elceef / yara-rulzLinks
Collection of generic YARA rules
☆16Updated 4 months ago
Alternatives and similar repositories for yara-rulz
Users that are interested in yara-rulz are comparing it to the libraries listed below
Sorting:
- USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is exec…☆20Updated 3 years ago
- Modular malware analysis artifact collection and correlation framework☆53Updated last year
- The repository accompanying the Buer Emulation workshop☆23Updated 4 years ago
- Rapidly building a Windows 10 system to use for dynamic malware analysis (sandbox), sending data to Elastic Cloud.☆50Updated 2 years ago
- ☆36Updated 2 years ago
- ☆18Updated last year
- ☆27Updated last year
- ☆33Updated 3 years ago
- Defeating Anti-Debugging Techniques for Malware Analysis☆13Updated 3 years ago
- ☆23Updated 2 years ago
- ☆12Updated 4 years ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated 2 years ago
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆28Updated 2 years ago
- Tricard - Malware Sandbox Fingerprinting☆22Updated 2 years ago
- Specialized tool to dump Position Independent Code.☆22Updated 5 years ago
- Python wrappers for mal_unpack☆37Updated 2 years ago
- Collection of my own detection rules☆20Updated 5 months ago
- Repository for LNK stuff☆31Updated 3 years ago
- Sources Codes of many Office Malwares☆17Updated 3 years ago
- Tools helpful for malware analysis☆23Updated last year
- ☆12Updated 3 years ago
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆24Updated 2 years ago
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆66Updated 3 years ago
- ProcDot Malware Sandbox☆25Updated 4 months ago
- Tools for playing w/ CobaltStrike config - extractin, detection, processing, etc...☆28Updated 2 years ago
- Continuous kerberoast monitor☆45Updated 2 years ago
- A Canary which fires when uninstalled☆34Updated 4 years ago
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆51Updated 3 years ago
- Extension functionality for the NightHawk operator client☆26Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 3 years ago