imp0rtp3 / js-yara-rules
Yara rules for malicious javascript files from public repositories or written by me.
☆12Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for js-yara-rules
- ☆24Updated 2 years ago
- ☆22Updated 3 years ago
- Threat hunting with EQL and Bro. This repo contains modifications to EQL and EQLLib to use BRO logs.☆8Updated 5 years ago
- Yara Based Detection Engine for web browsers☆47Updated 3 years ago
- The FastIR Server is a Web server to schedule FastIR Collector forensics collect thanks to the FastIR Agent☆12Updated 7 years ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆37Updated 4 months ago
- Generate bulk YARA rules from YAML input☆22Updated 4 years ago
- Virustotal Data to Timesketch☆17Updated 5 years ago
- Threat Feeds, Threat lists, and regular lists of known IP ranges and domains. It updates every 4 hours.☆15Updated 3 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- Python parser for Red Canary's Atomic Red Team Yamls☆27Updated 5 years ago
- Automated Static Analysis Framework☆10Updated 2 years ago
- Repository of tools, YARA rules, and code-snippets from Stairwell's research team.☆22Updated 9 months ago
- Analytics for Accounting logs from Network devices☆16Updated 3 years ago
- Setting up a training environment for MISP☆11Updated last year
- Surface Analysis System on Cloud☆19Updated 11 months ago
- Can you pay the ransom in your country?☆14Updated 11 months ago
- Scans through registry hives outputting entropy values for key/values, dumps binary contents to files...we are looking for those "fileles…☆11Updated 5 years ago
- Repository for scripts and tips for "Yara Scan Service"☆20Updated last year
- D-Scan project for office document analysis and generating flow diagram of macro in documents. For demo visit☆29Updated last week
- FastIR Agent is a Windows service to execute FastIR Collector on demand☆14Updated 7 years ago
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆34Updated 2 years ago
- Check IOC provided by a MISP instance on Suricata events☆17Updated 5 years ago
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆21Updated 2 years ago
- External telegram feeder for AIL framework☆13Updated last week
- A collection of Indicators of Compromise (IoCs), most aligning with samples derived from the signatures in the YARA-Signatures repo☆30Updated 4 years ago
- Yara rules☆20Updated last year
- #️⃣ 🕸️ 👤 HTTP Headers Hashing☆14Updated last year
- SACTI - Securely aggregate CTI sightings and report them on MISP☆13Updated 2 years ago