dr4k0nia / yara-rulesView external linksLinks
A collection of my yara rules
☆34Jul 11, 2023Updated 2 years ago
Alternatives and similar repositories for yara-rules
Users that are interested in yara-rules are comparing it to the libraries listed below
Sorting:
- A collection of small scripts and tools for deobfuscation and malware analysis.☆67Mar 27, 2023Updated 2 years ago
- A tool that adds reproducible UUIDs to YARA rules☆13Apr 24, 2024Updated last year
- Indicators of compromise☆17Jan 29, 2026Updated 2 weeks ago
- Placeholder for my detection repo and misc detection engineering content☆42Oct 20, 2023Updated 2 years ago
- Collection of generic YARA rules☆16Aug 17, 2025Updated 5 months ago
- ☆12Jun 6, 2025Updated 8 months ago
- Collection of rules created using YARA-Signator over Malpedia☆141Jan 6, 2026Updated last month
- ☆17Jan 22, 2026Updated 3 weeks ago
- This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports☆79Jan 26, 2026Updated 3 weeks ago
- Repository with selected IOCs and YARA rules for threat hunting.☆35May 21, 2025Updated 8 months ago
- Ghosting-AMSI☆18Apr 30, 2025Updated 9 months ago
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆21Mar 22, 2024Updated last year
- I have documented all of the AMSI patches that I learned till now☆75Nov 4, 2025Updated 3 months ago
- A tool to create randomly insecure file shares that also contain unsecured credential files☆48Apr 30, 2024Updated last year
- Unpacker and Config Extractor for managed Redline Stealer payloads☆41Feb 18, 2023Updated 2 years ago
- KoiVM,EazVM,AgileVM Patcher Por "Team Venturi77"☆18Aug 16, 2019Updated 6 years ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆46Feb 24, 2023Updated 2 years ago
- Documentation site for Velociraptor☆61Updated this week
- Top hashpwn rules☆21Dec 12, 2025Updated 2 months ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆22Apr 16, 2021Updated 4 years ago
- Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell pro…☆85Aug 2, 2023Updated 2 years ago
- TIBER-Cases is a project created to give cases of The Hive platform for Threat Intelligence Analysts mainly. All the cases are mapped to …☆27Jul 13, 2022Updated 3 years ago
- Yet, Another Packer/Loader☆25Feb 26, 2023Updated 2 years ago
- This repository regroups the Yara Rules for the Unprotect Project☆26Nov 19, 2020Updated 5 years ago
- Remote code execution in Power Platform connectors via JSON deserialization☆23Mar 30, 2023Updated 2 years ago
- This repository contains indicators of compromise (IOCs) of our various investigations.☆310Nov 4, 2025Updated 3 months ago
- Modular malware analysis artifact collection and correlation framework☆54Apr 23, 2024Updated last year
- powershell script i wrote that can suspend an arbitrary process (with limits)☆22Mar 26, 2023Updated 2 years ago
- ☆27Aug 18, 2023Updated 2 years ago
- Reverse-HTTP Redirector via DigitalOcean Apps Platform☆31Aug 16, 2023Updated 2 years ago
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆26Jul 21, 2022Updated 3 years ago
- Yara rules☆22Mar 27, 2023Updated 2 years ago
- A specification and style guide for YARA rules☆66Feb 17, 2024Updated last year
- A YARA Rule Performance Measurement Tool☆61Feb 26, 2024Updated last year
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆31Jul 12, 2023Updated 2 years ago
- ☆66Jan 27, 2023Updated 3 years ago
- A collection of my public YARA signatures for various malware families☆30Sep 20, 2024Updated last year
- A collaboration effort by the DFIR community to provide definitions (sometimes multiple) for common forensic terms!☆26Dec 1, 2022Updated 3 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆71Aug 14, 2021Updated 4 years ago