wrayjustin / yaids
YAIDS - Yara-Based IDS - Yara as an Intrusion Detection System / Yet Another Intrusion Detection System - An Intrusion Detection System (IDS) utilizing Yara and multi-threading
☆22Updated 2 years ago
Alternatives and similar repositories for yaids:
Users that are interested in yaids are comparing it to the libraries listed below
- Yara rules for malicious javascript files from public repositories or written by me.☆11Updated 3 years ago
- A collection of Indicators of Compromise (IoCs), most aligning with samples derived from the signatures in the YARA-Signatures repo☆30Updated 4 years ago
- A collection of my public YARA signatures for various malware families☆29Updated 5 months ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- ☆24Updated 2 years ago
- A python script that allows a researcher to merge databases from Malshare and Malware Bazaar to created enrriched datasets from SIEM tool…☆29Updated 4 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 3 years ago
- Parallel ssdeep clustering kit☆20Updated 7 years ago
- ☆22Updated 4 years ago
- Generate bulk YARA rules from YAML input☆22Updated 5 years ago
- Check IOC provided by a MISP instance on Suricata events☆17Updated 5 years ago
- This repository regroups the Yara Rules for the Unprotect Project☆24Updated 4 years ago
- Python based CLI for MalwareBazaar☆36Updated 3 months ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆39Updated 3 weeks ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆34Updated 2 years ago
- Yara rules☆20Updated last year
- Repository of Yara rules created by the Stratosphere team☆26Updated 3 years ago
- Analysis of file (doc, pdf, exe, ...) in deep (emmbedded file(s)) with clamscan and yara rules☆50Updated last year
- Collection of YARA signatures from individual research☆42Updated last year
- CyCAT.org taxonomies☆14Updated 3 years ago
- SACTI - Securely aggregate CTI sightings and report them on MISP☆13Updated 2 years ago
- Pythonic way to work with the galaxies defined there: https://github.com/MISP/misp-galaxy☆19Updated 3 months ago
- A map displaying threat actors from the misp-galaxy☆32Updated 2 years ago
- Carving tool based in Radare2 & Yara☆15Updated 6 years ago
- Tracking APT IOCs☆25Updated 4 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Updated 2 years ago
- This repository maintains the SaltStack state files for the REMnux distro.☆41Updated last week
- Repository of tools, YARA rules, and code-snippets from Stairwell's research team.☆22Updated last year
- D-Scan project for office document analysis and generating flow diagram of macro in documents. For demo visit☆29Updated 3 months ago
- Yara rules for detecting malware☆23Updated 5 months ago