anyrun / YARA
☆14Updated 3 months ago
Alternatives and similar repositories for YARA:
Users that are interested in YARA are comparing it to the libraries listed below
- Over 100K open-source YARA signatures evaluated against over 280K files to give insights into the performance of each YARA rule.☆23Updated 2 years ago
- Linux #rootkit and #malware revealer☆23Updated 6 months ago
- An experimental Velociraptor implementation using cloud infrastructure☆23Updated last week
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- Static Decryptor for IcedID Malware☆18Updated 2 years ago
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆22Updated 10 months ago
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆27Updated last year
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆32Updated 3 weeks ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆26Updated 2 years ago
- ☆34Updated 2 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- this repo is for red team process and tools collection☆20Updated 3 years ago
- Placeholder for my detection repo and misc detection engineering content☆42Updated last year
- Collection of generic YARA rules☆15Updated 8 months ago
- Triaging Windows event logs based on SANS Poster☆38Updated 2 years ago
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- Golang C2 Agent PoC utilizing web and social media paltforms to issue command and control and pasting results to PasteBin☆16Updated 4 years ago
- A cap/pcap packet parser to make life easier when performing stealth/passive reconnaissance.☆21Updated 7 months ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆56Updated 2 months ago
- Parser for Windows PowerShell script block logs☆13Updated last month
- Yara rules☆20Updated last year
- EventLogSilencer is a PowerShell script designed for disable Windows Event Logging☆14Updated last year
- ☆22Updated last year
- Scan and decode NetWire logs☆11Updated 2 years ago
- Detection rule validation☆41Updated last year
- Malware campaigns and APTs research by BlackArrow☆18Updated 4 years ago
- Pure Honeypots with an automated bash script☆20Updated 3 years ago
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated last year