library of threat hunts to get any user started!☆46Updated 5 years ago
- Penguin OS Forensic (or Flight) Recorder☆41Updated 11 months ago
- ☆21Updated last month
- The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.☆50Updated 7 months ago
- Forensic Artifact Collection Tool Matrix☆91Updated last year
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆84Updated 2 months ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆42Updated 2 years ago
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆32Updated 2 weeks ago