Automatically create YARA rules from malicious documents.
☆211May 16, 2022Updated 3 years ago
Alternatives and similar repositories for halogen
Users that are interested in halogen are comparing it to the libraries listed below
Sorting:
- Yara rules☆22Mar 27, 2023Updated 2 years ago
- YARA malware query accelerator (web frontend)☆437Feb 3, 2026Updated 3 weeks ago
- Awesome VirusTotal Intelligence Search Queries☆332May 16, 2023Updated 2 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Sep 18, 2018Updated 7 years ago
- Real-time, container-based file scanning at enterprise scale☆975Updated this week
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆585May 5, 2024Updated last year
- Re-play Security Events☆1,723Mar 20, 2024Updated last year
- Malduck is your ducky companion in malware analysis journeys☆349Jun 22, 2025Updated 8 months ago
- Automatic YARA rule generation for Malpedia☆168Sep 8, 2022Updated 3 years ago
- Malware similarity platform with modularity in mind.☆80Jul 18, 2021Updated 4 years ago
- Generate a Yara rule to find base64-encoded files containg a specific keyword☆40Jul 13, 2018Updated 7 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆75Jan 18, 2022Updated 4 years ago
- See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)☆108Feb 12, 2023Updated 3 years ago
- Yet Another Yara Automaton - Automatically curate open source yara rules and run scans☆300Dec 27, 2023Updated 2 years ago
- Simple yara rule manager☆67Dec 27, 2022Updated 3 years ago
- Distributed malware processing framework based on Python, Redis and S3.☆461Dec 1, 2025Updated 2 months ago
- A list of JARM hashes for different ssl implementations used by some C2/red team tools.☆144Apr 20, 2023Updated 2 years ago
- Repository of YARA rules made by Trellix ATR Team☆625Mar 18, 2025Updated 11 months ago
- Yara station is a management portal for Neo23x0-Loki. The mission is to transform the standalone nature of the Loki scanner into a centra…☆35Feb 1, 2022Updated 4 years ago
- ☆128Feb 2, 2025Updated last year
- Strelka Web UI for File Submission and Analysis☆75Feb 11, 2026Updated 2 weeks ago
- Encyclopedia for Executables☆471Nov 9, 2021Updated 4 years ago
- Threat intelligence and threat detection indicators (IOC, IOA)☆52Nov 27, 2020Updated 5 years ago
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆723Dec 26, 2022Updated 3 years ago
- Event Trace Log file parser in pure Python☆150Nov 27, 2020Updated 5 years ago
- ☆54Sep 6, 2020Updated 5 years ago
- Online hash checker for Virustotal and other services☆846Mar 21, 2025Updated 11 months ago
- Yara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies☆107Mar 4, 2021Updated 4 years ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆1,059Oct 5, 2023Updated 2 years ago
- Django web interface for managing Yara rules☆196Jul 28, 2018Updated 7 years ago
- Collection of YARA signatures from individual research☆44Nov 20, 2023Updated 2 years ago
- YARI is an interactive debugger for YARA Language.☆90Sep 10, 2025Updated 5 months ago
- Detect Tactics, Techniques & Combat Threats☆2,263Jan 21, 2026Updated last month
- Detection Ideas & Rules repository.☆178Sep 10, 2021Updated 4 years ago
- Kaspersky's GReAT KLara☆732Jul 24, 2024Updated last year
- Random hunting ordiented yara rules☆96Mar 27, 2023Updated 2 years ago
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Jul 12, 2021Updated 4 years ago
- Blueteam operational triage registry hunting/forensic tool.☆149Sep 2, 2025Updated 5 months ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆111Apr 20, 2021Updated 4 years ago